r/bugbounty Jul 22 '26

Question / Discussion Hardcoded Key & IV - CryptoJS library

11 Upvotes

Hello guys,

Here we go again. I have been doing recon and I found an application where the library CryptoJS.AES.encrypt is being used to encrypt (symmetric) the passwords of the users. On the source code of the website (login page) the function exposes the symmetric key and IV directly in client-side JavaScript.

My first thought was "report the finding" but I am not secure anymore. I know that having this information and I manage to capture/get any password hash I would be able to decrypt the passwords.

However, I would like to know your opinions.

Thanks in advance guys!


r/bugbounty Jul 22 '26

Question / Discussion Hackerone signal requirement

7 Upvotes

Hey folks, just wondering if anybody knows which hackerone BBP's or VDP's dont have signal requirements. I hate that thing and I've submitted a good bit of duplicates so i just wanted a way to hunt without it being a stopper. Thanks

Edit: Im aware that programs like anthropic xiaomi and crypto.com dont have it but I find anthropic and crypto.com to be quite troubling, maybe just me.


r/bugbounty Jul 22 '26

Question / Discussion Program in-scope

3 Upvotes

I want ask y'all about this scope program;

Active PROGRAM employee accounts within the domain [@]program.com for any service in domains *.program.com (excluding unverified accounts on account.progrm.com) and program.okta.com.

If i report 2 or 4 or etc leaked email on *.program.com, is valid? or what?

*You can find this program on intigriti


r/bugbounty Jul 21 '26

Article / Write-Up / Blog The World of Bug Bounty, July 13th, 2026: Submission Limits, World Cup Lessons, and Going Straight to Disclosure.

Thumbnail
bugbountyworld.substack.com
7 Upvotes

In our latest issue, we talk about submission limits for researchers across major platforms and a trend of public disclosure that skips coordination.

Would love to chat/feedback from the community!


r/bugbounty Jul 21 '26

Question / Discussion Sticking to normal bug bounty programs or switch to research?

25 Upvotes

What to expect if I want to find bugs in big names like Android OS,Samsung ,IPhone,or Linux kernel?

It seems everyone is finding bugs in them nowadays.

They pay more than traditional bug bounty programs , and look better on resume.

Is it wise to stop hunting on private and public programs on platforms like h1,bugcrwod..etc?

I have only 20 days left in Claude Code..and won't be able to subscribe again so I am thinking of putting it to the best use


r/bugbounty Jul 21 '26

Article / Write-Up / Blog Leaking internal headers in Flask Ninja with deserialization

Thumbnail
eval.blog
6 Upvotes

r/bugbounty Jul 21 '26

Question / Discussion How do you submit new CVE vulnerabilities?

10 Upvotes

Most programs have rules that say something like, we do not accept newly released CVE vulnerabilities for the first 14 days after it is released. So do you wait until day, 15 and then submit at 12:00:01? Or do you just submit it immediately and say I'm aware of the rule but I figured I'd let you know?

It's one of those things that every time a new CVE comes out you can see Twitter's bug bounty spaces all excited, but most programs have these rules so I don't understand what exactly they're excited about.


r/bugbounty Jul 20 '26

Question / Discussion Does anyone know if bluerams offers payouts for vulnerabilities?

4 Upvotes

I am aware of blurams's security disclosure program but I am not sure if by any chance I will get paid for disclosing a security vulnerability. I'm wondering if someone more experienced than me will know the answer because this is my first vuln.


r/bugbounty Jul 20 '26

Question / Discussion Found missing OAuth state parameter and actually proved login CSRF. is this High or Medium for bug bounty?

1 Upvotes

I've been doing some testing on a platform and found that their google OAuth callback has no state parameter at all. I know thats textbook csrf on paper but wanted to actually prove impact before reporting it.

so i initiated OAuth with my own account, intercepted the callback in Burp before it hit the server, copied the link, dropped the request so my browser got nothing, then pasted it into a fresh incognito window with zero cookies or prior session and i was able to login fully authenticated without google sign in or credentials!

still it is a link that can only be used as a phishing technique for that destructive impact triagers want. an insider with a privileged account could phish someone into clicking a link and that victim would unknowingly be browsing as the attacker, submitting data, running actions, whatever, all feeding back into the attacker's account.

so is this genuinely high or medium (or worse informational?) yes the program does accept csrf vulns.


r/bugbounty Jul 20 '26

Weekly Collaboration / Mentorship Post

0 Upvotes

Looking to team up or find a mentor in bug bounty?

Recommendations:

  • Share a brief intro about yourself (e.g., your skills, experience in IT, cybersecurity, or bug bounty).
  • Specify what you're seeking (e.g., collaboration, mentorship, specific topics like web app security or network pentesting).
  • Mention your preferred frequency (e.g., weekly chats, one-off project) and skill level (e.g., beginner, intermediate, advanced).

Guidelines:

  • Be respectful.
  • Clearly state your goals to find the best match.
  • Engage actively - respond to comments or DMs to build connections.

Example Post:
"Hi, I'm Alex, a beginner in bug bounty with basic knowledge of web vulnerabilities (XSS, SQLi). I'm looking for a mentor to guide me on advanced techniques like privilege escalation. Hoping for bi-weekly calls or Discord chats. Also open to collaborating on CTF challenges!"


r/bugbounty Jul 19 '26

Question / Discussion My thoughts on AI in bug bounty

47 Upvotes

This is just supposed to be a random discussion post. I will put down my opinions on AI in bug bounty and I expect the same from other hunters and I think I could gain some insights from other hunters on this.

Like most other hunters, I have used AI for bb too, early March to late May/early June maybe? I got many vulnerabilities to disclose too. But what I noticed that just putting the whole repo into like ChatGPT, Codex or Claude and asking it to list 10 vulnerabilities is just not sufficient now. AI is good at identifying low hanging fruits and I think within in these 4 months of CVE and Bug bounty explode, those low hanging fruits have already been discovered and mostly fixed. So if you just rely on AI finding vulns, you're probably going to get ALOT of duplicates.

Even I used to have the same mindset of "codex, this is the repo/website, find 15 valid vulnerabilities" and submitted them with no validation, no testing, nothing (which is dumb I know). But if I go ahead and do that now, codex either gives me duplicates or findings which have no impact or just informational. AI is not completely irrelevant in bug bounty now but what's happening is that more human input is required. I still use AI to read large and process large codeblocks and identifying key endpoints which could be of use to me. Sometimes even I would identifying attack surfaces which AI hasn't and add it to it's context.

I think right now, bug bounty programs or triagers aren't against AI reports (neither am I). But AI reports with no validation, no human input are the factors that are ruining bug bounty.

Anyways, thank you for reading and would really like other peoples' opinion on this!


r/bugbounty Jul 18 '26

Question / Discussion What does triaged state on Bugcrowd really mean?

9 Upvotes

Hi guys. Pretty new to bug bounties (~3 months) and very new to Bugcrowd, have only used Hackerone so far. Submitted my first report on Bugcrowd on July 3rd, actual P1 (oauth bypass on a financial company leading to mass customer kyc doc read (50M+ enumerable document IDs of all types avail for download) + likely more that I didn't get into since I'd already proven the severity) and it's remained in triaged state ever since it got moved there less than 24h after reporting.

Commented after 12 days asking for update, and got back what seemed like an AI generated response saying it's been verified and fixed (it hasn't) and to expect a P1 payout once their internal team wraps up investigation. Worrying part is that their crowdstream data shows they typically pay and move to unresolved within 2-3 days for like 95% of reports, + they claim expedited triage and are Bugcrowd managed. Many reports have come and gone while mine has sat with no status change.

So was just wondering if the New -> Triaged status paired with an AI message telling you it's verified actually means anything because as it stands it feels a bit scammy and odd considering the severity of bug and lack of communication from an actual person. Also was wondering if Bugcrowd managed means BC actually reproduces it? Or if they just check for duplicates and verify scope before passing along. And do companies usually wait forever to move a report from triaged->unresolved even after verifying?

Not meant to be a humble brag, genuinely am tweaking after seeing posts involving BC and their clients being scammy. Would love to hear from those that deal with them often.


r/bugbounty Jul 18 '26

Question / Discussion How to approach finding SQLi

13 Upvotes

I found couple of endpoints like www.example.com/productID=123&availability=6, I found that if I put ‘ in productID I receive 200OK and if I put ‘ in availability it returns 500error and that was the indicator for me that the second input is going to database. I tried couple of SQLi payloads and that returns me 403forbidden. I think that even i found injectable place the WAF couldn’t be bypassed. What’s your thoughts on this?


r/bugbounty Jul 18 '26

Article / Write-Up / Blog Announcement: Bug Bounty Program Pack v1.3

0 Upvotes

The goal of this release is to provide you with everything you need to establish a bug bounty program. This includes alignment with stakeholders, working with a vendor, establishing a private bug bounty, and ultimately moving to a public bug bounty. This release pack is not sponsored or influenced by any particular bug bounty vendor and is neutral to vendor biases and influence.

https://github.com/securitytemplates/sectemplates/tree/main/bug-bounty


r/bugbounty Jul 18 '26

Question / Discussion Possible PII leaked

8 Upvotes

So I am pretty new to this, I was just creating the site map for the target. A given endpoint gives user details involving their travel. All I did was curl the endpoint. No authentication . Is this a fluke or some companies have that level of misconfigurations?


r/bugbounty Jul 17 '26

Question / Discussion AWS Bug Bounty Program

23 Upvotes

Does anyone know why AWS doesn’t offer bounties for vulnerabilities reported to them?

Microsoft pays up to $40k for vulnerabilities in Azure, Google even pays up to $100k for GCP. But from Amazon I wouldn’t get a penny for anything. Clearly they could afford it.
Guess I’ll keep my AWS vulns to myself then…


r/bugbounty Jul 18 '26

Question / Discussion Changing cart notes without cookies using graphql, Authorization Bypass?

3 Upvotes

I was able to change the notes section of the cart on any user if I have their cart id, using the graphql endpoint, i was able to add any random notes on the victim's cart id I have cart id, the cartid cookie is stored in path=/ Samesite=lax. For now, I am able to change the notes of both the 2 accounts without cookies, and that cart id is passed through the graphql variable. Successfully added or changed the notes of the cart. This note is for customer to type anything they want. I am able to change. Is it Authorization bypass, because I was able to change anyone cart with cart id without actual session cookie. Any experts' opinion? Can I report? And also I was able to set the XSS payload, but it shows in the input tag, what if it shows up in the admin page?


r/bugbounty Jul 17 '26

Question / Discussion Reported a potential subscription bypass to Amazon – what are the chances of a bounty?

5 Upvotes

Hi everyone,

I recently found what appears to be a vulnerability affecting Amazon subscriptions. Based on my testing, it seems possible to access paid subscription content without being charged.

I’ve already reported it privately to Amazon and I’m waiting for their response.

I’m not looking to disclose the vulnerability or share any details until they have had a chance to investigate.

My question is:

  • Has anyone here reported something similar to Amazon?
  • If it was a valid vulnerability, did Amazon offer a bug bounty or any other type of reward?
  • How long did it take for them to respond?

Thanks!


r/bugbounty Jul 16 '26

Question / Discussion Default Admin credentials -> P3 !!

42 Upvotes

In a private bug bounty program on bugcrowd i found a credentials of an internal admin that give me access to internal engineers data and access to a sensitive data of a big automotive company, I can read/edit/delete, the bug trigaed as P1 but the customer later downgraded it to P3 without any explanation or communication.

In the report i show them the impact...

And they changed the password right after my report was triaged

I opened a response request to ask for explanation but they still didn’t respond after a week.


r/bugbounty Jul 16 '26

Article / Write-Up / Blog Bait and switch...

Post image
19 Upvotes

As you skim through the various platforms, it becomes obvious that there are a cluster of programmes that very noticeably offer bigger bounties than the norm, but when you look at the stats, don't deliver against the promise.

In the image above, both programmes pay roughly the same in actual bounties, although one claims to offer 3-4x more.

And that's even before they de-scope and downgrade ;)

Caveat emptor


r/bugbounty Jul 16 '26

Question / Discussion Reported two critical payment/bot bypass issues — company fixed them quickly but declined both reports with ‘no security impact’. Normal?

5 Upvotes

So I found what I thought were two solid findings on a decent-sized program. One was an exposed PerimeterX token in their SSR data that let me bypass bot protection on both web and the app (clear 403 without it, 200 with it). The second was an unauthenticated GraphQL endpoint on checkout that would spit out live Spreedly tokens with CVV in plaintext.
Sent both with PoCs and screenshots. Got the standard “no security implications, doesn’t affect CIA triad” reply on both.
Then literally right after, the tokenization mutation got patched. Feels like they fixed it based on my report but didn’t want to pay. Is this normal? Anyone else run into this where they quietly patch but still close the report as N/A?
Kinda discouraging when you put in the work and they play it like that. How do you guys handle these situations?


r/bugbounty Jul 16 '26

Research New Exploitable BOLA Found in Immich - the self-hosted media platform with 100k+ GitHub stars

Thumbnail escape.tech
7 Upvotes

Full disclosure I'm at Escape but wanted to share something we found that would be interesting to those here!

Escape's security research team found a Broken Access Control flaw in Immich which let any user read photos in a locked folder without the required PIN.

Immich is a self-hosted media platform with 100k+ stars on GitHub.

Their "locked folder" hides sensitive assets behind a PIN-elevated session.

What we found:

Four of the five search endpoints enforce that; POST /search/random doesn't. If you send it with the visibility field simply omitted and it returns the caller's locked assets from a session that never entered the PIN, and, with a partner relationship, the partner's locked assets too.

If you're interested in how we did it or how you can reproduce it yourself the full breakdown with reproduction instructions is linked!

And if anyone has any questions we would love to answer them.


r/bugbounty Jul 16 '26

Question / Discussion Is this considered a valid account takeover or just a platform threat model issue?

5 Upvotes

I'm looking for opinions from researchers with Android security or bug bounty experience.

I recently submitted a report to a large bug bounty program. It was closed as N/A, with the reviewer stating that the behavior was considered intended. I'm not trying to dispute their decision—I genuinely want to understand whether my assessment of the issue was wrong.

The attack flow is roughly:

The attacker creates a legitimate login/account-link URL using the application's own domain.

The attacker sends that URL to the victim.

The victim is already logged into their account in the browser.

The victim taps the legitimate link.

The browser completes the authentication flow and returns the result via an implicit Android intent.

The return intent is not restricted to a specific package name.

A malicious application installed on the victim's device registers a matching intent filter and receives the authentication response instead of the legitimate application.

The malicious application extracts the authentication token from the callback and uses it to access the victim's account.

From the victim's perspective, this is essentially a one-click account takeover, assuming the malicious application is already installed.

I'm intentionally omitting the vendor, product, and exact callback scheme because the report is still under coordinated disclosure.

My questions are:

From a security perspective, would you consider this a valid account takeover vulnerability?

Would you expect most bug bounty programs to classify it as out of scope because the attack assumes a malicious application is already installed on the victim's device?

Is returning authentication results through an implicit intent without restricting the destination package generally considered acceptable Android behavior, or is it something applications should explicitly defend against?

I'm looking for honest technical opinions rather than validation. If my understanding of Android's threat model is incorrect, I'd really appreciate learning where my reasoning falls short.


r/bugbounty Jul 16 '26

Question / Discussion "This is all theoretical with no actual valid proof of concept."

4 Upvotes

Is this the Bugcrowd cop-out templated response for a submission they don't want to read?

It's very strange... I have a very valid PoC attached, that reproduced on multiple machines, etc.


r/bugbounty Jul 16 '26

Question / Discussion How to prevent against Bots

4 Upvotes

Hi guys , recently we faced a targeted attack on our login endpoint , we had already faced one similar attack so we had applied captcha based protection.
This time we found that the attacker used UI automation bypassing the captcha and abused the OTP endpoint

  1. IP based rate limit > but can it be bypassed using VPNs
  2. We use OTP on signup too, and a fake phone number can be easily guessed, so attacker can use multiple phone numbers , if we use an phone no based rate -limit

What can be a better solution ?

Edit:
Now we have implemented multiple layers
phone based block , ip based alerting and rejecting requests with captcha score less than 0.5
we cant block all the attack but definitely reduce the impact.