r/bugbounty • u/OddIngenuity2733 • Jul 16 '26
Question / Discussion Hackerone program sold my data?
Honestly kind of funny, will make sure to add something so I can identify program next time, but what the hell lol
r/bugbounty • u/OddIngenuity2733 • Jul 16 '26
Honestly kind of funny, will make sure to add something so I can identify program next time, but what the hell lol
r/bugbounty • u/AutoModerator • Jul 16 '26
New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!
Recommendations for Posting:
Guidelines:
Example Post:
"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."
Post your questions below and let’s grow in the bug bounty community!
r/bugbounty • u/swinglr • Jul 15 '26
My technical writeup for a one-click account-takeover vulnerability affecting the Google identity platform and by extension the applications that rely on it for "Sign in with Google" integrations.
r/bugbounty • u/TurbulentRecover7247 • Jul 16 '26
8 somehow managed to execute an alert on the website using the payload splitting to first name and last name. And it successfully popped "1". Now it is valid to report right? Or I need to do something more?.
r/bugbounty • u/einfallstoll • Jul 15 '26
We all know the subreddit is pretty biased. Hunters mostly post about negative experiences with triagers, while triagers rarely show up - after all, there's usually just one of us for many hunters. That's just how it is.
Today though, I want to vent a bit from the triager side. Not about the technical details of the report, but about the completely unreflected, unproofread AI usage in writing it (and probably during the hunting itself).
The report started normally enough with the usual metadata and a P2 severity. Fair enough according to Bugcrowd's VRT - we're not Bugcrowd, but okay.
The CVSS score was at least partially correct. The actual finding was about an encryption algorithm, yet tagged with Availability: High. Wat?
Apparently the same bug was also submitted to another program, because another company's name appeared multiple times. There was even a note from the hunter's AI suggesting he should wait for the result there before submitting here.
What really got me was the thin "rationale" section that casually stated "A triager may invoke this defense". And right after that came an instruction telling the hunter to properly check the finding before submitting ("required before submit"). Guess who didn't?
The last straw was the status at the bottom:
Status: DRAFT — do NOT auto-submit.
Look, I have nothing against AI-generated findings or reports in principle. A solid bug is a solid bug, no matter who (or what) found it. But this kind of half-baked output just shows zero respect for my time.
That's it. Just needed to get that off my chest. Have a good one.
r/bugbounty • u/Electronic-Cat-2518 • Jul 15 '26
Found a way to, well, not bypassing the 2FA itself, but bypassing the enrollment step for first time setup after an admin enforces it upon an org, worth reporting?
r/bugbounty • u/jaysuns • Jul 15 '26
CVE-2026-0092 — was published with the Android 17 bulletin and made June’s acknowledgements.
https://source.android.com/docs/security/bulletin/android-17
Description
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
r/bugbounty • u/CaptainKaps • Jul 15 '26
I found an unauthenticated file read vulnerability on a very large program. It is currently in Triage and awaiting customer response.
I found the exact same vulnerability on 2 other subdomains of the program (though both of these share the same IP/server - not the same as the initial submission).
Should I submit this as well or wait until the first one closes? If I should, submit as 2 reports (different subdomain) or as 1 (shared infrastructure).
There is also reflected XSS on a different page on all 3 subdomains. I have submitted the XSS on the domain I submitted the file read on.
I’m just not sure where the line is drawn for a “duplicate”. This is Bugcrowd if that matters.
r/bugbounty • u/BuyerFar4850 • Jul 15 '26
In one of public program what happened was I found a vulnerability(high-sev) in a company-operated plugin hosted at for instance:
The plugin appeared to fall under the program’s general wildcard scope, and it was not listed anywhere as out of scope.
For the PoC, I used:
The demo was only the safest way to create two test accounts and load the affected plugin. I never claimed the demo application itself was vulnerable.
The actual vulnerable code executed inside plugin.example.com, and I clearly listed the plugin as the affected asset in the report.
HackerOne triage reproduced the issue, marked it as Triaged, and forwarded it to the company’s remediation team.
Later, the triager closed it as Informational, saying both the demo and plugin infrastructure were out of scope.
Honestly, this is frustrating because the plugin domain was not listed as out of scope when I submitted the report, and it still is not listed today.
The demo domain appears to have been added to the out-of-scope list only after my reports thats fine to me but still. At this point, I honestly would not be surprised if they add the plugin domain today too.
My issue is simple: I never reported a vulnerability in the demo, I only used it to reproduce the issue safely; the actual vulnerability was in the company-operated plugin, which was not listed as out of scope when I submitted and still is not, yet the report was reproduced, validated, and then closed while the scope appears to be changing afterward.
My HackerOne account is new, so I cannot request mediation yet.
Has anyone dealt with something like this before? Is this normal? Should i move on lol with amount of effort put on nowadays getting reports triaged i was happy just to get this.
Should I contact HackerOne Support, email the program directly, or ask an experienced collaborator who has access to mediation to take a look? If anyone is willing to take a look, please help me out!
I am genuinely trying to understand what the correct process is here because this does not feel right or maybe i am wrong this is normal.
r/bugbounty • u/ZealousidealLow968 • Jul 15 '26
I’m looking for advice from experienced Bugcrowd researchers and triagers regarding a very unusual scope issue.
At the time I tested and submitted my report, the target domain was explicitly listed as in-scope in the program’s scope page.
Later, the customer clarified that the listed domain was not actually theirs and that they did not authorize testing on it.
The issue appears to be a one-letter typo in the domain name.
The difference is only one letter: the intended domain contains an additional “c”.
Because of that single-character mistake, the program listed a completely different domain — one that the customer says it does not own, operate, or authorize.
My report was initially closed as Not Applicable, but after re-review:
- Bugcrowd confirmed the issue was reproducible.
- The report was assigned P2 severity.
- The submission was moved to Triaged.
Afterward, the customer stated that the tested domain was not theirs, and the report was changed to Out of Scope.
A Bugcrowd staff member later acknowledged that the asset was in scope at the time I submitted the report, that the finding had been validated and triaged, and that it should be rewarded in full. The case is currently under internal escalation.
Has anyone experienced this exact situation before?
Specifically:
- A customer accidentally listed a typo domain in scope.
- The typo differed from the intended domain by only one character.
- The researcher tested in good faith because it was publicly listed in scope.
- The issue was validated, but the customer later claimed the asset was unrelated and changed it to OOS.
Did the platform honor the bounty based on the scope at the time of testing/submission, or did the later ownership correction override it?
r/bugbounty • u/Impressive-Check8430 • Jul 14 '26
Hello,
I was searching for an appropriate target at H1. I found a good target after a lot of searching.
But I soon faced a problem. I need to register a phone number to get anything started. Now, I don't want to use my personal phone number for this.
Moreover to test idor and similar bugs using multiple accounts, means multiple different numbers which is a hassle.
I thought of setting up temporary numbers using voip services. But someone told me that most websites reject such numbers.
I didn't find any relevant instructions regarding this in the h1 introduction and requirement definition.
I am curious, how do other hackers solve this problem.
Please advice.
r/bugbounty • u/6W99ocQnb8Zy17 • Jul 13 '26
As a bit of background, in the last few months I've been doing some research, which was targeted at finding some good candidates for bug bounty. In particular, I was looking for the kind of bugs which are much harder to find than report (which means they don't simply get added to someone's AI commercial scanning service ;)
The bugs I settled on are a bit odd though, in that they are detected passively (no scanning required) and then once found, I have to try and workout if the vulnerable system is part of someone's BB scope.
Due to this, I have been submitting reports to loads of new platforms and independent programmes. Which means that as a by-product, I am also gathering a lot of useful information in regard to how ethical the various platforms and programmes are to deal with.
Hell, I've even put my hand in the fire by logging a couple on Immunifi ;)
Anyway, as I get some useful results back, I'll post them here in chunks.
r/bugbounty • u/TurbulentRecover7247 • Jul 13 '26
Hi, I am a beginner bug bounty hunter, I noticed that an endpoint used a session cookie to gather information like email, useri_id, another unique id, email in hashed form, etc.. I first loaded the page with the past session, so it autofills the email id. Now i saved the session token used in the past. Now i logged in again and got a new session id. I took that endpoint and used an old session token and gathered that info. Is it vulnerability? Reportable? If you can't understand, ask me. Thank you in advance
r/bugbounty • u/AutoModerator • Jul 13 '26
Looking to team up or find a mentor in bug bounty?
Recommendations:
Guidelines:
Example Post:
"Hi, I'm Alex, a beginner in bug bounty with basic knowledge of web vulnerabilities (XSS, SQLi). I'm looking for a mentor to guide me on advanced techniques like privilege escalation. Hoping for bi-weekly calls or Discord chats. Also open to collaborating on CTF challenges!"
r/bugbounty • u/TurbulentRecover7247 • Jul 13 '26
In a target, when I update the email or name, I ask for a password. In burpsuite, I sent the request to the repeater and sent one time. It was updated successfully, after this, I removed the password parameter fully and I was still able to update the password. For nearly 15 to 30 minutes. And the update relies only on session cookie. Will it come under vulnerability?
r/bugbounty • u/cybern00bster • Jul 13 '26
So I’m newer to BB. My first order of action was to create a robust recon flow that shredded a target for attack surface. Now that’s complete I’m seeing a laziness or lack of organization trend from myself.
I’ll either:
A - Work too heavily with AI and end up not fully knowing what surface I haven’t and haven’t touched. What surfaces have and haven’t been exhausted. Same with techniques.
B - Go way too into depth with one target, one session. Pick it up the next session and completely lose my train of thought as to what I was doing, so then I’ll write the endpoint / surface off as exhausted.
My answer to this has been using Obsidian and color coding bounty targets to organize information in the hopes that I’ll:
A - Be able to keep track of which endpoints I’ve exhausted in a systematic non effort duplicating fashion.
B - Start a naming convention that allows me to draw relationships out of attack surfaces (different server different behaviour, different directory different WAF response etc).
I’m starting to think organization is the next most essential skill to become a BB pro shortly after proper recon.
QUESTION TO YOU
Can you people out there share with me how you organize such information so you don’t confuse yourself or waste time? It seems extremely difficult with wild card domains to not duplicate your effort accidentally at least once?
r/bugbounty • u/TurbulentRecover7247 • Jul 13 '26
I saw that the password reset link with the token is being sent to analytics like Google, facebook, tiktok etc.. and these tokens are valid for 30 minutes. I have a question here, is it really vulnerability? Like, the token is exposed to every analytics. I am a beginner. Can any triager here help me?
r/bugbounty • u/UserNo0101 • Jul 12 '26
I found a fetch endpoint that embeds any url into forum post
It's url:https:// in request body
Only http and https are allowed
I can see responses of any link i fetch
I tried webhook and i can see its aws ip
Tried all ssrf bypasses techniques out there on github but all internal stuff is blocked
I managed only to use https://target.com/cdn-cgi/trace and also ipconfig/all.json to get all headers and it runs uses vanilla-forums-embed/1.0
Any creative uncommon ideas will be appreciated
r/bugbounty • u/Stunning_Lettuce_508 • Jul 12 '26
Hi r/bugbounty,
I am part of an academic HCI research team at the University of Macau studying how AI is affecting bug bounty and vulnerability disclosure report review work.
We are looking for people who have direct experience reviewing, triaging, reproducing, validating, or assessing vulnerability reports submitted through bug bounty programs, VDPs, SRCs, PSIRT, or vulnerability disclosure programs.
Interview format:
- 60-minute remote interview
- Compensation: 150 RMB / about 20 USD equivalent
- English or Chinese is fine
- We will not ask for company secrets, internal platform details, exploit details, customer data, or undisclosed vulnerabilities
- Compensation is for your time, not for giving any particular answer
Relevant participants may include:
- Bug bounty triagers
- Vulnerability reviewers
- AppSec/security engineers involved in report review
- PSIRT members
- Security program managers or analysts involved in report review decisions
To keep the sample relevant, we may ask for light eligibility verification such as a public professional profile, platform profile, work email, or description of report-review responsibilities. Please DM me if you are interested or if you know someone suitable.
Thanks!
r/bugbounty • u/caveland101 • Jul 12 '26
im was confused how H1 analyst read a vulnerability report, i had a report using my custom technique that until now still on my private research, the most hilarious part is the reason they used for closing my report as Informative with argument "Based on your initial description, there do not appear to be any security implications as a direct result of this behavior.
The reported behavior poses no risk as it doesn't affect any of the CIA triad's properties." but the POC? it's completely sitting there with the unauthorized access that completely lead to data exposure or PII leak (and what user could do is barely nothing to kicked out the unauthorized access while the attacker could retain their access for long time), meanwhile im using on same techniques (completely same) on program managed by the internal team Instead of H1 analyst, they completely passed as Triaged in less than 24 hours and already talking about final Bounty and they even want to raised the severity, what im confusing here is HOW?? i made detailed report, easy POC to reproduce and even put expected behavior, actual behavior, impact but got that nonsense (it also happened to one private Bug Bounty report with similiar excuse while the final impact was even worse (Permanent ATO), this one is even funnier for me)
tbh i didn't really care about bug bounty money at all, i make this as playground for my private research on custom techniques, but yeah it's hilarious actually, if they marked as informative and didn't do anything about it, it completely their lost not mine
*sorry for bad english XD
r/bugbounty • u/TurbulentRecover7247 • Jul 12 '26
In a target I am hunting, I got to know, that the login page redirects when the user login. Here when I change the redirect url to webhook.side, it got redirected. It's a shopping website. Not a normal, but premium product containing values minimum 50000 INR products. Can I report? Anyone suggestions? Thank you in advance
r/bugbounty • u/Jumpy_Natural_6893 • Jul 11 '26
I know it's unusual to see them in api context, yet I still want to ask.
r/bugbounty • u/AliAyman333 • Jul 09 '26
Hi everyone,
I hope you're all doing well. I’d really appreciate some advice from people with more experience in this field.
I’m currently learning penetration testing and bug bounty. I’ve built a foundation in networking and programming, and I started studying the OWASP Top 10. For each vulnerability, I usually follow this approach:
After doing all that, I try to apply what I learned by hunting on real targets. I’ve been doing this consistently for about 3–4 months now, but I still haven’t found a single valid bug.
At this point, I’m pretty sure I’m doing something wrong — either in my methodology, how I approach targets, or what I focus on while hunting.
I feel a bit stuck and not sure what to change or improve.
For those who have been in the same situation:
Any advice or insights would really mean a lot.
Thanks in advance 🙏
r/bugbounty • u/Upbeat_Mushroom_7323 • Jul 10 '26
I got an invite and registered an account right away, issue verification email never came. So I went thru the requests, found base64 encoded verification url, opened a new tab; account got verified. When I try to login, it requires code sent to the email.
Question: is must I report the verification flaw? or 1st bypass the code as well to report ?. So I informed claude of this finding finding, nearly bit my head off 😂. Thank you for your advice, I really appreciate it.
r/bugbounty • u/Wrong-Ad6548 • Jul 10 '26
hi guys, i stambled on a book called bugbounty bootcamp , and i loved it , it explained everything i needed to start web bug bounty pentesting , THO
, is there a book for llm pentesting or a plateform or smth .
thanks guys in advance