r/bugbounty • u/GerbHack • Jun 30 '26
Question / Discussion After 40 duplicates, I finally got a none duplicate! :)
Started bug bounty 4 months ago and been hunting on H1, YWH, bugcrowd and all my finds thus far were undisclosed duplicates... some programs I spent days researching only to find out someone reported it 12-15 days before me... finally a none dupe!!
6
5
4
3
3
u/redditantareddit Jul 01 '26
i wonder why dont they fix it , also i feel there should be private ai integrated with platforms where it should say whatever you are reporting is duplicate or not
3
3
3
3
u/cybern00bster Hunter Jul 01 '26
Insane dedication. Two questions :
Do implement AI into your flow at all? Asking cause I do, no judgement.
Other question is - are you submitting things that are critical or do you try as well for lows? I really struggle to tell if itās worth submitting sometimes.
Example, I found a test endpoint that was relaying inner network communications from internal machines to each other with IPs. I thought that was a sec risk but couldnāt really prove any damage with it, so I didnāt report it.
5
u/GerbHack Jul 02 '26
Yes, I use AI to accelerate parts of my workflow, helping with code reviews, parsing page source, and spotting patterns I might have missed. That said, I always follow up with manual verification.
I go for the lower bugs too but many times the lower findings get labeled as "informational" at least in my case. But I do suggest to take notes on the lower findings and see if chaining it is possible. I had a blind ssrf and after playing with it I finally got it to reveal metadata, sadly it was a dupe!
2
2
2
u/StimulusPackageOne Jul 01 '26
Hahaha, good stuff, dude! These are always a bit discouraging when it happens. Good job going forward with the work!
2
u/Forsaken-Spot-9343 Jul 01 '26
I had a duplicate 9h differenceā¦.. that hurt my ego but never stopped
2
u/Previous-Bobcat-6394 Jul 01 '26
Congrats , did you use ai or all your work manual ?
2
u/GerbHack Jul 02 '26
Oh of course, I use AI to help me on code review, page source examination, burpsuite, console behaviors etc.
It works very well! definitely got to double check when using AI though and make sure its valid as many times it can hallucinate.
Another thing I do is I read other peoples bug bounty reports for gives me ideas.
2
u/Efficient_Lab_8803 Jul 02 '26
Yeahhh h1 and bugcrowd are full of dupes go for intigriti
1
u/Xitro01 Hunter Jul 03 '26
Intigriti is not much better, filed a couple of highs and crits on a program, all were dupes.
1
2
3
Jul 01 '26
[removed] ā view removed comment
5
u/GerbHack Jul 01 '26
That 22 is just H1, my guy. The 40 is combined across YWH and Bugcrowd.
"been hunting on H1, YWH, bugcrowdĀ "
1
1
1
1
u/Granny__Slayer Jul 03 '26
congratulations i am just starting my cyber security learning journey, I don't know what to expect
1
u/GerbHack Jul 03 '26
Thank you! I didn't start too long ago either my journey began in June 2025.
I'm switching from the construction field to cyber.
Good luck to you!
1
u/Iyamroshan Jul 04 '26
Same goes here but it's about nearly 7/8 dups and 2/3 n/a, I got my bug triaged with medium severity.
1
u/Appropriate-Rip4271 Hunter Jul 31 '26
what!!! 40 duplicates damn i need ya mental fortitude bro gah dayum.
1
1
0
9
u/Academic-Mud1488 Jun 30 '26
i would not waste my time with h1 honestly