Bug › Module 2 › Lesson 3
Picking Programs
Choose programs that match your skill, time, and ethics — enroll in YOUR $SCOPE_HOST deliberately.
Visual · bounty_picking_programs
Picking programs literacy. $SCOPE_HOST only. Original Cyberlium.
Opening
Pick one program, read it fully, enroll — do not spray recon across the platform catalog.
Good program selection weighs scope clarity, technology familiarity, response time reputation, and your available hours. Beginners benefit from narrow scope, clear policy, and practice labs at $LAB_HOST before touching complex production. Picking ten programs and scanning all of them violates the one-program-at-a-time discipline triage teams expect. Cyberlium expects you to name ONE enrolled program at $SCOPE_HOST (or $LAB_HOST for pure practice). You will NOT pick programs solely by highest bounty and ignore scope size. Next: Platform Lab.
1. Selection criteria that matter
Clear in-scope list including $SCOPE_HOST, explicit out-of-scope section, published safe harbor, reasonable rate limits, and technology you can study ethically. Avoid programs with vague scope unless you will ask questions and wait.
Response time and duplicate policy affect learning — read program stats and recent disclosures for literacy, not as a target shopping list.
Command guide
Try these commands — Selection criteria that matter
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Program notes — why this program fits your skill level Scope parsing — *.domain vs single host
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
grep program_url "$HOME/cyberlium-lab/t20-program-notes.txt" 2>/dev/null || echo 'program_url: (fill after joining)' curl -sS https://httpbin.org/robots.txt | head -10
Primary tools to practice this lesson: curl, grep. Reference sites: Program notes; Scope parsing. Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Start narrow, grow deliberately
First programs: small scope, staging assets, or vendor practice labs at $LAB_HOST. Wide-scope production giants come after scope-reading and recon habits are solid.
Jumping to complex programs while scanning classmate URLs on the side destroys both learning and account standing.
3. One enrolled program for Cyberlium
Name $SCOPE_HOST as YOUR primary enrolled program for this topic. Optional $LAB_HOST for offline practice — never substitute random sites when scope feels hard.
Ship: three reasons you picked YOUR $SCOPE_HOST program. Next: Platform Lab.
4. What you ship: program selection rationale
Three reasons for picking $SCOPE_HOST. Narrow scope note. NEVER catalog-spray recon. chmod 600.
5. What you record before the next lesson
Date. Three selection reasons. $SCOPE_HOST named. File t20-m02-l03-picking-programs.txt chmod 600.
6. Wrong vs right: random sites vs in-scope program
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Enroll in twenty programs and scan all tonight. Pick highest bounty and ignore out-of-scope list.
Right
Write three reasons for YOUR $SCOPE_HOST pick. Next: Platform Lab.
Mission: justify YOUR program choice
1) List three reasons you chose $SCOPE_HOST. 2) Confirm scope is readable and you enrolled. 3) chmod 600. Never multi-program spray recon.
Stuck? Ask Cyberlium AI Mentor
One good program beats ten unread policies.
Knowledge Check
APPLY: Best first program trait for learners:
Multiple choice
Knowledge Check
APPLY: True or False: Enrolling in many programs authorizes simultaneous recon on all of them.
True or False
Knowledge Check
APPLY: When scope feels too wide you should:
Multiple choice