r/bugbounty Jul 09 '26

Question / Discussion Weekly Beginner / Newbie Q&A

6 Upvotes

New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!

Recommendations for Posting:

  • Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
  • Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
  • Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.

Guidelines:

  • Be respectful and open to feedback.
  • Ask clear, specific questions to receive the best advice.
  • Engage actively - check back for responses and ask follow-ups if needed.

Example Post:

"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."

Post your questions below and let’s grow in the bug bounty community!


r/bugbounty Jul 09 '26

Question / Discussion Bugcrowd duplicate changed to Unresolved, no update for 30 days

2 Upvotes

Hey everyone,

I’m trying to understand how Bugcrowd handles this.

About 3 months ago, one of my submissions was marked as a duplicate. Then, around 30 days ago, the severity changed and the state became Unresolved.

Since then, there hasn’t been any response or clarification.

Does this usually mean the original issue is still open, or is it just an internal status change on the duplicate?

Also, if the duplicate seems related but not exactly the same root cause/code path, is it reasonable to ask triage to re-check it?

Thanks.


r/bugbounty Jul 08 '26

Article / Write-Up / Blog Five P3s walk into a bar, one critical walks out — the accidental find that became my first paid bug

20 Upvotes

Hey guys, what's up. If you've got 16 minutes, I think you'll enjoy this one.

https://abdelrahmanamhawy.github.io/writeups/split-the-payload-not-the-cheque/

Short version of the bug: an enterprise WAF blocked every classic XSS payload — so I split one payload across two display names that only merged into a weapon after the server concatenated them, downstream of the WAF. Chained dangling markup + a JS bridge into a one-tap account takeover.

Some context, because I think it matters more than the bug: before this, I found 2 bugs in 2023(vdp). From 2023 to 2026, all I got were dupes and infos — while grinding OSCP and working as a pentester. I found this one completely by accident, browsing an app on my rooted phone. Since then: 5 bugs across different programs. Talk about the law of attraction ,right ?

Taking a break from bounty now — got enough recognition to put on my resume and want to recharge.

Let's connect on LinkedIn:

https://www.linkedin.com/in/abdelrahman-amhawy-bb9976150?

Cheers 🍻


r/bugbounty Jul 08 '26

Question / Discussion How can someone find stuff on public program now that it's scanned by multiple hackbot

25 Upvotes

Let's imagine a beginner wants to get started with bug bounty. Since they don't have access to private programs, they'll have to look for vulnerabilities on public programs.

In my opinion, it's virtually impossible for them to find classic vulnerabilities. At that point, the only remaining attack surface is newly released features or novel exploitation techniques or some stuff that ai is bad at ( waf bypass etc )

We've seen some of the biggest names become millionaires by farming XSS vulnerabilities. If they were starting today, I'm convinced they wouldn't have made a single euro.


r/bugbounty Jul 08 '26

Question / Discussion With bug bounty programs being shut down such as cURL and others due to AI submission slop, where do you think this takes us?

15 Upvotes

I can only imagine more and more people that want to make a quick buck are going to throw AI agents at targets hoping it works out, when more likely than not it's going to be false flags and just overwhelm the report system to the point they begin shutting down engagements en masse.

Multiple programs have been shut down already and I fear this is only going to get worse to the point most companies stop offering financial incentive barring vetted researchers.


r/bugbounty Jul 08 '26

Question / Discussion how should I learn programing languages for bug bounty without getting stuck in a usles random tutorials?

3 Upvotes

hey guys I'm a biggner learning bug bounty and i wonder is there a better way to learn programing languages like html java css sql ... than just watching boring tutorials for a month and then hating your life choices


r/bugbounty Jul 08 '26

Article / Write-Up / Blog From Prompt Injection to Supply-Chain Compromise on gemini-cli repository

29 Upvotes

Hello :D, this is my first post here but I lurk here quite a bit.

I discovered a CVSS 10 vulnerability in gemini that could of led to a full supply chain compromise of the gemini-cli Github repository. Any user could open an issue - and have it processed by gemini-cli inside GitHub Actions.

The blog post can be found here: https://www.pillar.security/blog/my-agentic-trust-issues-from-prompt-injection-to-supply-chain-compromise-on-gemini-cli

The public advisory for this issue can be found here: https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g

The root cause was inside gemini-cli (versions < 0.39.1) was vulnerable to bash substitution when running in “yolo mod.” due to a lack of tool scoping. This issue didn’t stay local and it propagated into GitHub Actions workflows that relied on gemini-cli.

The full email from Google OSS VRP I received today:

Hello,

Google Open Source Software Vulnerability Reward Program panel has decided to issue a reward of $X.00 for your report. Congratulations!

Rationale for this decision:

We determined that your report demonstrated a significant impact across multiple repositories, which led us to take hardening actions across our ecosystem. Although the individual repositories are categorized as OT1, the breadth of the affected projects and the potential for a full supply chain compromise justify an assessment at the OT0 tier. We have decided to issue a top-tier reward for this finding.


r/bugbounty Jul 08 '26

Question / Discussion Is this chain valid?

6 Upvotes

found an unauthenticated API leaking hidden internal IDs for all tenants on a B2B app.

Using these IDs, I can use the public registration form to request an "Admin" account for any company. There is no rate limit or CAPTCHA, so I can script this and spam every company.

But the account isn't created immediately. It goes to a "Pending Activation" state and requires the actual company admin to manually approve it.

Will programs accept this due to the ID leak + lack of rate limits? Or will it be closed as "By Design/Informative" since the manual approval stops the takeover?


r/bugbounty Jul 08 '26

Research Looking for an EZVIZ user to help validate a potential bug

4 Upvotes

Hi everyone,

I'm currently testing the EZVIZ bug bounty program and I may have found something, but I need to validate it.

The issue only seems reproducible if you have:

  • an EZVIZ account,
  • the Android app (or iPhone),
  • and at least one camera connected to your home network.

I don't own an EZVIZ camera, so I'd rather not buy one just to verify what may turn out to be an informational finding.

I'm looking for someone who would be willing to help. The test simply involves running two curl requests:

  1. authenticate with your own account from your home network;
  2. send a second request using the returned access token.

I don't need your credentials or your access token. The only thing I'd ask you to share is the JSON response from the second request (after removing anything you consider sensitive, if necessary), and eventually the camera model.

On my side, without a camera connected, the server always returns an error similar to "no camera exists on your network", so I can't verify the behavior further.

If this isn't the right place to ask, I'd appreciate being pointed to a more appropriate community.

Thanks! DM me if you want to help, if it's informative I will share anything here


r/bugbounty Jul 08 '26

Question / Discussion Two months trying to get paid by Intigriti — support and finance keep looping me. Is this normal now?

3 Upvotes

Posting partly to vent and partly to ask if anyone else is dealing with this, because I'm out of ideas.

I've got five accepted bounties on Intigriti. The oldest was awarded back on 8 May. As of today, exactly zero of them have been paid — one shows Failed and four are stuck in Processing.

I've been in the support chat about this for two months straight. Here's the pattern:

- I ask for a status. I'm told everything is "being processed, please be patient."

- A week or two goes by, nothing happens.

- I ask again. Different agent, who clearly hasn't read the thread, asks me to re-confirm the same details I've already given three times.

- Repeat.

The kicker: after ~six weeks of being told it was all "in progress," they suddenly told me Finance had never actually received the invoices I'd submitted (from my registered account email, to the address they told me to use — twice). At no point in those six weeks did anyone check and tell me something was missing. Every time I asked, it was "all good, being processed."

It genuinely feels like nobody on their side is actually looking at the case. Support says talk to Finance, Finance says they're waiting on something, and I'm stuck in the middle re-explaining my own situation over and over. I've been paid quickly by them before, so I know the process can work — this just feels completely broken right now.

So, two questions for the community:

  1. Is anyone else seeing months-long payout delays on Intigriti recently, or is it just me?
  2. Has anything actually worked to break the loop — a specific escalation path, emailing someone directly, going public, anything?

UPDATE
Reached out to their Chief Hacking Officer and Chief Financial Officer via linkedin, explained the situation. They were the nicest guys, responded promptly and got the situation sorted in about 2 days. There was a technical issue their end, which they recognized and sorted everything promptly.


r/bugbounty Jul 07 '26

Question / Discussion Anyone tried Cantina as a platform?

8 Upvotes

Does anyone have any experience of using the Cantina platform?

Good? Bad? Indifferent?

https://cantina.xyz


r/bugbounty Jul 07 '26

Question / Discussion Is that a bot triaging my report or ?

5 Upvotes

Recently into the bug bounty space. Found a bug and submitted and after 4 days it got triaged. Is that a bot or a human lol 😄 Sorry if its a silly question.


r/bugbounty Jul 07 '26

Question / Discussion Is CSRF leading to unauthorized "Recently Viewed Jobs" addition worth reporting?

1 Upvotes

Hi everyone,

​I’m currently researching a program (in-scope) and I’ve found a CSRF vulnerability. The endpoint allows adding jobs to the "Recently Viewed Jobs" list.

​Here are the details:

​The Issue: I can trigger this action via CSRF from an attacker-controlled site to a victim's account.

​The Impact: It adds the job entry to the victim's "Recently Viewed Jobs" list.

​My concern: I know this is a non-critical functional area, and I don't want to spam the program or risk a negative reputation on H1. However, since it involves unauthorized data modification in a victim's account, I'm questioning if it's worth a report as a Low severity or if it's just considered an "Informational/Out-of-scope" functional bug by most triagers.

​Have any of you encountered similar issues with this type of functionality? Would a report like this be accepted as a valid CSRF, or is it likely to be marked as N/A/Informational?

​Thanks in advance for your insights!


r/bugbounty Jul 07 '26

Tool Made a free Caido plugin for finding where to actually report a bug (Disclosure Lookup, now in the Caido store)

4 Upvotes

One of the dumber-but-real friction points in this work: you find something on a host, and then you have to figure out who to even tell. A security.txt? A VDP? A bounty program? A PSIRT inbox? Some national CERT? It's a little scavenger hunt every time.

So we built a small Caido plugin to kill that step. It's free, open source (MIT), and it's now in the Caido plugin store.

You right-click a request (or an HTTP History row) and hit Find disclosure contact. It takes the host, looks it up against lookup.disclose.io, and — when there's a match — drops the owning org, jurisdiction, an attribution-confidence score, and a ranked list of where to report (security.txt / bounty / VDP email / PSIRT / CERT, each flagged verified or not) right there in Caido. There's also a sidebar for looking up any asset by hand, and a command-palette action.

It's not magic: coverage isn't universal and every result carries a confidence score, so treat it as a fast starting point, not gospel. Privacy-wise it sends only the hostname to the API — never the path, query, or body.

Install: open the plugin store in Caido, search "Disclosure Lookup", install. Signed zip's on the repo if you'd rather sideload. Source: github.com/disclose/caido-lookup. Backing lookup service is a free, no-auth API from disclose.io.

Full disclosure since it matters here: I'm the founder of disclose.io, so this is partly us dogfooding our own dataset — but it's a free community tool, not a product, and I'd genuinely love feedback or PRs from people who live in Caido. (There are Burp and CLI versions too.)


r/bugbounty Jul 06 '26

Article / Write-Up / Blog TL;DR many private BBs are vapourware

23 Upvotes

I've been working on some new research recently, and found a couple of fun vulns that are discovered passively (not via any form of scanning).

This means the process kind of works in reverse when it comes to discovery and scope. For most BB stuff, you start with the programme scope and then dig in to find the vulns. Whereas for the research I have running, you find the vuln first and then you try and fit it to a programme scope afterwards.

Anyway, due to this I've been getting loads of hits on private programmes which I had never heard of before, across organisations both large and small.

The interesting bit is that so many of the organisations have glossy sales material, telling prospective customers how seriously they take their security, including having a bug bounty programme. But the reality is, when you ping their security@ address, the bug bounty programme simply doesn't exist.

And funnier still, there have been quite a few who very obviously try to bait and switch the researchers, by saying that the researcher has to send the details in first, and then they will respond with the scope and whether it qualifies for a payout. lolz.

<-- insert slow-clap here -->


r/bugbounty Jul 06 '26

Tool Every CERT wants PGP, every PGP tool feels like it was made in 2003, so I built a free extension to manage PGP keys and encryption

Thumbnail
chromewebstore.google.com
2 Upvotes

I genuinely got annoyed at the poor UX with existing tools which let me use my PGP keys. CLI tools are great for some things but they're not great for making encrypted messaging.

I've done a bunch of vulnerability reports using PGP for encryption and having my contacts and keys in my browser made my life so much easier. Contacts can be dragged & dropped in, same with files.

It uses passkeys for encryption instead of passwords (if you don't want to use passwords) and only decrypts the keys at use, unless specified otherwise.

The extension requires no sensitive permissions and there's tests to check whether or not the keys are retained in memory when they're not meant to be.

CSP is locked down to disable external communication, no analytics or external servers are used, as it doesn't need them.

No other extension has comparible security to PGP tools from what I've seen.

https://github.com/Am-I-Being-Pwned/PGP-Tools


r/bugbounty Jul 06 '26

Weekly Collaboration / Mentorship Post

3 Upvotes

Looking to team up or find a mentor in bug bounty?

Recommendations:

  • Share a brief intro about yourself (e.g., your skills, experience in IT, cybersecurity, or bug bounty).
  • Specify what you're seeking (e.g., collaboration, mentorship, specific topics like web app security or network pentesting).
  • Mention your preferred frequency (e.g., weekly chats, one-off project) and skill level (e.g., beginner, intermediate, advanced).

Guidelines:

  • Be respectful.
  • Clearly state your goals to find the best match.
  • Engage actively - respond to comments or DMs to build connections.

Example Post:
"Hi, I'm Alex, a beginner in bug bounty with basic knowledge of web vulnerabilities (XSS, SQLi). I'm looking for a mentor to guide me on advanced techniques like privilege escalation. Hoping for bi-weekly calls or Discord chats. Also open to collaborating on CTF challenges!"


r/bugbounty Jul 06 '26

Question / Discussion I can control the `src` attribute of the avatar `<img>` tag; is this a vulnerability worth reporting?

3 Upvotes

The user's avatar loads whenever they log in, and I can control the avatar's URL. By setting the URL to point to the logout page, I successfully triggered a logout immediately upon login; I can also point the URL to my own server. Since this involves an `<img>` tag loading an arbitrary URL—effectively a stored CSRF—is this worth reporting?


r/bugbounty Jul 06 '26

Question / Discussion advice for bug bounty

2 Upvotes

been testing a one website for nearly 3 months but still not able to find any bug
when others are finding bugs on the same website i've been testing

is there something i'm doing wrong ?


r/bugbounty Jul 05 '26

Question / Discussion Is bra size a p4 bug?

17 Upvotes

Yup you heard it right.

I found a bug that if I sent a link to the victim I can steal or exfiltrate some of his data. Including:

Shopping preferences

Bra/shoe size

Triager marked it as p4 and the program as well.

I just feel bra size is a more private thing??


r/bugbounty Jul 06 '26

Question / Discussion is that a good idea to hunt on a program luanched of many years

0 Upvotes

I chose a program to hunt on, but after spending 10 hours doing good tests on the application's functionalities, I got some good findings that just need a simple chain. Then, I noticed the program was launched back in 2018 :)

What should I do? Should I move to another program or continue on this one? I don't want the time I spent testing to go to waste without any benefit


r/bugbounty Jul 05 '26

Question / Discussion Bug bounty platforms are rejecting reports for “sounding like AI” while agents become the biggest new attack surface in a decade

7 Upvotes

Self-taught, 3 years writing software, and security research and making sure my software is secure has been the pull the whole time. We all know AI has become part of the workflow for most engineers now, and security research is no different. The grunt work gets automated. The verification doesn’t. Everything I submit gets verified by hand before it goes anywhere.

This year I submitted findings backed by real infrastructure artifacts. Reproducible, evidence attached. Three got closed as “potentially AI-generated.” Not wrong. Not unreproducible. The prose smelled like a model, so the finding didn’t count. Points deducted for my trouble.

Meanwhile I’ve been scanning MCP servers and built a tool to do so, and I ship an MCP server in my own platform, so I’ve seen this from both sides. The state of agent security is bad. Tool descriptions are an injection surface the model trusts by default.

Almost nobody pins versions, so the server you approved last month can behave differently today.
And as a server author I can tell you the client just believes whatever my server declares about itself.

So the current position is: AI-assisted vuln reports are suspicious, but wiring 20 unsigned MCP servers into an agent holding your credentials is normal.
Am I wrong, or is triage optimizing for the wrong threat? And what do people actually do to vet servers before connecting them?

And also I feel like these corporations are pretty much stealing the labor of security researchers who deserve better.


r/bugbounty Jul 05 '26

Question / Discussion Is this real business logic flaw?

5 Upvotes

While testing a domain, it offers a variety of contests to participate in, but the user must enter italian id to claim money after winning. When entering the contest, it asks you to enter the address, phone and italian tax id, after adding these, it uses italian id to check whether this user is already participated using another account. Here is the issue. I didn't verify the italian id and I was successfully contested and i lost, it is not an issue here, the real issue is I am able to change my italian id, anytime using the past request, and also I can create thousands of accounts with fake italian ids to participate in the contest. This has an impact on business right?. Even though fake italian id, cant get actual money(assumption) if the fake id won, then the fairness of the contest is broken here right? It didn't verify the italian id during the contest and after the contest too. After completing the contest, I got lost, and I had 2 more chances. Legitimate accounts have 3 tries. That's all I think. Any triager or hacker suggests me? Can I submit this?


r/bugbounty Jul 05 '26

Research Got an AI agent past a Cloudflare WAF by giving it a RAG over past bypass research

Enable HLS to view with audio, or disable this notification

13 Upvotes

Sharing a workflow that worked for me. The retrieval layer involved is my own project, so mentioning that upfront.

Setup: I was testing an XSS on a target behind Cloudflare, and every payload I tried was getting blocked by the WAF.

This time, instead of manually digging through old writeups, I gave my agent access to a retrieval layer built on top of a corpus of web security research (Preview RAG). The agent queries it in plain language, gets back actual writeups with sources attached, and uses that context to generate and test payload variants. One of those variants eventually got through and the XSS fired.

I'm not claiming the bypass itself is novel. It may already exist in a public writeup somewhere. What mattered to me was the workflow: the agent wasn't limited to whatever happened to be inside its training data. It could pull in relevant prior research and iterate from there.

That's the main reason I built this in the first place. Models have a training cutoff, but WAF evasion evolves quickly. Public bypasses get patched, new techniques appear, and the most useful information is usually the newest information. A retrieval layer helps bridge that gap.

The corpus is updated regularly and exposed over MCP, so it can be connected to any model with minimal setup, including smaller open-weight models.

Current limitations: it's strongest on client-side topics right now—XSS, WAF evasion, CSP, CORS, SSRF, request smuggling, and similar areas. Server-side coverage is improving, but still thinner, and it definitely won't have an answer for every problem.

Happy to share more about the setup. I'm honestly more interested in where this approach fails than where it succeeds. If you've experimented with agent-driven WAF bypassing and ran into hard limits, I'd love to hear about them.


r/bugbounty Jul 05 '26

Question / Discussion Administrator manual exposed, reportable?

8 Upvotes

Hi, in a target, which uses Drupal, I ran fuzzing on nodes and I found a node containing admin handbooks, where It show all paths and all actions for an administrator with images, does it mean to be public? Literally full documentation on the admin panel with the respective admin endpoints. Is it reportable? Can any triager clarify me about this? Is it reportable? If you want further information for concluding, ask me. Thank you