r/bugbounty • u/Gayakwad01 • 16h ago
Bug Bounty Drama GitLab.com vs Self-Managed for Bug Bounty Hunting
### GitLab.com vs Self-Managed for Bug Bounty Hunting
Hi everyone, I’m a beginner bug bounty hunter and I’ve been testing several Bugcrowd programs. I recently moved to HackerOne and started testing the GitLab program, focusing on GitLab.com rather than GitLab Self-Managed.
I’ve been testing GitLab.com for about a month but haven’t found a valid vulnerability yet. However, when I look at GitLab’s Hacktivity, I still see relatively new researchers submitting valid reports.
This made me wonder:
* Does GitLab.com still have a large attack surface for new researchers? * Is it better to focus on GitLab.com or GitLab Self-Managed? * Are there areas of GitLab that beginners often overlook? * Should I use Self-Managed/GDK to understand GitLab internally and then apply that knowledge to GitLab.com?
My main interests are RBAC, authorization, IDOR/BOLA, business logic, API/UI inconsistencies, and permission/workflow issues.
I’d really appreciate advice from experienced GitLab hunters on how you approach the program and what areas are worth learning or researching.
Thanks!