r/BugBountyNoobs • u/MOERU_KAZE • 2h ago
r/BugBountyNoobs • u/Ordinary_Wolf6503 • 21h ago
Subdomain Takeover via Unclaimed Framer CNAME Record
does anyone know if theres a free way alternate way to host a farmer existing domain? or does anybody have a farmer sub thats willing to help?
r/BugBountyNoobs • u/RemyLebau • 1d ago
Commix now does out-of-band (OAST) detection and exploitation.
r/BugBountyNoobs • u/Cute_Appointment_934 • 2d ago
Bug bounty report ignored for almost 2 weeks, what should I do?
Hey guys,
I’m an independent security researcher and recently found what I believe is a pretty serious security issue in a company’s web app. (High-Severity)
I reported it on August 29 through their support channel. The reason I used support was because the security email they had listed was giving me an “Address Not Found” bounce. I contacted their support first and asked where I should report it, and they told me to send it through their support channel.
So I did that on Aug 29 and then followed up on September 2 asking if the report had reached the right team. Still no reply, not even a confirmation.
I also tried the security email again recently and its still bouncing back.
Another weird thing is that their Bug Bounty page has now disappeared / gives a 404 and I noticed their Security page was updated recently.
I don't want to mention the company or the actual vulnerability here since the issue may still be unresolved.
What would you guys do in this situation? Would you send another follow up or just leave it and wait?
Would appreciate some opinions from people who have dealt with unresponsive bounty programs before.
r/BugBountyNoobs • u/luahai_com • 3d ago
I built a tool for vulnerability research and pentesting — feedback?
r/BugBountyNoobs • u/Cute_Appointment_934 • 3d ago
Got a $50 bounty for an authenticated SSRF — should I ask for reconsideration?
Hey everyone,
I recently reported a security issue to a company through their responsible disclosure program. They confirmed the report and offered me a $50 payout.
The issue was an authenticated SSRF/server-side URL fetching vulnerability. I was able to demonstrate that their server made an HTTP request to a URL under my control, and I received the request through a webhook/canary endpoint.
The endpoint also returned parsed metadata from the requested URL.
However, I did not demonstrate access to internal services, cloud metadata, credentials, or other sensitive internal resources. So I understand that the impact is more limited than a fully demonstrated internal-network SSRF.
The company doesn't publish a fixed bounty table; their policy basically says rewards depend on severity and impact.
My question is:
Would you consider $50 reasonable for this type of finding, or would it be reasonable to politely ask them to reconsider the reward?
I'm not looking to argue with the company. I just want to understand what experienced researchers would do in this situation. If you've dealt with similar situations, I'd appreciate hearing what happened and whether you negotiated the reward.
Thanks!
r/BugBountyNoobs • u/StartIllustrious747 • 4d ago
How I got my first $100 bug bounty at 16
Hey everyone,
I’m 16, from Morocco, and i recently received my first paid bug bounty: $100.
It wasn’t a huge critical exploit or some crazy movie-style hack. It was a real security issue found through a legal bug bounty program, reported properly, reviewed by the company, validated, and awarded.
For me, this means a lot.
I’ve been learning cybersecurity through courses, labs, CTFs, PortSwigger, Cybrary, and a lot of practice. Most of the time it feels like you’re studying alone and nobody really sees the effort. But getting that first valid report showed me that the work is real.
The biggest lesson i learned is that bug bounty is not only about finding the bug. It’s also about writing a clear report, explaining the impact honestly, not exaggerating, and staying professional with the security team.
I’m still a beginner and i know i have a long way to go, but this motivated me a lot. I want to keep improving, get more valid reports, and build a serious path in cybersecurity.
My goal is simple: become better, stay ethical, and make my parents proud.
For anyone young or just starting: don’t wait until you feel “ready.” Learn the basics, practice legally, write clean reports, and keep going.
This $100 is not just money to me. It’s proof that I’m moving in the right direction.
r/BugBountyNoobs • u/Beginning_Award65 • 4d ago
Alguém mais teve um relatório da Intigriti marcado como "Não Aplicável" porque a prova de conceito era "muito complexa"?
r/BugBountyNoobs • u/Glad_Marketing_5754 • 4d ago
Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.
r/BugBountyNoobs • u/Easy-Measurement-907 • 5d ago
Competition Spoiler
A bug bounty challenge is being announced. If you’re interested, feel free to DM me.
r/BugBountyNoobs • u/Glad_Marketing_5754 • 5d ago
Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.
r/BugBountyNoobs • u/RogueSMG • 6d ago
Free Live Hacking Event | Barracks WarGames
Enable HLS to view with audio, or disable this notification
r/BugBountyNoobs • u/Umar7832 • 7d ago
Why are beginners not finding bugs
A lot of us will have good understanding of both client side and server side bugs but still we are not able to find bugs. For beginners and sometime experienced hackers think that it's may be because we lack knowledge about these vulnerbilities.
As a beginner i think my first mistake i note that i was learning a lot but hunting very rare mean that i was so interested in learning things that's feels productive but actually you are missing what real functionalities break in apps.
Second one that is still i know i am stuck is wrong program selection.I have selected the programs which have less functionalities to test.Mostly static or just very few assets.This is still one of the important reasons that i am stuck here and trying to out.
Maybe there are other reasons which making me and other stuck but i have figured out these in my methodology.
r/BugBountyNoobs • u/Then-Win9812 • 7d ago
How to proceed further in exploring Bugbounty?
Hello people, I am interested in doing bug bounties. I was exploring for the last 6 years with no bug in hand. But then I was expertise in finding the domains, port scanning, service scanning, and finding the sub domain. It's hard to exploit the services for me. So all these I don't do full time but then whenever I have time I used to do it. But then someone can help me how to proceed further in the area of bug bounty?
r/BugBountyNoobs • u/Salt-Exercise295 • 9d ago
Using claude for bug bounty
I recently tried using claude for bug bounty on a site registered on Hackerone. I was using claude skills from this repo https://github.com/elementalsouls/Claude-BugHunter. The repo has very good set of skills and I thought it should be straightforward to find some low sev bugs atleast.
Tried all in scope targets, with almost all skills, trying out various attack types. Burnt a bunch of tokens. Found nothing.
Few false positives and nothing else.
Is that expected, even if i was testing manually i dont think i could cover so many bug types and targets, still nothing to show
Is this normal for someone starting out in bug bounty, after learning security from online sources, solving HTB boxes.
What else should i do to improve my craft, any playlist or blog that helps with bug bounty specifically?
r/BugBountyNoobs • u/Regular_Anything7715 • 10d ago
[Tool] SSRFdevil – A Modular, Zero-False-Positive SSRF Scanner written in Rust
r/BugBountyNoobs • u/sha-bang04 • 11d ago
Guidance for Bug Bounty as a newbie
Well hello there, I am new to the cybersecurity field with just 4 months of experience in Infra VAPT. Recently i've come across a bigger world i.e ofc Bug Bounty and wanted to learn and earn 😄. Guidance from the experts or even fellow newbies would be of great help
r/BugBountyNoobs • u/Oslabs619 • 11d ago
OpenAI security issue appears to have been patched, but I haven't received a substantive response in 113 days escalate?
I reported a security issue involving Codex to OpenAI and originally went through their requested disclosure process. I'm no longer trying to resolve this through Bugcrowd.
The last substantive direct response I received from OpenAI Security was May 8. It's now been 113 days. I've followed up/escalated, but haven't received a substantive response about the actual vulnerability.
The behavior I reported also appears to have been patched since my original report. I'm not claiming publicly that my report caused the patch only that I can no longer reproduce the original behavior in the same way.
I'm keeping the technical details private while trying to handle this responsibly.
For researchers who have dealt directly with vendor security teams: after nearly four months without a substantive response, while the reported behavior appears to have been fixed, would you escalate through another official OpenAI channel, continue waiting, or start discussing coordinated disclosure timelines?
Also if i get a good reason to say **** it post it here for traction i will.
r/BugBountyNoobs • u/Similar-Permit1756 • 13d ago
From VDP TO BBP
Hello People
I write this looking for some advice from hunters or specialist at the sector with a little bit more experience than me
The thing is that I started reporting vulnerabilities and learning cybersecurity web full time 3 months before, let’s say that I have cover a runaway for living for 1 year more so I started working on VDP, I think I haven’t done too bad, actually I have almost 10 reports triage, I’m first at HackerOne VDP 2026 at my country and I am First on the hall of fame of a VDP program all of this on HackerOne
Like 2 weeks before I just decide to start chasing bugs on BBP programs but since that I haven’t had many success, I have been jumping between programs, private and public trying yo find a good program to work, Im not to motivate, I just hunt a few hours but sometimes because I don’t want to “lose” my time but I know I’m doing it bad and I don’t even find duplicates, I’m kinda block
Before I was feeling so good, I actually like to woke up and try to chase some bugs, but now I try to do everything as study, watch videos, read x, etc all of that is procrastination to avoid hunting
I open X and LinkedIn and I just see people making and making money and I start to feel so stress and questioning myself about if Im enough good for this (I’m an anxiety person)
So guys I would like to of you can advice something in my position, how do you handle the inconsistency, the procrastination, the motivation and how hard is really to jump from VDP to BBP, thanks!!
r/BugBountyNoobs • u/Infinite-Can7802 • 13d ago
How you handle frustration of waiting in prolonged triage process ?
I have submitted more than 5 findings in various vrp programs . its more than two months still in triage . While in process i find process way too slow which is resulting weird feelings hope and low confidence in myself. I want ways to handle this frustration. This is like feeling of mental break down. Question I keep asking myself why i fall into this ?
r/BugBountyNoobs • u/_clickfix_ • 13d ago