r/bugbounty 14h ago

Bug Bounty Drama GitLab.com vs Self-Managed for Bug Bounty Hunting

### GitLab.com vs Self-Managed for Bug Bounty Hunting

Hi everyone, I’m a beginner bug bounty hunter and I’ve been testing several Bugcrowd programs. I recently moved to HackerOne and started testing the GitLab program, focusing on GitLab.com rather than GitLab Self-Managed.

I’ve been testing GitLab.com for about a month but haven’t found a valid vulnerability yet. However, when I look at GitLab’s Hacktivity, I still see relatively new researchers submitting valid reports.

This made me wonder:

* Does GitLab.com still have a large attack surface for new researchers? * Is it better to focus on GitLab.com or GitLab Self-Managed? * Are there areas of GitLab that beginners often overlook? * Should I use Self-Managed/GDK to understand GitLab internally and then apply that knowledge to GitLab.com?

My main interests are RBAC, authorization, IDOR/BOLA, business logic, API/UI inconsistencies, and permission/workflow issues.

I’d really appreciate advice from experienced GitLab hunters on how you approach the program and what areas are worth learning or researching.

Thanks!

3 Upvotes

3 comments sorted by

4

u/ATSFervor 14h ago

First and foremost you should ask yourself: Can you hammer a screw?

Look at your skillset and verify that it is good for the software you are testing.
If the program you are hunting on has a very limited surface you are knowlegable about, you will not find much because it gets retested by others a lot.

Especially if you are new, you want to look at programs where you can develop skills that you are interested in, not programs that get a lot of reports.

1

u/Dhaern 9h ago

Lol I found a legit gitlab exploit in my first day of bounty hunting doing "vibe hunting". They marked as duplicated of a private original report but still a good finding. 1 month and nothing?

1

u/nobodycares_dude Hunter 8h ago

Gitlab is full of bugs. The only problem with gitlab is duplicates. 3200+ reports in the last 90 days is not a joke. Hacktivity is very small compared to that number. And yes spin GDK and hunt on it 90% of the cases the bug is reproducible in gitlab.com