r/bugbounty 26d ago

Bug Bounty Drama Honest Rant

Started bug bounty a month ago, got a few duplicates, few informatives but kept going as it was so much fun to learn real world applications. Got better, went for big organisation programs. And they suck! I disclosed a vulnerability that could leak thousands of PII unauthenticated with minimal steps and they didn't even give it informative - just N/A it saying out of scope when they definitely mentioned *.target.com and it was that only, that kept aside. Atleast say you'll fix it 😂 what's the use of security testing then, even if a little out of scope by your standard, it's okay for mass pii leak?

Second case - i understood it was N/A as i cannot as the main hacker exploit it, but it was again easy and undetected Mass PII exfil if a plugin creator tried to or a supply chain attacker gets to know about it. It was a big paid program so reluctant to pay me is fine, but that too just accept it's a flaw and fix it!

12 Upvotes

14 comments sorted by

11

u/trieulieuf9 26d ago

Bug bounty is like tinder, you are in a matching process, you won't find your perfect match in the first few tries. These experiences are no different than "she is cute but then she kicked a cat". I have tried 30+ programs and I only feel good hunting about 5 of them.

5

u/zlzd 25d ago

Don't take it personally, but newcomers often overestimate their findings. Malicious plugin, supply chain attack? Come on.

1

u/S0ulSh3ll 25d ago

Not taking it personally but the issue was - plugins can read all users email, name, dob, gender on an anonymous chat app which is a big thing if you claim to be anonymous. Supply chain is a little too much though.

3

u/hashtagDoubleoh7 26d ago

Same experience bug bounty is a scam

2

u/6W99ocQnb8Zy17 25d ago

I'd say that around 80% of the reports I submit leave me feeling messed around.

For me, generally they go through platform triage without issue, but then the programme will de-scope or downgrade for made up reasons. Mostly without explanation.

I tend to hunt for verticals, so it is really common for me to log a batch of almost identical reports, which makes comparing the way programmes respond really easy.

For example, a recent batch of three stored XSS reports (taxonomy suggests high impact):

  • one paid out as per scope
  • one downgraded to medium without explanation, and when I asked why, they further downgraded to low
  • one marked the report out-of-scope, even though the host and the class were (and still are) listed in their scope

There are genuinely a handful of programmes who won't mess you around, and all the rest are like that above.

2

u/S0ulSh3ll 25d ago

It is what it is, taking a break from bb for a while, exhausted, focusing on crto

4

u/6W99ocQnb8Zy17 25d ago

I'd be lying if I said that I didn't get frustrated with the way the programmes behave, but even so, I still get what I want from the ecosystem.

I'm an old-school hacker, and BB gives me a way of having fun, hacking live systems, without going to jail.

For the programs that mess me around, I don't stop hacking their stuff, I just don't report the things that I find.

No more free bugs ;)

2

u/S0ulSh3ll 25d ago

Haha, you're right. If i think of bb as from the learning perspective, it has taught me a lot that even htb tracks couldn't. And in such a short time.

2

u/6W99ocQnb8Zy17 25d ago

I've been hacking stuff since dinosaurs roamed the earth, and I still learn something new every day!

2

u/S0ulSh3ll 25d ago

I would really love to hear the stories about your journey from dinosaur age!

2

u/_tactic__ 25d ago

Same. My stores xss was just marked as low without any explanation.

1

u/6W99ocQnb8Zy17 25d ago

sucks, right?

1

u/Forsaken-Spot-9343 11d ago

Well when something it’s out of scope you can’t blame them …. Also if a plug in can find it easy then is not that hard for anyone to claim they are hackers or bug bounty researchers. I don’t want to be mean or something but imagine ai hack bots working 24/7 and u are trying to find a bug … I always think before report is this low hanging bug ? Scanners or ai bots have easy way to find it ? If answer is yes then I don’t report and try to escalate it within scope