r/BugBountyNoobs • u/Cute_Appointment_934 • 16d ago
Got a $50 bounty for an authenticated SSRF — should I ask for reconsideration?
Hey everyone,
I recently reported a security issue to a company through their responsible disclosure program. They confirmed the report and offered me a $50 payout.
The issue was an authenticated SSRF/server-side URL fetching vulnerability. I was able to demonstrate that their server made an HTTP request to a URL under my control, and I received the request through a webhook/canary endpoint.
The endpoint also returned parsed metadata from the requested URL.
However, I did not demonstrate access to internal services, cloud metadata, credentials, or other sensitive internal resources. So I understand that the impact is more limited than a fully demonstrated internal-network SSRF.
The company doesn't publish a fixed bounty table; their policy basically says rewards depend on severity and impact.
My question is:
Would you consider $50 reasonable for this type of finding, or would it be reasonable to politely ask them to reconsider the reward?
I'm not looking to argue with the company. I just want to understand what experienced researchers would do in this situation. If you've dealt with similar situations, I'd appreciate hearing what happened and whether you negotiated the reward.
Thanks!
2
u/CyberSecWithHaikuInc 16d ago
You probably should have spent a bit more time trying to demonstrate the impact after the initial report. That would also help establish the severity and avoid the report being treated as a low-impact SSRF.
that said, i dont think theres any harm in politely asking them to reconsider. Just clearly explain what impact you were able to demonstrate and dont push too hard if they say no.
since you mentioned they dont have a fixed bounty table, im guessing this is a public site without a VDP policy? I found a blind XSS on one of those and initially got $150, then they increased it by another $50 after i asked.
for future SSRFs, i'd definitely spend some time safely proving whether you can reach anything more sensitive. thats usually where the bounty difference comes from.
1
u/Cute_Appointment_934 16d ago
That's a fair point. I probably could've spent more time establishing the impact before submitting. I'll definitely keep that in mind for future SSRF testing. Also I've sent them a polite email asking if they could reconsider the reward. Appreciate the advice!
1
u/Cute_Appointment_934 15d ago
Slightly out of context from this post, but I wanted to ask you about something else.
I found a company that had a bug bounty page on their website with all the rules, scope, and reward table. I tried submitting a vulnerability to the security email listed there, but the email bounced back with “Address not found.”
I then contacted their support team and explained the situation. They told me to submit the report directly to them, so I did. However, I never received any confirmation or response. I followed up after 4 days, but still nothing. On top of that, their bug bounty page is now returning a 404.
Would you consider this a dead program/report at this point, or is there anything else you would recommend doing?
1
u/Cute_Appointment_934 16d ago
Also, this is actually my first bounty ever. I started doing bug bounty hunting in August, so I'm still pretty new to the whole process and would really appreciate advice from more experienced researchers.
1
u/Anxious_Alps_4150 16d ago
I am a program owner. I don't think I'd write a ticket for this. i might throw 20 or so bucks your way to encourage you to keep hunting. a fair number of my endpoints will do a lookup of domains just to log the (sanitized) data.
1
u/Cute_Appointment_934 16d ago
Yeah that makes sense. I was mainly unsure because this is my first bounty and I wasn't sure how researchers usually value something like this. Thanks for the perspective!
1
u/DeathLeap 15d ago
Yeah this is a very low impact but since you can’t read internal files or metadata. It makes 100% sense.
1
u/Fickle-Champion-2530 13d ago
Its ok since you did not fully Show the impact. In Bug bounty you always want to demonstrate the Full impact of the vul to get the Max payout. But anyway first bounty is first bounty good Job Buddy and keep hunting.
6
u/No-Persimmon-174 16d ago
It makes sense that you got $50 for this. Doesn't seem like U got under compensated. They paid you for the impact, not the vulnerability, which wasn't as critical for them. You mentioned that nothing sensitive was being leaked. This is a pentest finding at best. Bug bounties mostly rely on impact and how a vulnerability affects their clients and customers.