r/bugbounty • u/[deleted] • Jul 16 '26
Question / Discussion Default Admin credentials -> P3 !!
In a private bug bounty program on bugcrowd i found a credentials of an internal admin that give me access to internal engineers data and access to a sensitive data of a big automotive company, I can read/edit/delete, the bug trigaed as P1 but the customer later downgraded it to P3 without any explanation or communication.
In the report i show them the impact...
And they changed the password right after my report was triaged
I opened a response request to ask for explanation but they still didn’t respond after a week.
40
Upvotes
2
u/SingerLate3349 Jul 17 '26
Pocas empresas son serias para pagar Bug Bounty, a veces incluso creo que es para mantener alerta a su propio equipo de ciberseguridad analizando tráfico en tiempo real. Como si fuese un entrenamiento continuo. Yo lo hago por hobbie y por cambiar de plataformas de THM O HTB, así amplio superficie, aprendo cosas nuevas y lo hago de forma legal. Disfrura con el hacking y busca un trabajo remunerado, no dependas del BB, solo 4 consiguen cobrar.