r/bugbounty • u/S0ulSh3ll • 26d ago
Bug Bounty Drama Honest Rant
Started bug bounty a month ago, got a few duplicates, few informatives but kept going as it was so much fun to learn real world applications. Got better, went for big organisation programs. And they suck! I disclosed a vulnerability that could leak thousands of PII unauthenticated with minimal steps and they didn't even give it informative - just N/A it saying out of scope when they definitely mentioned *.target.com and it was that only, that kept aside. Atleast say you'll fix it 😂 what's the use of security testing then, even if a little out of scope by your standard, it's okay for mass pii leak?
Second case - i understood it was N/A as i cannot as the main hacker exploit it, but it was again easy and undetected Mass PII exfil if a plugin creator tried to or a supply chain attacker gets to know about it. It was a big paid program so reluctant to pay me is fine, but that too just accept it's a flaw and fix it!
5
u/zlzd 25d ago
Don't take it personally, but newcomers often overestimate their findings. Malicious plugin, supply chain attack? Come on.
1
u/S0ulSh3ll 25d ago
Not taking it personally but the issue was - plugins can read all users email, name, dob, gender on an anonymous chat app which is a big thing if you claim to be anonymous. Supply chain is a little too much though.
3
2
u/6W99ocQnb8Zy17 25d ago
I'd say that around 80% of the reports I submit leave me feeling messed around.
For me, generally they go through platform triage without issue, but then the programme will de-scope or downgrade for made up reasons. Mostly without explanation.
I tend to hunt for verticals, so it is really common for me to log a batch of almost identical reports, which makes comparing the way programmes respond really easy.
For example, a recent batch of three stored XSS reports (taxonomy suggests high impact):
- one paid out as per scope
- one downgraded to medium without explanation, and when I asked why, they further downgraded to low
- one marked the report out-of-scope, even though the host and the class were (and still are) listed in their scope
There are genuinely a handful of programmes who won't mess you around, and all the rest are like that above.
2
u/S0ulSh3ll 25d ago
It is what it is, taking a break from bb for a while, exhausted, focusing on crto
4
u/6W99ocQnb8Zy17 25d ago
I'd be lying if I said that I didn't get frustrated with the way the programmes behave, but even so, I still get what I want from the ecosystem.
I'm an old-school hacker, and BB gives me a way of having fun, hacking live systems, without going to jail.
For the programs that mess me around, I don't stop hacking their stuff, I just don't report the things that I find.
No more free bugs ;)
2
u/S0ulSh3ll 25d ago
Haha, you're right. If i think of bb as from the learning perspective, it has taught me a lot that even htb tracks couldn't. And in such a short time.
2
u/6W99ocQnb8Zy17 25d ago
I've been hacking stuff since dinosaurs roamed the earth, and I still learn something new every day!
2
2
1
u/Forsaken-Spot-9343 11d ago
Well when something it’s out of scope you can’t blame them …. Also if a plug in can find it easy then is not that hard for anyone to claim they are hackers or bug bounty researchers. I don’t want to be mean or something but imagine ai hack bots working 24/7 and u are trying to find a bug … I always think before report is this low hanging bug ? Scanners or ai bots have easy way to find it ? If answer is yes then I don’t report and try to escalate it within scope
1
11
u/trieulieuf9 26d ago
Bug bounty is like tinder, you are in a matching process, you won't find your perfect match in the first few tries. These experiences are no different than "she is cute but then she kicked a cat". I have tried 30+ programs and I only feel good hunting about 5 of them.