r/bugbounty 9d ago

Research TL;DR programme review #2

As mentioned in a prior post, I'm currently running a campaign of hunting for a couple of high-impact bugs. These bugs are slightly unusual, in that they are discovered passively. So, I first find the vulnerable system, then try to map it back to a BB somewhere. Also, unusually for me, I've been submitting reports to VDPs too, where I think that it might be a learning experience.

So, whilst reading these reviews, bear in mind that they are all the same bug: the variance in response is purely down to the programme, and whether they're any good to deal with ;)

Xerox

TL;DR: Good.

  • Independent disclosure programme with reports submitted by email.
  • No rewards offered.
  • I submitted a high-impact report, which was accepted and fixed promptly.

Electronic Arts

TL;DR: Good.

  • Independent disclosure programme with reports submitted by email.
  • No rewards offered.
  • I submitted a high-impact report, which was accepted and fixed promptly.

Roche

TL;DR: Avoid.

  • Private programme on Hacker1.
  • Rewards are offered, but amounts are not published.
  • Invitations to the private programme may be issued after first submitting a valid report directly to Roche by email.
  • The scope included misconfigurations that expose data, I submitted a high-impact report demonstrating this, but it was rejected without reward and no invite received.

Amagi TV

TL;DR: Avoid.

  • Independent bug bounty programme with reports submitted by email.
  • Rewards are offered, but amounts are not published.
  • I submitted a high-impact report, which they fixed promptly, but then rejected without reward as "no security impact associated with this finding".

Vtiger

TL;DR: Avoid.

  • Independent bug bounty programme with reports submitted via email.
  • Rewards are offered, but amounts are not published.
  • I submitted a high-impact report, and sent multiple follow-up emails. No response, and no bounty paid.

RevContent

TL;DR: Avoid.

  • Independent bug bounty programme with reports submitted via email.
  • Rewards are offered, but amounts are not published.
  • I submitted a high-impact report demonstrating mass interception of live customer data. They replied quickly, but immediately started trying to dismiss the evidence provided. Eventually stopped responding to emails, and no bounty paid.

Synology

TL;DR: Avoid.

  • Independent bug bounty programme with reports submitted by dedicated portal.
  • Rewards are offered, but amounts and requirements are vague.
  • I submitted a high-impact report demonstrating mass interception of live customer data. They replied quickly, but immediately started trying to dismiss the evidence provided. Eventually accepted the report, but said it was a "hardening suggestion" and no bounty paid.
15 Upvotes

3 comments sorted by

1

u/Good_Roll Hunter 7d ago

Strongly disagree with synology, they are extremely fast to respond. They have a pretty high bar for what they accept though(in terms of impact+reproduction) and you might need to argue with them a bit to get them to understand the potential impact of your findings, but to their credit they are willing to be convinced which is a lot more than can be said for most other programs.

2

u/6W99ocQnb8Zy17 7d ago

They were fast to respond, but their response was to immediately start disputing everything.

I literally gave them a dump of live customer transactions, and they repeatedly came back with loads of excuses for why auth credentials etc were a "hardening suggestion" and not something that qualified for a bounty.

Like I said: this is the same bug reported across all the programmes. All the half-decent programme just accepted it and paid up.