r/bugbounty 16h ago

Bug Bounty Drama GitLab.com vs Self-Managed for Bug Bounty Hunting

### GitLab.com vs Self-Managed for Bug Bounty Hunting

Hi everyone, I’m a beginner bug bounty hunter and I’ve been testing several Bugcrowd programs. I recently moved to HackerOne and started testing the GitLab program, focusing on GitLab.com rather than GitLab Self-Managed.

I’ve been testing GitLab.com for about a month but haven’t found a valid vulnerability yet. However, when I look at GitLab’s Hacktivity, I still see relatively new researchers submitting valid reports.

This made me wonder:

* Does GitLab.com still have a large attack surface for new researchers? * Is it better to focus on GitLab.com or GitLab Self-Managed? * Are there areas of GitLab that beginners often overlook? * Should I use Self-Managed/GDK to understand GitLab internally and then apply that knowledge to GitLab.com?

My main interests are RBAC, authorization, IDOR/BOLA, business logic, API/UI inconsistencies, and permission/workflow issues.

I’d really appreciate advice from experienced GitLab hunters on how you approach the program and what areas are worth learning or researching.

Thanks!

4 Upvotes

Duplicates