Bug Bounty Checklist for Web App

Reconnaissance:

Recon on wildcard domain

Single Domain Scanning:

Manual Checking:

Configuration Management:

Secure Transmission:

Authentication:

OAuth Test Cases:

Session Management:

Authorization:

Data Validation:

Denial of Service:

Business Logic:

Cryptography:

Risky Functionality - File Uploads:

Risky Functionality - Card Payment:

HTML 5:

Happy Hacking :)