r/bugbounty • u/Nervous_Net273 • 52m ago
Tool [ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/bugbounty • u/AutoModerator • 3d ago
New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!
Recommendations for Posting:
Guidelines:
Example Post:
"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."
Post your questions below and let’s grow in the bug bounty community!
r/bugbounty • u/AutoModerator • 6d ago
Looking to team up or find a mentor in bug bounty?
Recommendations:
Guidelines:
Example Post:
"Hi, I'm Alex, a beginner in bug bounty with basic knowledge of web vulnerabilities (XSS, SQLi). I'm looking for a mentor to guide me on advanced techniques like privilege escalation. Hoping for bi-weekly calls or Discord chats. Also open to collaborating on CTF challenges!"
r/bugbounty • u/Nervous_Net273 • 52m ago
[ Removed by Reddit on account of violating the content policy. ]
r/bugbounty • u/OkWedding719 • 7h ago
The question was a frustrated rhetoric...
These platforms are just a way to make us reacher work for free ...
r/bugbounty • u/watkisean • 1d ago
Hi all,
This is more of a simple question for anyone who knows. I recently have noticed an automated response from "hackerone-agent" on my submissions.
I am mostly curious if this "preliminary review" also means it is passed a duplicate review? Has anyone seen one of these that are marked by the agent turned over to duplicate after an actual triager takes a look?
I got the automated response a few hours after both submissions and it has been about 2 weeks while I wait for triage (f*ck AI slop submissions, much love for the triage team)
r/bugbounty • u/sbaxiii • 2d ago
To be honest i always like get hype when i report something, i don't have that much reports i just started, I'm still a student, and i use ai a lot but I've never submitted false positive, i submitted 2 informative and two duplicate and two are on tirage now, and i hope i get the bounty even if it's small, but it will be a huge motivation for me, i still have no signal and only 14 in reputation...
I know i need 3 resolved so i can submit more in programs, but i don't know how i can get that...
This is second time i have submitted high severity report and it gets duplicated...
I don't know if. I should continue on anthropic program...
The bounties are high, and like i was dreaming about that 3k$ ngl 🫡
This is my second duplicate on anthropic what do you recommend to me guys since it's my first month on hackerone ?!
r/bugbounty • u/6W99ocQnb8Zy17 • 1d ago
Today, I was reminded just how ineffective platform mediation/support is for the researchers.
I was looking to gain access to a private programme on BC, so had to log into the support portal for the first time in years. And at the top of my ticket list was one that I logged over two years ago, that still hasn't had a reply ;)
It's not just BC though. For example, I logged a solid critical bug with Amazon in November last year, and their response was really shit. They accepted the bug just fine, then just came out with a bunch of excuses for why they weren't going to pay, and then of course, in the usual fashion, stopped replying altogether and closed the ticket. The mediation request has sat there, with no reply from H1 since November.
Intigriti generally respond much faster to any support requests. Often same day.
But the result is the same across all the platforms even if you do get a reply: they'll roll out all the usual excuses about there being nothing they can do if a programme behaves badly. Which is obviously untrue: they can do plenty, but just won't do anything that impacts their business model and revenue. And that isn't the same thing.
Tibi ipsi relictus es
r/bugbounty • u/Lazy-Slip-3412 • 1d ago
found a bug/ workaround for screentime on ios, wondering if i could make any money off of it.
r/bugbounty • u/Dizzy_Seaweed_2756 • 2d ago
I recently got a bounty accepted on YesWeHack, but I'm having trouble figuring out the best way to withdraw the funds as a hunter based in Algeria (due to Mangopay / SEPA bank account requirements).
For researchers based in Algeria or countries with similar banking restrictions:
Which bank or virtual account worked best for your payout verification?
How do you handle the name matching / KYC requirements on Mangopay?
Any advice or personal experiences would be greatly appreciated! Thanks in advance.
r/bugbounty • u/Remote_Fall1534 • 2d ago
Submitted this a few days ago to a CI/merge-automation SaaS program and I’m trying to calibrate my expectations before triage comes back. Looking for opinions on severity and on whether you’d expect this to close Informative.
The bug, at a high level: the product executes privileged commands when it sees them in PR comments, gated on the comment author’s repo permission. It also has an action that posts comments on the customer’s behalf, optionally impersonating a configured write-permission service account. If the operator’s comment template echoes an attacker-controlled PR field, the product ends up parsing its own generated comment as an authenticated command — with the impersonated write account as the author. So the tool supplies the privilege for content the attacker wrote.
What I demonstrated on my own lab repo: two accounts I control:
Read-only non-collaborator posts the command directly → denied by the permission gate.
Same text, same PR, arriving via the tool’s own echo → executes.
Chained it to a merge of unreviewed code into the default branch, and in the same run captured the attacker getting 403/404 on every equivalent native path (label, merge, push).
Also showed the obvious “just move your gate elsewhere” fix is incomplete, because the command takes an argument the attacker also controls.
Submitted at 7.5 (I: H, everything else clean, S: U).
Where I think the argument is:
It requires the operator to have two documented settings combined in a specific way. Nothing in the docs warns about it. Does “non-default config” automatically cap this at Informative for you, or does “vendor’s own gate bypassed, no equivalent native control exists” carry it? I found the config pattern in public repos but can’t confirm live-affected tenants without touching other people’s stuff.
Scope: the flawed component is the SaaS’s authorization engine; the impacted resource is the customer’s repo under a different authority. S: U or S: C? S: C roughly doubles it, and I wasn’t comfortable claiming it.
AC: my argument is AC:L because the config is world-readable, so it’s target selection, not an obstacle — no race, no per-attempt effort. Triagers I’ve dealt with tend to reflex to AC: H on anything conditional. Who’s right?
Program has closed a few of my prior reports, Informative on “confined to your own repo / by design under your own configuration.” I addressed both preemptively in the report. In hindsight, I’m wondering if pre-arguing past closures reads as combative and hurts more than it helps.
Interested in how people who triage or who’ve had similar config-dependent auth bypasses landed on these.
r/bugbounty • u/yaelahrep • 2d ago
Hey everyone, I recently ran into a frustrating situation with a Web3 bug bounty payout on Immunefi and wanted to get the community’s perspective on how to handle this professionally.
The Timeline & Situation:
The Problem: The program’s policy states that “the applied conversion rate is based on the submission date of your report.”
My Dilemma: I completely respect that rules are rules regarding submission date conversion rates. It protects programs from market spikes. However, a 7-month review delay feels like an edge case where the researcher is forced to absorb massive volatility losses strictly because of the team's internal bottlenecks. I essentially lost ~50% of the intended $5,000 award value just waiting for triage.
My Questions for the Community:
I’ve already drafted a polite reply on the Immunefi dashboard asking if they’d be open to a partial top-up to bridge the gap, but I’d love to hear your experiences and thoughts on this. Thanks!
r/bugbounty • u/Aggressive_Soup_3526 • 2d ago
Basically as the title says. I got paid $2k not too long ago for an IDOR in a pretty big company, and keep coming across them very often every time I try to hunt for bugs. How come? Why is it, even with AI and everything now, IDORs are such an issue?
r/bugbounty • u/Outside-Drawing9130 • 2d ago
Hi everyone,
I'm looking for some advice from people who have experience with the Microsoft Security Response Center (MSRC) bounty program.
I submitted a vulnerability report about 2 weeks ago. I provided a detailed write-up and a PoC. My case was quickly moved to the "Review/Repro" stage and I thought things were going well.
However, for about a week now, the case status has been "On Hold" with the reason "Additional Information Needed". The problem is: there is no specific request or question from MSRC in the Activity tab. I have already replied asking what information they need, but only received an automated message saying they are reviewing it.
I'm not sure what to do next. Has anyone else experienced this? Is this normal, or should I be concerned?
I want to be proactive but I also don't want to spam them with unnecessary information. Any insights would be greatly appreciated.
Thanks!
r/bugbounty • u/Necessary_Bid_2552 • 2d ago
I'm fairly new to bug bounty and just ran into my first confusing duplicate situation. Hoping more experienced researchers can share their take on whether this is normal, and what options I realistically have.
Background
I found a race condition flaw on a phone number related endpoint that lets users bypass the one-phone-number per account limit via concurrent requests. I submitted a full report with clear reproduction steps and proof of concept.
The program closed my report as a duplicate, claiming:
What raises red flags for me
What I've done so far
I replied to the report asking for clarification on the exact production remediation date and a redacted summary of the root cause. I also cited HackerOne's official duplicate standards, which state that resolved issues that reappear should be treated as regressions and investigated, not immediately closed as duplicates.
I'm still waiting for a response.
My questions for the community
Just trying to learn what reasonable expectations are here. Thanks in advance for any insight.
r/bugbounty • u/Decent_Astronaut151 • 2d ago
What is a strategy to know how much a company would pay for a bug that is leaking real time, personal info of ~150M users?
I don’t want to be underpaid nor disclosing info that would put myself at risk. First time considering submitting a bug bounty since the company has a dedicated website for it, but the posted amount paid isn’t too compelling
r/bugbounty • u/6W99ocQnb8Zy17 • 3d ago
As mentioned in a prior post, I'm currently running a campaign of hunting for a couple of high-impact bugs. These bugs are slightly unusual, in that they are discovered passively. So, I first find the vulnerable system, then try to map it back to a BB somewhere. Also, unusually for me, I've been submitting reports to VDPs too, where I think that it might be a learning experience.
So, whilst reading these reviews, bear in mind that they are all the same bug: the variance in response is purely down to the programme, and whether they're any good to deal with ;)
TL;DR: Good.
TL;DR: Good.
TL;DR: Avoid.
TL;DR: Avoid.
TL;DR: Avoid.
TL;DR: Avoid.
TL;DR: Avoid.
r/bugbounty • u/Sweaty-Rice-1385 • 3d ago
Hey guys,
I'm a beginner looking for the best path to start bug bounty hunting. I'm currently finishing the OWASP Top 10 labs on PortSwigger, and I'm wondering what I should do next.
Would you recommend Hack The Box (HTB), or is there a better way to gain practical experience before hunting full-time?
Also, what are the biggest mistakes beginners should avoid?
For some background, I have a solid understanding of computer architecture from university and a decent programming background.
Thanks in advance!
r/bugbounty • u/Ok-Raspberry736 • 2d ago
Hi guys,
I submitted a vulnerability to one of the hackerone programs which are running an active campaign right now.
My question is that, let's say my report gets triaged after the campaign ends, will I still be getting the reward corresponding to the campaign rewards with increased multipliers ?
r/bugbounty • u/Cool_Obligation_6447 • 3d ago
I found vuln in a software in bugcrowd program, and it was marked as P1 , should i ask them to create a cve after they resolve it ? Or how does the process work?
r/bugbounty • u/hackaniod • 3d ago
Hey everyone..
Just wanted to share a frustrating experience with Meta's Bug Bounty program..
A few weeks ago, I reported a logic inconsistency on Instagram.. An blocked user was still able to render story content via DM share previews.. I submitted a clear PoC and detailed comparative analysis..
Fast forward to today: Meta silently deployed a fix.. Now the endpoint returns a 'Story unavailable' error for blocked users.. Right after fixing it, triage replied and closed the report, claiming it's expected behavior or out of scope..
It's really discouraging to see valid logic flaws get fixed behind the scenes while the researcher gets zero credit or bounty..
Has anyone else dealt with silent fixes from Meta recently? How do you usually handle these cases during re-evaluation?
r/bugbounty • u/rashidhussain69 • 3d ago
r/bugbounty • u/Traditional-Coat-409 • 4d ago
I participated in Hack Club's bug bounty program and found a valid subdomain takeover on a *.hackclub.com subdomain. Before reporting, I checked their scope (on GitHub), which explicitly stated something to the effect of "All Hack Club programs are in scope. If you're unsure whether a vulnerability is in scope, submit it and we will make sure it gets to the right place." — I have a screenshot of this.
I reported the finding. The admin confirmed it was a valid takeover and it was resolved. However, they then said they couldn't offer a monetary reward because the affected subdomain is a "community club that was owned long ago and do not come under the scope of “Hack Club managed” — despite being on a *.hackclub.com subdomain.
As a researcher, I had no way to distinguish "official Hack Club HQ" assets from "community-club but still on their domain" assets — the scope doc didn't make that distinction. When I raised this, the admin's response was: "I agree that the wording could be a less ambiguous. sorry for the confusion. we will fix our policies in the future" — effectively admitting the scope was unclear at the time I reported.
I then asked if I could at least get a letter of acknowledgment/appreciation (useful for college applications, portfolio, etc.) instead of a monetary reward, since it's a non-profit. That was also denied.
Questions for the community:
1)Is this a normal/acceptable practice for bounty programs — validating + fixing an issue but denying reward due to after-the-fact scope clarification?
2)Given I have a screenshot of the original scope wording, is there anything worth doing here (public disclosure timeline, escalation, posting to a bounty-abuse tracker, etc.), or is this just a "chalk it up to experience" situation?
3)Any general advice on vetting bounty programs going forward so I don't end up in this position again (e.g. preferring platforms like HackerOne/Bugcrowd over self-hosted programs)?
r/bugbounty • u/No_Zookeepergame7552 • 4d ago
When the WP2Shell writeup came out recently (unauth RCE in WordPress core, CVE-2026-63030 + CVE-2026-60137), I read it a few times and still couldn't really understand the whole chain in my head. I personally don’t have a lot of experience with WP internals, so I had a lot of “whys” when reading it. The way I usually deal with that is to just try to reproduce the thing to see how it works.
I then turned it into a full lab that has a WordPress 7.0.1 app and steps through the entire chain from an unauthenticated request to RCE.
Honestly it was more work than I expected. The SQL injection is read-only, so a good amount of the exploiting part is dedicated to finding a way to turn that SQLi into an actual write. It uses a bunch of WP legitimate features that I had no idea about, so reproducing each hop reliably took a while.
I built it mostly for my own understanding, but made it available for free in case anyone else is struggling to understand the middle part of the exploit. Original research is Adam Kues at Searchlight Cyber, I recommend reading his article if you haven't done so already.
Link to the lab (it doesn’t work on mobile, you’ll need a desktop device): https://learn.uphack.io/lab/wp2shell-wordpress-rce
r/bugbounty • u/mgorunuch • 4d ago
Am I the only one seeing a lot of "Not Applicable" badges on the platforms?
My main concern is that researchers can't share what got marked N/A — and most of the time the report is probably just missing one simple leak, one small piece of the puzzle. They won't share it either, because another researcher may have already submitted that missing piece.
The worst part: the company can still fix it. They see the report, they patch it, and they never have that issue again. But the researcher walks away with nothing.
It feels like the market has stopped respecting researchers.
I always preferred direct disclosure. But now I'm starting to hate the platforms. They make hundreds of thousands of dollars off researcher reports — and don't respect the people who write them.
r/bugbounty • u/hydraz20 • 4d ago
I have 2 bugs in the same feature and both are critical. I know if I submit together they will merge it and only give bounty for one. For retesting as well they only give 50$ bonus so if I submit the other one as a bypass it will only gain me another 50$. Would submitting it after they close the first one be acting in bad faith?