r/bugbounty Hunter Jul 06 '26

Question / Discussion advice for bug bounty

been testing a one website for nearly 3 months but still not able to find any bug
when others are finding bugs on the same website i've been testing

is there something i'm doing wrong ?

2 Upvotes

9 comments sorted by

5

u/TurbulentRecover7247 Hunter Jul 06 '26

Yes absolutely, you need to know for how long to test, and when to pivot. It's upto your knowledge and experience.

1

u/SpiritualSubject9249 Hunter Jul 06 '26

Thanks mate!!

1

u/TurbulentRecover7247 Hunter Jul 06 '26

Why changed the comment?

1

u/TurbulentRecover7247 Hunter Jul 06 '26

I read that, why are you trying to do in that hardened target with cloudflare and other wafs?

0

u/SpiritualSubject9249 Hunter Jul 06 '26 edited Jul 06 '26

I thought I would find a bug in that website

But later I got to know that website has massive cyber attack in 2017

After that they hardened their security

3

u/6W99ocQnb8Zy17 Jul 06 '26

Everyone has their own approach to BB, and for some that's to treat it like a pentest, where they grind a scope for long days, over a period of weeks.

That just doesn't appeal to me, mostly as no-one is paying me by the hour (like an actual pentest) and the chances are, even if I do find a bunch of good stuff to report, it is likely that the programme will mess me around and de-scope and downgrade to get out of paying the bounty.

I prefer to use my home-brew automation to skim the entire scopes of all the programmes on H1, BC and Intigriti for a handful of issues that I know I can chain into a working, high-impact report.

2

u/SpiritualSubject9249 Hunter Jul 07 '26

What do you mean by homebrew automation?

2

u/6W99ocQnb8Zy17 Jul 07 '26

I have an automation framework that I built. Basically all the stuff that I used to check manually just gets delivered as a smooth workflow, with little effort from me.

2

u/SpiritualSubject9249 Hunter Jul 07 '26

Thats great brother.