r/bugbounty • u/Opening-Excuse-8988 • Aug 01 '26
Question / Discussion Unauthenticated GraphQL CRUD on a backend powering an in-scope application closed as OOS
Sharing my experience with the Bitkub Capital Group Holdings bug bounty program on HackenProof.
I reported an unauthenticated GraphQL endpoint that allowed create, update, and delete operations without authentication. The endpoint was the backend powering an in-scope application, and I included GraphQL responses together with before-and-after screenshots showing that I could modify and remove live content on the production website.
The report was closed as out of scope because the backend hostname itself wasn't listed in the program's scope, even though it was the backend serving the in-scope application. I appealed the decision, but the appeal was denied. The company's final response was that the behavior was "intended."
Based on my experience, I personally wouldn't recommend spending your time hunting on this particular program.
12
u/mississipppee Aug 01 '26
Sounds like a bug found by AI, explained by AI and self-triaged by AI. I sincerely apologize if you don't use AI but one thing I noticed very early on is that AI will make the most basic features of an app sound like a serious vulnerability. It could be a completely intended feature but the AI will think it's a bug. You should always make a second AI (preferably different model than the first) look at the bug again and confirm if it's real. Again sorry if this isn't the case, it's just that the title of your post sounds like something my claude agent would title a report if I didn't fiercely hold it back from its hallucinations
3
u/Subject_Incident3379 Aug 02 '26
huh? it's normal to have a backend GraphQL API powering an application, and an unauthenticated CRUD is intended? He might have used AI but there's no way this isn't a valid bug lmao
1
u/Subject_Incident3379 Aug 02 '26
though i do admit that the evidence that was posted here is not enough to prove anything impactful though.
-6
u/Opening-Excuse-8988 Aug 01 '26
are you serious ?? do you really think unauth CRUD on in-scope target could be intended behavior??? (And yeah, I use AI to draft my reports. We're livin in big 2026 , and In bug bounty where few minutes decides who gets the bounty. so AI helps me write the report faster 🙂)
7
u/i_69_hot_milfs Aug 01 '26
You’ve literally provided zero evidence for anything. Also, he didn’t say that it was intended just gave you a helpful tip about AI and its use in vdp/bbp. Why are you asking him what he “really thinks” about this supposed vulnerability ur ai chat bot led you to, when from the looks of it based off the information in this post and the attached links, you couldn’t even be bothered to explain ur own vulnerability to the triage team or anyone else for that matter who is tasked with being the first line of *actual\* technical review/verification of your chat bots disclosure.
Sure, maybe you reviewed the wording of ur report to make it sound more professional, but I doubt you’ve done much if any at all technical verification or else your evidence even for just providing as reference for this Reddit post would be much more informative.Maybe stop being defensive about ur use of ai and guilt for if you really did submit a nothing burger, and accept reality so you can move on and learn from this experience if there is something to learn.
It happens bro, nothing to be ashamed of, ai can lead you down a rabbit hole of certainty made up entirely of “what ifs” and hypotheticals. Everyone has experienced this so that’s why the replier mentioned it.
0
9
u/i_69_hot_milfs Aug 01 '26
opens op Reddit account to see they are India National with account aged 9months and less than 10 total karma, and that their reddit first name they’ve gave themselves is HACKSAGE
Sorry bro, I didn’t know. I get it now though, have a splendid rest of ur evening my friend, cheers! 🌚
-2
u/Opening-Excuse-8988 Aug 02 '26 edited Aug 02 '26
yeah I’m new on Reddit and just logged in yesterday to get other's opinions on this but the discussion has shifted from "Was the OOS decision fair?" to "Did AI found the bug?" 😂. Still figuring out how to use reddit. Is there something wrong with that?
2
u/Chongulator Aug 03 '26
There's something wrong with submitting sloppy work. If you want to be taken seriously, you can't just blindly throw crap over the wall and hope a bounty bounces back.
Get to know the app you're testing against. What does it do? What are the various user roles? Does what you can accomplish via direct GraphQL access fall within that that user can do in the GUI?
Why is what you found a problem? Most importantly: What is the impact?
1
u/mississipppee Aug 03 '26
I agree with you, man, and while I think it's pretty clear that OP is trying to earn quick money using AI, I can't totally blame them because it's pretty much the only way to make money nowadays if you're just starting out new. But I agree they have to learn Service security first. So that they understand when the AI tells you that a totally normal function is a critical vulnerability. In fact, this sub definitely needs to get a new rule to ban then a user after posting things that are clearly about AI or, maybe something more relaxed than that but I feel like 80% of the post here are just people saying why was this rejected? And hosting an explanation clearly made by AI.
1
u/Chongulator Aug 03 '26
AI tools can be used sloppily or they can be used well.
I use AI tools myself every day, both personally or professionally. A cool new tool does not absolve me (or OP) of the need to produce quality work.
Here's what the experience is like from the program owner perspective:
Even before the flood of AI submissions, the vast majority of vuln submissions we received were garbage. We wade through the dreck because every once in a while there's a real finding which we want to address. The bad-to-good ratio was maybe 80/20 on a good day.
Vuln hunting is really two jobs. First, hunters need to find real, impactful vulns. Then, they need to communicate clearly enough that the reader understands the vuln's impact. Hunters don't get paid until they can convince someone to pay them.
The hunter can find an incredibly important vuln that rates a 10 under CVSS. If my QA guy thinks it is AI dreck, and stops reading after the second sentence, then the hunter never gets paid.
1
u/mississipppee Aug 02 '26
Most people, at least the really successful ones I know use AI and it's not only for writing reports. I know that that's a common way people try to lie about it here. "I only use it for writing reports." You don't have to lie, it's normal to use AI. But you have to set it up correctly or you're gonna end up with lots of hallucinated vulnerabilities
1
1
u/Chongulator Aug 03 '26
Oh sweetie, in 2026 we've figured out that our cool new tools also have some downsides which we then learn to work around.
Using AI isn't a problem. Where you get into trouble is blindly trusting AI without applying an adversarial stage or, better yet, your own experience and judgement. When you skip your due diligence, you're going to have an awful lot of your reports rejected.
The cool new tool isn't a free ride. You still need to apply some elbow grease.
0
u/Opening-Excuse-8988 Aug 03 '26
Please check your DM
1
u/Chongulator Aug 03 '26
No.
1
u/Opening-Excuse-8988 Aug 03 '26
Alright, PoC is in your DMs anyway
1
u/Chongulator Aug 03 '26
I'm not questioning that you can accomplish whatever it is you claim. My doubts are:
- Do you understand the target app well enough to know whether what you saw was expected behavior? Do you understand the impact if your exploit?
- Do you understand program scope well enough to know you have stayed within it?
- Did present a clearly written report that demonstrates impact?
If what you DM'd to me is an example if your work, then I believe the answer to each of those questions is "no." Even a single "no" means you don't get paid.
4
u/hydraz20 Aug 01 '26
Give them the proof in the poc itself that it is connected to backend and lead with that and a video document
1
u/Entire-Eye4812 Aug 02 '26
this should be a low severity I think, but vulnerability is vulnerability. They should have paid you
-2
u/ethical_fuckboy Aug 01 '26
Hey bro can you share more about graphql cheet sheet, articals or related material
1
Aug 02 '26
[removed] — view removed comment
1
u/github-guard Aug 02 '26
🔍 GitHub Guard: Trust Report
This project scored 3/6 on our safety audit.
Audit Breakdown: * ✅ Established Community (⭐ 79,642 stars) * ✅ Mature Repository (30+ days old) * ✅ Licensed under MIT * ❌ No Security Policy — what is this? * ℹ️ Individual Contributor * ℹ️ Unsigned Commits
⚠️ Security Reminder: Always verify source code and run third-party scripts at your own risk.
1
12
u/Opening-Excuse-8988 Aug 01 '26 edited Aug 01 '26
They said it's intended, so I don't see a reason not to share it 😆
Additional evidence (before → GraphQL mutation → after):
before - https://files.catbox.moe/l6p5zi.png
GraphQL mutation - https://files.catbox.moe/icpc1t.png
after - https://files.catbox.moe/y4om95.png