# How this seasoned bug bounty hunter combines Burp Suite and HackerOne to uncover high-impact vulnerabilities

DevFeed: [How this seasoned bug bounty hunter combines Burp Suite and HackerOne to uncover high-impact vulnerabilities](<https://devfeed.tech/articles/how-this-seasoned-bug-bounty-hunter-combines-burp-suite-and-hackerone-to-uncover-high-impact-vulnerabilities-7722.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/how-this-seasoned-bug-bounty-hunter-combines-burp-suite-and-hackerone-to-uncover-high-impact-vulnerabilities>)

Author: Amelia Coen

Published: 2025-09-12T12:21:38Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [API](<https://devfeed.tech/topics/api.md>), [Extension](<https://devfeed.tech/topics/extension.md>), [Networks](<https://devfeed.tech/topics/networks.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [extension](<https://devfeed.tech/tags/extension.md>), [http](<https://devfeed.tech/tags/http.md>), [networks](<https://devfeed.tech/tags/networks.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

## AI overview

The article profiles Tess, a full-time bug bounty hunter who combines Burp Suite Professional with HackerOne to discover, document, and report high-impact web security vulnerabilities. It describes how Burp Suite exposes backend requests, supports API testing, and provides evidence for triage, including a $38,000 Zoom bounty involving HTTP request smuggling.

## Source excerpt

Arman S. (Tess), a full-time independent security researcher and bug bounty hunter, talked us through how he uses Burp Suite Professional and HackerOne in tandem to find and report high-value security