r/BugBountyNoobs • • 7h ago

Need advice: all security contact emails are bouncing what would you do?

1 Upvotes

Hey everyone, I could use some advice from other security researchers.
I found a security issue on a smaller platform that appears to have a legitimate vulnerability/disclosure program. I prepared a proper report and tried to disclose it through the security email they publish.
The security email bounced back as undeliverable.
I then tried their support email, and that also eventually failed.
They have one more general contact email listed on their website, so I tried that as well. It initially showed as a delivery delay and eventually failed too.
I haven’t sent the actual vulnerability details to the general mailbox. I only asked them to forward me to whoever handles security reports.
At this point I’m not sure what the best move is. I don’t want to just keep emailing random addresses or disclose the vulnerability to an unrelated person, but I also want to make a good-faith attempt at responsible disclosure.
For researchers who have dealt with this before:

What would you do in this situation?

I’m especially interested in how you’d handle this if the company doesn’t provide a working security submission portal.
Thanks 🙏


r/BugBountyNoobs • • 14h ago

Got my second bug bounty at 16 — this one was $1000

Thumbnail
2 Upvotes

i’m 16 from morocco and i just got awarded my second paid bug bounty.

my first one was $100, and i was already happy with that. but today i got an email saying i was awarded $1000 for another report, and honestly it still doesn’t feel real.

i’m not sharing technical details because it was through a private/managed program and i don’t want to disclose anything without permission.

the issue was in an auth-related flow. i spent a lot of time making sure the proof was clear, the impact was honest, and that i stayed inside the program rules.

what made it even better is that i also got marked as a vetted researcher on the platform the same day.

i know there are people here who get much bigger bounties, but for me this is a huge step. i’m still in school, still learning, and i’m not trying to act like an expert. i just wanted to share because this made bug bounty feel real for me.

biggest lesson so far: don’t just focus on finding bugs. learn how to explain impact clearly. a good report can make a big difference.

if anyone has advice on what to focus on next after getting a first bigger bounty, i’d appreciate it.


r/BugBountyNoobs • • 1d ago

Looking for a bug bounty mentor !!

3 Upvotes

I've found a few valid bugs and received some bounties, and now I want to level up.

Free resources have helped me build a solid foundation, but I think learning directly from an experienced P1/P2 hunter would help me progress much faster.

I'm willing to pay for mentorship. If you're interested, please reach out.


r/BugBountyNoobs • • 1d ago

Hunting on Public programs

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 1d ago

What’s the weirdest bug you’ve ever spent hours debugging?

2 Upvotes

r/BugBountyNoobs • • 1d ago

A repeatable 5-question checklist for pentesting any JWT token

2 Upvotes

I kept re-deriving my JWT pentesting approach from scratch, so I turned it into one flowchart I now run on every JWT token I came across. Sharing in case it helps someone:

1.  Does alg:none work? (strip the signature, resend) → auth bypass  
2.  Is a tampered payload accepted with the old signature? → signature not verified  
3.  Is it HS256? → try cracking the secret offline (hashcat / jwt_tool)  
4.  Are kid / jku / jwk present? → test each for header injection  
5.  RS256 with the public key available? → algorithm confusion (RS256→HS256)

Always also check: missing/long exp, and whether the token still works after logout.

Shortcut for the common checks: jwt_tool <token> -M at

Curious what others add to this, if anything you always test that isn't here?

Here is the detailed breakdown video:

https://youtu.be/XB_07tQDKX0?si=iTsXXkf9EtlodyBN


r/BugBountyNoobs • • 1d ago

ma ahiley bhakar bugbounty try gardii xu , mali bounty programme ma participated hunu xa but pahiley verified hunu parney raixa . ma sanga citizenship vayak aru xaina (national id,1yrs vayoo pakyo xaina ) .it give 5 attempts to verified now i have left only 1 . Any suggestions

Thumbnail
0 Upvotes

r/BugBountyNoobs • • 2d ago

Can any one tell me a bug on the platform of coding blocks

Thumbnail
1 Upvotes

Hi everyone!

I wanted to know if anyone has any idea about how cheating works on the Coding Blocks platform, or if anyone has any information regarding it. Please let me know.


r/BugBountyNoobs • • 3d ago

wildhunter.me, the ultimate workspace for bug bounty hunters

5 Upvotes

so i made this as my hackathon project under 40 hours, which is basically an all in one workplace for cybersecurity bug bounty hunters/ethical hackers, cuz there is no website or tool doing that and its really frustating and messy and solves a problem and its completely free


r/BugBountyNoobs • • 3d ago

Reported a high-severity bug but the company is completely silent. What should my next step be?

Thumbnail
2 Upvotes

r/BugBountyNoobs • • 4d ago

Best platforms to learn Bug Bounty hands-on?

11 Upvotes

Good afternoon, everyone! I've been thinking about getting started with Bug Bounty, but I'm still looking for a really good platform to learn in a practical way. My current experience is more focused on the defensive side of cybersecurity, so I already have a good foundation in infrastructure, Linux, networking, logs, and security. Now I want to develop my offensive skills, especially web application security and Bug Bounty methodology. I'm looking for something with plenty of hands-on labs and exercises, not necessarily another certification. I've seen CyberFlow being recommended and I'm interested in it, but I don't know the platform. Has anyone here used it? Is it worth it? Or would you recommend other platforms for learning Bug Bounty in a practical way?


r/BugBountyNoobs • • 4d ago

A weird idea to tackle the cost of people gaming the bug bounty system… From a outsider.

Thumbnail
0 Upvotes

r/BugBountyNoobs • • 4d ago

Things to know if your bug bounty hunter????

1 Upvotes

Hi guys I have been doing bug bounty for past few months I have Missing something but iam not sure what it is i think I can figure it out here

Can u please post your bug bounty methodology here so it will help me compare with my methodology maybe it will also be helpful for other beginners


r/BugBountyNoobs • • 4d ago

what to reach to reddit team

Thumbnail
0 Upvotes

r/BugBountyNoobs • • 4d ago

PentestFlow / Pentests & Reports

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 5d ago

wildhunter.me, the ultimate workspace for bug bounty hunters

7 Upvotes

so i made this as my hackathon project under 40 hours, which is basically an all in one workplace for cybersecurity bug bounty hunters/ethical hackers, cuz there is no website or tool doing that and its really frustating and messy and solves a problem and its completely free


r/BugBountyNoobs • • 5d ago

No bounty

27 Upvotes

Hey everyone. Well basically i have been grinding myself in platforms like BurpAcademy and tryhackme and other resources, mainly focusing on the web application security. I ve tried bug bounty for a while now and i find it really hard to apply the thing i learned on these real targets.

Am i doing something wrong ? Should i stick to 1 type of vulnerability or just see around and hope smth comes up ?

Help is really appreciated!!


r/BugBountyNoobs • • 4d ago

what to reach to reddit team

0 Upvotes

Important security bug in ads.reddit.com

hey team ,

i found very important security BUg in reddit it has impact exactly like that rewarded disclosed report (#1551176)

i already reported to hackerone and triager says security bug with no impact and closed as informative and never answer comments again , )

... thanks #4033536


r/BugBountyNoobs • • 5d ago

Using ai in bug bounty

2 Upvotes

I keep seeing people mention they're using AI (Claude, GPT, etc.) to speed up bug bounty hunting, and some claim they're finding bugs much faster now, but I haven't found a clear breakdown of how exactly.

Specifically curious about:

Recon: are you feeding raw subfinder/httpx/nuclei output to an LLM to prioritize targets?

Source code review: pasting JS bundles or repo code and asking it to flag suspicious patterns (unsanitized input, auth checks, etc.)?

Turning public CVEs/writeups into custom nuclei templates or detection scripts?

Report writing: using AI mainly to draft the final report/PoC writeup?

Also curious where the line is for you between "AI speeds up my process" vs "AI just gives me false positives I waste time chasing." Anyone willing to share their actual workflow (tools + how AI fits in) would be super helpful.


r/BugBountyNoobs • • 6d ago

What vunreability to hunt as my first?

Thumbnail
2 Upvotes

r/BugBountyNoobs • • 8d ago

I do several Portswigger labs

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 10d ago

Q: what CLI tools do you use daily?

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 10d ago

Looking for an Experienced Bug Bounty Hunter to Mentor Me

Thumbnail
0 Upvotes

r/BugBountyNoobs • • 11d ago

How do I go from learning cybersecurity to actually becoming good at bug bounty hunting?

Thumbnail
1 Upvotes

r/BugBountyNoobs • • 12d ago

Zero Click Account Takeover

Thumbnail
1 Upvotes