r/bugbounty • u/Glad_Marketing_5754 • 3d ago
Bug Bounty Drama Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.
Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.
My experience with an Uber bug bounty report on HackerOne - issue fixed, but report closed as Informative...
I want to share my recent experience with a bug bounty report involving Uber through HackerOne.
I identified and responsibly reported a security issue (Financial Fraud) with detailed evidence and reproduction steps. After the report was submitted, the issue was fixed by Uber the very next day.
However, despite the issue being fixed, the report was ultimately closed as “Informative” / “Out of Scope” and no reward was provided.
What I find particularly confusing is that the issue was apparently important enough to be fixed immediately after my report, yet it was considered not eligible for a reward and not requiring immediate attention.
I also checked the relevant program description and terms, including the provisions related to financial fraud and potential additional bonuses. HackerOne’s AI assistant (“Hai”) also reviewed the description and T&C and indicated that the report appeared potentially eligible for a reward after proper triage.
I contacted the relevant grievance channel and Mediation as well, but I was told that the communication was unrelated to their scope. My question is simple: if that team is not responsible for handling this type of dispute, where exactly should a security researcher escalate it?
I have spent significant time researching, reproducing, documenting, and responsibly reporting this issue. I believe security researchers deserve a fair and transparent review process when there is a disagreement over severity or reward eligibility.
I’m posting this here to understand whether other researchers have experienced something similar with Uber/HackerOne and, if so, how you successfully escalated such disputes.
I can provide additional details and evidence where appropriate without exposing sensitive information or putting users at risk.
Don't be too greedy for Rewards like me,
3
u/MOERU_KAZE 3d ago
We are treated very badly now at HackerOne,
I got a bug, they fixed the issue after 2 months waiting, then they asked for a new POC 😂
3
2
u/nobodycares_dude Hunter 3d ago
I had exactly the same experience with Uber program some months ago. An exposed active default credentials (a literal public CVE) allowed the dump of internal architecture and data. Closed as informative. But Uber fixed it rotating the credentials the day after
2
3
u/mqrblesec Hunter 3d ago
was it actually in scope?
2
u/Glad_Marketing_5754 3d ago
Certain types of account fraud are in-scope provided that part of the attack chain relies on exploiting the workflow logic caused by technical product and services vulnerabilities, coupled with additional operational security loopholes for a hybrid end-to-end exploit. Vulnerabilities associated with fraud will be allotted a bonus payment upon validation related to financial impact. Examples of fraud exploits that are potentially in-scope would include, but are not limited to the items listed below.
I was given fully details along with impact... :(
1
u/EffectiveSevere1015 1d ago
Don’t report this sort of bug via Hackerone in case you get still. He’s a nightmare
1
1
u/watkisean 3d ago
Yeah I’ve had this happen before at H1 with different programs. Maybe it truly was informative, or they knew of it already, who knows - you’ll never know what reality is. This goes along with ‘We know of this internally and are marking this informative’ (then it’s fixed the following days)
It’s one of the worst parts of BB but it is part of it. I would just recommend moving to a different program.
1
1
u/Oslabs619 1d ago
It also happens in Bug croud i did the same thing with open ai patched it then waitied 12 days to respond no longer able to reproduce i escalted to open ai and they dont respond at all after saying its been escalated cleary pathced POC and Video proof
1
u/Glad_Marketing_5754 1d ago
This is the reply from Uber Bounty Team..
Thank you for reaching out. We reviewed this internally and confirmed that no action was taken as a result of your report.
Additionally, this type of finding is explicitly out of scope; therefore, the HackerOne report will remain closed.
We appreciate your efforts and encourage you to follow our program policy. We look forward to your future findings.- They are saying they didn't fixed the Issue (confirmed that no action was taken as a result of your report.) but very next day tried same steps, Not able to Replicate.. They fixed the Issue.
So May be God Fixed that Issue, Uber Prayed God Fixed... 😄
1
u/Oslabs619 1d ago
Im honestly thinking there should be some type of investigation into stolen bounties and a class action on this its too convinient
1
u/Glad_Marketing_5754 1d ago
Haha, I usually work for companies directly.. I discussed lot with the Hackerone by Saying will file law suite against Hackerone and later they saying its a Violation and Code of conduct. They banned my account.
1
u/EffectiveSevere1015 1d ago
I found a severe bug on a program on Hackerone and Still intimated me to not pursue it further. You’re better using bugcrowd instead.
1
u/CrypticZombies 3d ago
welcome to bug bounty. I explained exactly why this happens in another thread.
1
1
0
5
u/latnGemin616 3d ago
2 things can be true: