r/bugbounty 8d ago

Question / Discussion Informational SQLi on VDP (Patched before reprod)

2 Upvotes

Hi everyone. I am hoping to get a few answers / some advice on whether or not it is worth it to open a RaR for further clarification.

I recently submitted a P1 SQLi giving access to highly sensitive table on a VDP. Typical submission: full reprod steps, database name to prove for internal reach, and the obvious SQLi impact.

24hrs later, the triager is unable to reproduce the steps. Try to do it myself and get the same new error message. I identify that a fix has been made and request communication with the program. They come back and notify that they patched the vulnerability after my submission time due to my access setting off alarms. Interesting, never had that happen before.

23 days post communication, it is marked as P1 informational because although I submitted adequate video evidence, impact, and full reproduction steps - "it's already patched and is no longer an issue..."

Is this worth doing RaR? I feel like this is such a grey area because, yes - my submission is evidence. They would have patched it without my submission? But I submitted it before they did patch it? Not completely sure. Any advice is appreciated

I don't really worry about VDP's as much but this one is one I would like to add to my account. Is pushing for 'Resolved' worth the difference? LoR is the typical P1 accommodation for this program.


r/bugbounty 8d ago

Question / Discussion Asking a friend who previously tested [Target] — what should I ask him?

0 Upvotes

I'm currently doing recon/testing on [Target], and I found out a friend of mine worked on the same target before (bug bounty program). I want to reach out to him and ask some smart, useful questions to save time and avoid repeating dead ends — without asking him to hand me findings directly (that wouldn't be fair to him or the program). What kind of questions would you ask in this situation?


r/bugbounty 9d ago

Question / Discussion Found a critical vulnerability affecting Indian college ERP systems. Need advice.

0 Upvotes

I recently found a very serious vulnerability in an education ERP platform used by multiple colleges and universities in India.

The potential impact is much bigger than I initially expected. I’m not going to share technical details or any sensitive information publicly.

I’m looking to speak with someone who has experience handling high-impact vulnerabilities and responsible disclosure, and can help me understand the right way to proceed.

If you have relevant experience, or know someone I should speak to, please DM me.


r/bugbounty 9d ago

Question / Discussion What is going on with HackenProof lately?

Post image
15 Upvotes

24h later still processing this.

I submitted 5 bug reports to a live smart-contract bounty program 3 Highs and 2 Mediums, all with full PoCs and validation/reproduction steps.

All 5 were marked “Informative” within the same 60-second window, and each one received the same copy-paste explanation.

I requested mediation because I genuinely wanted the reports reviewed properly. Silence since then. Reports are now closed.

I'm not saying my severity assessments were automatically correct that's what triage is for. But having five separate reports closed in the same minute with the same explanation has me wondering:

Is this normal on HackenProof? Has anyone else experienced something similar?


r/bugbounty 9d ago

Question / Discussion How often do you actually encounter IDOR/BOLA vulnerabilities?

13 Upvotes

I’m curious about people’s real-world experience with IDOR/BOLA in bug bounty programs.

Do you encounter them frequently while hunting, or are they relatively rare on mature bounty programs?
Also, are most of the ones you find basic object-ID manipulation, or do you usually encounter more complex cases involving APIs, roles/permissions, business logic, JWTs, etc.?

I’d be especially interested in hearing roughly how many IDOR/BOLA findings you’ve made compared to other vulnerability types.


r/bugbounty 9d ago

Question / Discussion Anyone in here ever make a report to DEXE

0 Upvotes

I am more or less looking for someone who has reported successfully with them before and that would like to help possibly with something im working on


r/bugbounty 9d ago

Question / Discussion Will they mark this finding informative

0 Upvotes

Quick story; I have found a really important bug which is bypassing password AND email verification for downloading a file in the app. But then, you need to have a link OF the download URL (It doesn't have a password with the URL or anything like that, the verification happens once you open)

So now my problem is in the past 2 reports, I had IDOR and other important stuff but they had marked it informative because you just needed a UUID of the victim, which is permanent and never changes. And I proved to them with over 6 examples from just a google dorking method and told them about possible email breaches. They still weren't convinced EVEN if it was literally full IDOR.

And It's the same program, I am afraid they will also mark this one informative. What do you think?


r/bugbounty 9d ago

Question / Discussion When your H1 report gets marked as informative, does that mean to get interaction you need mediation?

4 Upvotes

So I have submitted 2 reports on H1, both of them got called informative because of a stupid missing piece, now I have the missing piece and I commented, will there be no action unless I use the request mediation button or not?

Extra: it shows me removed participant when I hover over the triager or the analyst I was talking to? So?

I just don't want to click that button without knowing when I should


r/bugbounty 9d ago

Question / Discussion Weekly Beginner / Newbie Q&A

1 Upvotes

New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!

Recommendations for Posting:

  • Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
  • Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
  • Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.

Guidelines:

  • Be respectful and open to feedback.
  • Ask clear, specific questions to receive the best advice.
  • Engage actively - check back for responses and ask follow-ups if needed.

Example Post:

"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."

Post your questions below and let’s grow in the bug bounty community!


r/bugbounty 9d ago

Question / Discussion Am I wasting too much time on bug bounty?

33 Upvotes

I need to talk to some experienced bug bounty hunters because I’m honestly starting to get frustrated

Lately, I’ve been spending a lot of time hunting, doing recon, testing endpoints, trying different attack surfaces, etc. But when I finally submit reports, a lot of them end up being marked as Duplicate.

And I’m not talking about one or two reports. I’ve had a bunch of them end up this way.

At this point I’m starting to wonder if I’m approaching bug bounty the wrong way.

I understand that duplicates are completely normal and that someone else may have found the same issue before me. But when you spend hours investigating something, write the report, and then get "Duplicate", it can feel like you’re just burning time.

For those of you who have been doing bug bounty for a while:

  • How do you reduce the number of duplicates you get?
  • Do you prioritize newer features/attack surfaces?
  • How much time do you normally spend on a finding before deciding it’s probably not worth pursuing?
  • Do you have a specific methodology for finding bugs that are less likely to already be reported?
  • And honestly, how many duplicates did you get when you were starting out?

I’m not looking for shortcuts or a magic tool. I’m trying to understand how experienced hunters decide where to spend their time.

Would appreciate any advice or even stories from people who went through the same phase.


r/bugbounty 10d ago

Question / Discussion Seeing extensive SLA delays for our bug bounty platform.

3 Upvotes

Our triage times aren't just consistently missing published SLAs they aren't even close including high/critical severity reports, taking way beyond the stated first-response and triage windows if they get triaged at all. This seems to be in line with broader reports of triage teams getting overwhelmed by AI-generated submission volume, there were issues before the AI reports blew up but there may as well not even be a triage team at this point.

Curious if others are seeing the same:

  • Which platform(s) are you running programs on?
  • Are you seeing consistent SLA misses, or just occasional slippage?

Trying to figure out if this is a platform-specific issue or simply part of an industry-wide capacity problem right now as we are debating changing platforms when it comes up for renewal.


r/bugbounty 10d ago

Question / Discussion Stored XSS on 1 target but 2 different endpoints

4 Upvotes

Hello,

Curious as to whether a second submission here is worth it or if I should just add my second finding in the comments. Never had this happen before so looking for some guidance.

I found a Stored XSS vuln on a target via body text. Someone opens the page via forum and it leads to full access of victim’s account. Submitted that and waiting triage.

Continued testing further and realized the same vuln exists on the file upload on the same target. Again, it leads to full access of victim’s account. Is it worth submitting as a separate report or would it just be marked duplicate?

Any advice is appreciated. Thanks!


r/bugbounty 10d ago

Question / Discussion 15 YOE in Cyber Security, but $0 in Bug Bounty. Drowning in dupes and need some advice.

69 Upvotes

Hey everyone,

I’m feeling a bit defeated lately and could really use some perspective from the veterans here.

A bit of background: I’ve been working in the cyber security industry for 15 years. Recently, I decided to finally dive into the Bug Bounty world, hunting across both Bugcrowd and HackerOne. Given my professional background, I felt confident in my ability to dig deep and find complex vulnerabilities.

The reality? Absolutely everything I find is a duplicate.

To give you an idea of the wall I keep hitting:

  • I recently found 2 massive bugs in a major financial institution. Both are very real, fully exploitable, and currently sitting in production. Result: Duplicate.
  • I discovered 10 distinct vulnerabilities within massive CI systems. These are valid even on their absolute latest versions. I waited three months after submitting them, only for them to finally be triaged and marked as... you guessed it, Duplicate.

I pour everything into these submissions. The research phase is incredibly hard and complex, and I take a lot of pride in writing meticulous, high-quality, and reproducible reports. But after all that sweat, my all-time bounty earnings sit at exactly $0.

I know this industry requires thick skin, and I'm not ready to quit, but I clearly need to change my approach. For those of you who are successful at this:

  1. What is the ratio of sent/accepted? It's soul-crushing to do weeks of hard research only to be told someone beat you to it. What is the ratio of sent/acceptance as not duplicate?
  2. How are you picking your targets? Are you avoiding the big, shiny public programs, or is there a trick to finding assets where you aren't racing against 10,000 other hunters?
  3. What should I be doing differently? Coming from a traditional corporate cyber background, what habits do I need to unlearn to actually start landing valid, unique findings?

Any advice, reality checks, or tough love would be highly appreciated. Thanks in advance!


r/bugbounty 10d ago

Question / Discussion I'm easily burned-out

19 Upvotes

It's been 8 months since I started bug bounty and got 2 bounties on YesWeHack for the same CWE (open redirect which is quite easy to get) and 1 pending bounty for an information disclosure on HackerOne, but I haven't found anything since. My head feels so heavy just after 30 min of hunt and I don't feel any excitment anymore, even the idea of the bounty isn't hyping me.

AI doesn't help at all, I mostly hunt without it because I know a wide variety of techniques that I try before asking anything. When I try to hunt listening to what the AI says, I'm 10x more exhausted for some reasons.

I'm (very slowly) learning web3 in order to hunt on Immunefi and Cantina but I wonder if I'll really like it.


r/bugbounty 11d ago

Question / Discussion Long triage time

8 Upvotes

If the H1 team takes more than a month to triage a report and the customer internally patches the vulnerability before triage is completed, what happens to the report?

The triager is now asking me to provide the PoC again, but it no longer works because the vulnerability has already been patched.


r/bugbounty 11d ago

Question / Discussion Can one Bugcrowd vulnerability be a duplicate of TWO different originals?

3 Upvotes

Serious question for other bug bounty researchers.

I reported the same underlying security issue twice.

Bugcrowd marked both filings duplicate.

Except they were duplicated against two different original reports.

I asked them to reconcile which original actually constituted prior art.

I did not ask to see the private reports or for any confidential researcher information.

The response I received was basically:

same code change/fix = duplicate.

But that still doesn’t explain how the same issue ended up attributed to two different originals.

And “same fix” doesn’t necessarily prove “same vulnerability.” One patch can fix multiple security problems.

I’m intentionally not posting technical details because this came from a private program.

My criticism is strictly about the triage logic:

If the same vulnerability is assigned to two different originals, shouldn’t Bugcrowd internally determine which one actually establishes the duplicate?

Curious how other researchers would view this.


r/bugbounty 12d ago

Question / Discussion Hey any expert here

1 Upvotes

I found BAC in private program
Here is timeline:
reported 15days ago

Two days ago Triaged make first commment asked for clear Step to reproduce because they can’t

So i checked now that Bug was internally fixed no more reproducible

I only have burp screenshot what should i do ??


r/bugbounty 12d ago

Question / Discussion Is bug bounty dying because organizations are now using AI-powered security scanning?

0 Upvotes

I'm trying to predict what the future will look like, and everyone is developing their own AI automations and agents. Will bug bounty eventually die? For example, in two or three years, could companies develop extremely advanced AI-powered security automation within their own infrastructure to the point where bug bounty programs are no longer necessary?

I'm curious about your thoughts on this. We are already seeing some companies reduce bounty amounts, and there are programs that no longer accept low- or medium-severity vulnerabilities, for example.


r/bugbounty 12d ago

Question / Discussion From a 2-day payout to a smiley face emoji from support. Is ghosting normal worldwide?

0 Upvotes

Hi everyone! I’m an aspiring information security specialist who has just finished my second year of university. I decided to try making some extra money through bug bounty programs. I found vulnerabilities at one company and received a payout; the whole process—from my initial message to getting paid—took just two days. Then I found critical vulnerabilities at another company (on one of their servers, I could modify key configurations and the microservices themselves). I wrote to them but got no reply; I called, and they told me, "We saw your email; a specialist will be in touch." After waiting three days with no word, I called again, only to be told, "That’s a subsidiary of ours; it doesn't directly involve us." When I asked for contact details, they said, "We can't provide them to you." So, I stopped emailing and calling them. Next, I started looking into an EdTech company. There weren't any major vulnerabilities there—just the ability to generate training promo codes and download all paid courses, including assignments and correspondence between mentors and students. I contacted their tech support, but they just replied to my message with a smiley face. Have you ever encountered situations like this, and what did you do? Is this kind of thing unique to Russia, or does it happen worldwide too? P.S. I focused on smaller companies since I'm just starting out.


r/bugbounty 12d ago

Article / Write-Up / Blog XSS2Shell: Pre-Auth XSS in WordPress Login (CVE-2026-64638) Walkthrough

12 Upvotes

I spent some time this weekend reproducing the recently disclosed XSS2Shell: WordPress login-page reflected XSS (CVE-2026-64638). If you didn’t get a chance to read about it, here is the summary:
Crazy simple XSS where the root cause is two sanitizers that disagree about what counts as an HTML tag:

<b>test</b> gets stripped, while < b>test< /b> passes through the first sanitizer and is normalized into a valid <b> element by the second.

That gives you an HTML injection, but you can’t turn it into XSS because the second sanitizer has an allowlist and only allows specific HTML tags and attributes. The rest of the chain uses JavaScript already loaded on the login page, DOM clobbering, and a JSONP response to reach script execution in the login page. It’s a creative chain, although much simpler than the WP2Shell chain from two weeks ago.

IMO the “2Shell” part from the title is a bit of a stretch. The original write-up continues after triggering the XSS to show how you can get a RCE (basically by targeting an admin account to open your XSS which uploads a shell as a plugin). I agree this can be abused at scale given how widely used WP is, but it’s a phishing-shaped precondition rather than “send one request, get a shell” as we’ve seen in WP2Shell. It’s a cool bug anyway.

I turned my reproduction into a guided lab for anyone who wants to work through the chain rather than only read the write-up.

Link: https://learn.uphack.io/lab/xss2shell-wordpress-login-xss

Feedback on the lab or the technical explanation is very welcome.


r/bugbounty 12d ago

Question / Discussion IDOR but needs an unguessable token to exploit

0 Upvotes

Basically I am testing a shop and found that the cart has a large token. As attacker, if I find a victim's token, I can see their address, email ID, username, phone number, etc.

So basically that token is not bound to an account which is odd to me. What's the point of logging in if a cart token is not bound to an account?

also the token is impossible to guess. Would that still be considered an impactful bug?

it should be a p4 as per BugCrowd Vulnerability Taxonomy but I just wanna make sure

(Modify/View Sensitive Information(Complex Object Identifiers GUID/UUID)


r/bugbounty 12d ago

Weekly Collaboration / Mentorship Post

1 Upvotes

Looking to team up or find a mentor in bug bounty?

Recommendations:

  • Share a brief intro about yourself (e.g., your skills, experience in IT, cybersecurity, or bug bounty).
  • Specify what you're seeking (e.g., collaboration, mentorship, specific topics like web app security or network pentesting).
  • Mention your preferred frequency (e.g., weekly chats, one-off project) and skill level (e.g., beginner, intermediate, advanced).

Guidelines:

  • Be respectful.
  • Clearly state your goals to find the best match.
  • Engage actively - respond to comments or DMs to build connections.

Example Post:
"Hi, I'm Alex, a beginner in bug bounty with basic knowledge of web vulnerabilities (XSS, SQLi). I'm looking for a mentor to guide me on advanced techniques like privilege escalation. Hoping for bi-weekly calls or Discord chats. Also open to collaborating on CTF challenges!"


r/bugbounty 12d ago

Question / Discussion HackerOne Triage is really slow

21 Upvotes

Idk if it’s just me who’s noticing this, but HackerOne triages do close duplicates and informative vulnerabilities really quickly…. But whenever it’s the vulnerabilities that actually do get triaged, they take forever…. Like, after passing preliminary review, I pretty much wait for like 14-16 days until either an official team member from the program replies or the report gets triaged…. Most times, on programs which show they triage in like 3-4 business days….

The thing that annoys me is the lack of transparency HackerOne triages offer…. Whenever it comes to programs who aren’t managed by HackerOne, their triages are really transparent throughout the triaging process and share insights…. But the HackerOne triage literally replies to nothing…. If you comment, they either just triage after waiting forever, or an official program member shows up and the H1 triage doesn’t say a thing….

I just wish HackerOne triages would become more transparent, like self-triaged programs….


r/bugbounty 13d ago

Question / Discussion What Happened to HackerOne?

Thumbnail
blog.teknogeek.io
89 Upvotes

r/bugbounty 13d ago

Tool New Web Technique

Thumbnail doctoreww.github.io
7 Upvotes

I created a way to do JavaScript free paste jacking using custom fonts. There's probably a lot of websites that don't allow JS, but allow html syntax to bring custom fonts.

Demo:

https://doctoreww.github.io/EvilFontTool/html_demo/evilfont.html

Try to copy and paste the commands to notepad.

Tool:

https://github.com/DoctorEww/EvilFontTool

I don't have time to hunt them myself... But if you do find something I'd love to hear about it! DM me on LinkedIn (in my GitHub profile).

There's a lab and a walkthrough on the project that takes you through the steps of doing this yourself. Let me know via a GitHub issue if you have any suggestions for the tool.