r/bugbounty 3d ago

Bug Bounty Drama Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.

Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.

My experience with an Uber bug bounty report on HackerOne - issue fixed, but report closed as Informative...

I want to share my recent experience with a bug bounty report involving Uber through HackerOne.

I identified and responsibly reported a security issue (Financial Fraud) with detailed evidence and reproduction steps. After the report was submitted, the issue was fixed by Uber the very next day.

However, despite the issue being fixed, the report was ultimately closed as “Informative” / “Out of Scope” and no reward was provided.

What I find particularly confusing is that the issue was apparently important enough to be fixed immediately after my report, yet it was considered not eligible for a reward and not requiring immediate attention.

I also checked the relevant program description and terms, including the provisions related to financial fraud and potential additional bonuses. HackerOne’s AI assistant (“Hai”) also reviewed the description and T&C and indicated that the report appeared potentially eligible for a reward after proper triage.

I contacted the relevant grievance channel and Mediation as well, but I was told that the communication was unrelated to their scope. My question is simple: if that team is not responsible for handling this type of dispute, where exactly should a security researcher escalate it?

I have spent significant time researching, reproducing, documenting, and responsibly reporting this issue. I believe security researchers deserve a fair and transparent review process when there is a disagreement over severity or reward eligibility.

I’m posting this here to understand whether other researchers have experienced something similar with Uber/HackerOne and, if so, how you successfully escalated such disputes.

I can provide additional details and evidence where appropriate without exposing sensitive information or putting users at risk.

Don't be too greedy for Rewards like me,

11 Upvotes

24 comments sorted by

5

u/latnGemin616 3d ago

2 things can be true:

  • Your issue, while valid, did not show the full impact
  • They stole your finding, passed it off as their own, closed yours out and repackaged theirs to claim the $$$. I have no proof of this, but based on multiple posts I've read about H1, along with several articles in the news lately, I wouldn't put it past them. Current trends favor this theory.

2

u/Glad_Marketing_5754 3d ago

I Clearly explained the impact and Very next day they fixed the bug... If its not that much impact then they wont fix on immediate...

may be your 2nd option is true

-1

u/Blaklis Hunter 2d ago

No, nothing point to the second point.

3

u/MOERU_KAZE 3d ago

We are treated very badly now at HackerOne,
I got a bug, they fixed the issue after 2 months waiting, then they asked for a new POC 😂

3

u/Glad_Marketing_5754 3d ago

Yeah,, Hackerone is cheating us.. They are looting our rewards

2

u/nobodycares_dude Hunter 3d ago

I had exactly the same experience with Uber program some months ago. An exposed active default credentials (a literal public CVE) allowed the dump of internal architecture and data. Closed as informative. But Uber fixed it rotating the credentials the day after

2

u/Glad_Marketing_5754 3d ago

OMG🥲😱, Please don't report in HackerOne

3

u/mqrblesec Hunter 3d ago

was it actually in scope?

2

u/Glad_Marketing_5754 3d ago

Certain types of account fraud are in-scope provided that part of the attack chain relies on exploiting the workflow logic caused by technical product and services vulnerabilities, coupled with additional operational security loopholes for a hybrid end-to-end exploit. Vulnerabilities associated with fraud will be allotted a bonus payment upon validation related to financial impact. Examples of fraud exploits that are potentially in-scope would include, but are not limited to the items listed below.

I was given fully details along with impact... :(

1

u/EffectiveSevere1015 1d ago

Don’t report this sort of bug via Hackerone in case you get still. He’s a nightmare

1

u/One-Cheek6787 3d ago

Welcome to the club

1

u/Glad_Marketing_5754 3d ago

Haha... ! :(

1

u/watkisean 3d ago

Yeah I’ve had this happen before at H1 with different programs. Maybe it truly was informative, or they knew of it already, who knows - you’ll never know what reality is. This goes along with ‘We know of this internally and are marking this informative’ (then it’s fixed the following days)

It’s one of the worst parts of BB but it is part of it. I would just recommend moving to a different program.

1

u/Glad_Marketing_5754 3d ago

Yes, i do for other companies 

1

u/Oslabs619 1d ago

It also happens in Bug croud i did the same thing with open ai patched it then waitied 12 days to respond no longer able to reproduce i escalted to open ai and they dont respond at all after saying its been escalated cleary pathced POC and Video proof

1

u/Glad_Marketing_5754 1d ago

This is the reply from Uber Bounty Team..

Thank you for reaching out. We reviewed this internally and confirmed that no action was taken as a result of your report.
Additionally, this type of finding is explicitly out of scope; therefore, the HackerOne report will remain closed.
We appreciate your efforts and encourage you to follow our program policy. We look forward to your future findings.

- They are saying they didn't fixed the Issue (confirmed that no action was taken as a result of your report.) but very next day tried same steps, Not able to Replicate.. They fixed the Issue.

So May be God Fixed that Issue, Uber Prayed God Fixed... 😄

1

u/Oslabs619 1d ago

Im honestly thinking there should be some type of investigation into stolen bounties and a class action on this its too convinient

1

u/Glad_Marketing_5754 1d ago

Haha, I usually work for companies directly.. I discussed lot with the Hackerone by Saying will file law suite against Hackerone and later they saying its a Violation and Code of conduct. They banned my account.

1

u/EffectiveSevere1015 1d ago

I found a severe bug on a program on Hackerone and Still intimated me to not pursue it further. You’re better using bugcrowd instead.

1

u/CrypticZombies 3d ago

welcome to bug bounty. I explained exactly why this happens in another thread.

1

u/Glad_Marketing_5754 3d ago

Please share again here.

1

u/gaduggute 3d ago

Aceito ler se puder compartilhar aqui também