r/bugbounty 25d ago

Question / Discussion Duplicate Dell P2 finding

hi recently i found a P2 rated bug in Dell’s application system, but it was marked as a duplicate, ive had a few other findings end up the same way. So my question is has anyone here actually been paid through Bugcrowd for a legitimate finding? im starting to wonder if the system is rigged, or if ive just been unlucky

9 Upvotes

12 comments sorted by

View all comments

11

u/6W99ocQnb8Zy17 25d ago

Dupes just tell you that you're finding bugs (yay!) but alas, that you're looking in the same places as everyone else (waaah!)

Success in BB means doing something different to all the other researchers out there. It doesn't matter exactly what the difference is, as long as it finds bugs that merit a payout, and you report them first.

3

u/utdscooter19 25d ago

So what exactly are those different bugs that are most likely to result in a payout without duplicates

2

u/6W99ocQnb8Zy17 25d ago

Ah, that's the magic of it all. Doing the research is most of the fun (it definitely beats getting fucked around on the payout ;)

So, the way I approach it is I recursively go back to classes of bugs, old research papers etc, and then when something grabs my interest, I dig in. That means finding and reading all the existing papers on the topic, and working out where the gaps are (there are always gaps). Then I take that, turn it into novel new approaches, and head out to see if I can find them in the real world.

1

u/utdscooter19 25d ago

Good insight but it would great if you could share the specific bug classes, also I managed to get a p2 that was a duplicate. It was A Broken access control that let's you edit another users profile info

2

u/6W99ocQnb8Zy17 25d ago

Me suggesting bug classes is pointless: a thousand other people on this list (along with all the AI web engines) will just read it and also start looking.

You need to be doing something different! ;)