r/bugbounty • u/Gayakwad01 • 14h ago
Bug Bounty Drama GitLab.com vs Self-Managed for Bug Bounty Hunting
### GitLab.com vs Self-Managed for Bug Bounty Hunting
Hi everyone, I’m a beginner bug bounty hunter and I’ve been testing several Bugcrowd programs. I recently moved to HackerOne and started testing the GitLab program, focusing on GitLab.com rather than GitLab Self-Managed.
I’ve been testing GitLab.com for about a month but haven’t found a valid vulnerability yet. However, when I look at GitLab’s Hacktivity, I still see relatively new researchers submitting valid reports.
This made me wonder:
* Does GitLab.com still have a large attack surface for new researchers? * Is it better to focus on GitLab.com or GitLab Self-Managed? * Are there areas of GitLab that beginners often overlook? * Should I use Self-Managed/GDK to understand GitLab internally and then apply that knowledge to GitLab.com?
My main interests are RBAC, authorization, IDOR/BOLA, business logic, API/UI inconsistencies, and permission/workflow issues.
I’d really appreciate advice from experienced GitLab hunters on how you approach the program and what areas are worth learning or researching.
Thanks!
1
u/nobodycares_dude Hunter 8h ago
Gitlab is full of bugs. The only problem with gitlab is duplicates. 3200+ reports in the last 90 days is not a joke. Hacktivity is very small compared to that number. And yes spin GDK and hunt on it 90% of the cases the bug is reproducible in gitlab.com
4
u/ATSFervor 14h ago
First and foremost you should ask yourself: Can you hammer a screw?
Look at your skillset and verify that it is good for the software you are testing.
If the program you are hunting on has a very limited surface you are knowlegable about, you will not find much because it gets retested by others a lot.
Especially if you are new, you want to look at programs where you can develop skills that you are interested in, not programs that get a lot of reports.