Alternatively to bounty begging, one could use these tools to find vulnerabilities and then try to figure out why it is a vulnerability and how it might be practically exploited. Seems like a good way to learn real security research. (Don’t actually exploit it, though...)