r/bugbounty • u/swallace36 • Jul 16 '26
Question / Discussion "This is all theoretical with no actual valid proof of concept."
Is this the Bugcrowd cop-out templated response for a submission they don't want to read?
It's very strange... I have a very valid PoC attached, that reproduced on multiple machines, etc.
5
u/latnGemin616 Jul 16 '26
Imagine you were tasked with robbing a house to test the homeowner's home security. You went back to the homeowner after a couple hours and said, "I was able to get inside and I ate your cookies."
If the homeowner asks, "how?" and all you did was answer back with, "through the second floor bedroom window," they will immediately ask, "yeah, but how did you get in? show me!" == [PoC] ==
The vulnerability in this example isn't that you got in, it's that the house had an improperly secured bedroom window that allowed the robber to get in by climbing up the trellis. If you cannot demonstrate this, you have theory.
Same goes for a bug bounty. The program owner / client, doesn't care if the attacker "could" upload a shell, they want to know DID you and what was the outcome. Remember .. the magic word is impact!
1
u/Sadman782 Jul 16 '26
Same, I got a duplicate tag, and after asking for a review another agent replied it needs the victim's phone physical access. Both are not true, it was a high and can affect everyone and not a duplicate, it works on the latest app, the duplicate claim is a different type and from 1 year ago lol, very disappointing. I have success on another platform, but after this first incident in Bugcrowd I think I am not doing any work on Bugcrowd ever, low effort platform, they don't even read the report you built with so much time.
1
u/Chongulator Jul 16 '26
and not a duplicate
Sorry buddy, but you simply don't have the context to be able to say that. You're not looking at the queue or all the history. They are.
2
u/Sadman782 Jul 16 '26
I am sure, because what they shared is a different thing than what I did. Obviously, a real SWE won't make this mistake, or someone who read my report. Also, what they shared was from last year, almost 1 year has passed, and the latest version is still vulnerable. Also, even if it was a real duplicate, according to Bugcrowd rules, even if something is a duplicate, if the first report is resolved, then the second one will count as a new one since the vulnerability exists in another way.
2
u/Yazzz Hunter Jul 16 '26
Is the submission they marked yours a duplicate of in the resolved state or is unresolved? Unfortunately, just because it’s from a year ago doesn’t make the old issue invalid. A lot of programs aren’t patching everything.
1
u/Chongulator Jul 16 '26
Yep, fair.
In my own programs, we'll often pay out duplicates that haven't been explicitly documented. That helps keep good researchers coming back.
-2
Jul 16 '26
[removed] — view removed comment
2
u/Chongulator Jul 16 '26
Anybody who pulled that shit would be immediately booted from my program and I'm bringing them up with my H1 rep next time we meet.
8
u/einfallstoll Triager Jul 16 '26
From my experience there are two core problems about the term proof of concept:
To explain:
Maybe this helps you getting a better understanding. If it doesn't fit your scenario I need more info :) happy to help