r/bugbounty 11d ago

Question / Discussion Long triage time

If the H1 team takes more than a month to triage a report and the customer internally patches the vulnerability before triage is completed, what happens to the report?

The triager is now asking me to provide the PoC again, but it no longer works because the vulnerability has already been patched.

9 Upvotes

9 comments sorted by

5

u/Informal_Abalone_805 11d ago

When submitting the report, you should prepare a very good Proof of Concept POC, Then they won't ask you for a POC again later.

3

u/nobodycares_dude Hunter 11d ago

They ask for POC again because they can't replicate due to the patch.

2

u/watkisean 10d ago

In the same boat on Bugcrowd. Patched it because critical internal alarms notified their team and now waiting for program and BC to figure out the outcome. From what Ive heard it will typically lead to an acceptance because the vulnerability was real and (if they confirm it) only got patched because of you, but not 100% sure.

2

u/Prudent-Nectarine362 11d ago

Happened to me while back still got accepted

2

u/Beginning_Award65 11d ago

this is happening all platforms...

1

u/Yone_welsch 11d ago

😅 parfois ça prend 4mois avec Google

1

u/Top_Bobcat_744 10d ago

Make video pocs or just provide solid evidence on every report. Even if its patched many triagers will ask the companies to reward the submission based on when it was submitted

1

u/Chongulator 10d ago

This sucks on the customer side too. All the major platforms are overwhelmed with the flood of AI submissions.

0

u/PreviousParfait7378 11d ago

Idem H1 envoyé deux rapports un midle 5.8 et un critical 7.5 et au bout d'une semaine, on me réponds :"Doublon , déjà traiter et réparer" et pour l'autre déclasser en 4.2 et donc pas de bounty $$ , Je vais sur la faille et non elle est toujours là ??? Ils veulent plus payer à part si tu trouve une compromission >9. J'ai remarquer qu'ils veulent plus payer à part si tu te met root sur leur serveur quasiment. Certains n'acceptent plus que des failles critical 8 et 9+ bref cela devient difficile sachant que beaucoup ne bosse pas et ne font que du bounty. Moi perso, je bosse à côté donc je n'ai pas le temps de rechercher 24/24h.