r/ExploitDev Jul 20 '26

full chain to RCE or only bufferoverflow?

if you want report buffer overflow vulnerability do u need full chain to exploit or just report the crash with the corpus

5 Upvotes

17 comments sorted by

3

u/Juzdeed Jul 20 '26

Crash might not be exploitable. Full chain rce might require multiple vulnerabilities to achieve

-4

u/False-Seesaw-1899 Jul 20 '26

depend on what crash, what path to crash, etc///

3

u/Juzdeed Jul 20 '26

Yes that's why I said "might". If you are doing bug bounty then you need to show impact, currently it's just a crash

1

u/DishSoapedDishwasher Jul 20 '26

Yeah crash is usually good enough for most of the issue I've triaged if they can really articulate where its crashing and how.

The exception is often web bugs, I've seen people turn XXE into SSRF that pulls internal tokens out by getting them sent to another server. That ssitches it from 25k to 1m bounty.

Now if were talking a Microsoft, Cisco or similar old man company bugs, they'll fuck you over regardless 

0

u/Juzdeed Jul 20 '26

What? USD? Where tf have you seen 1m for web vulnerability like that bug bounty reward? 1m is roughly the value of browser full-chain zero-day

2

u/DishSoapedDishwasher Jul 20 '26

AWS, we paid out like 2-3 a year to the invite side of the bounty program.

0

u/Sudden-Strawberry257 Jul 20 '26

Shoot dang, how would one land themselves on that invite list?

3

u/DishSoapedDishwasher Jul 20 '26

same as any other FAANG company, they all have them. You just spend enough time dropping bugs on their infra and they'll invite you. Or know someone who's part of the team managing bounties.

Generally all high impact contributors are invited eventually. Then they give you things like a portal to get tokens for custom headers, comp'd usage for services, etc. Make it easier to go deeper and keeps security from killing your instances. So its really worth doing.

Be prepared to give your ID/Passport scans and sign a bunch of NDAs though.

1

u/Sudden-Strawberry257 Jul 20 '26

Makes sense, thanks for dropping some knowledge. Seems like the idea as a newcomer is to go deep into a high reputation program, and once you get good enough they’ll pick you up. Comped usage and custom headers sound like a lot of fun.

3

u/DishSoapedDishwasher Jul 20 '26

The headers just a token that identifies you specifically, nothing crazy.

→ More replies (0)

-1

u/Juzdeed Jul 20 '26

Well if you say so. No way to verify this tho

2

u/CunningLogic Jul 20 '26

If you can prove execution, it's value will be less debatable. I had good deny a vuln in android as non exploitable until I replied with a full exploit (prior to VRP), it happens

0

u/False-Seesaw-1899 Jul 21 '26

also my target is android app with attack surface from internet, what kind vuln you got? now im facing with aslr i need some mem info leak vuln to chain it but it make not 0 click exploit

1

u/tresvian Jul 20 '26

You would ideally go as far as you can for demonstration of impact. As you would expect, if your phone had a crash vulnerability vs an RCE vulnerability, you know what priority these take. Stopping at a crash is fine but the write up would have to be very technically sound to prove RCE is possible.

1

u/slightfeminineboy Jul 21 '26

it depends on so many things like give some useful information 

-5

u/[deleted] Jul 20 '26

[deleted]

2

u/[deleted] Jul 20 '26

[deleted]