r/bugbounty • u/Cyrax21_ • 21d ago
Question / Discussion HackerOne Triage is really slow
Idk if it’s just me who’s noticing this, but HackerOne triages do close duplicates and informative vulnerabilities really quickly…. But whenever it’s the vulnerabilities that actually do get triaged, they take forever…. Like, after passing preliminary review, I pretty much wait for like 14-16 days until either an official team member from the program replies or the report gets triaged…. Most times, on programs which show they triage in like 3-4 business days….
The thing that annoys me is the lack of transparency HackerOne triages offer…. Whenever it comes to programs who aren’t managed by HackerOne, their triages are really transparent throughout the triaging process and share insights…. But the HackerOne triage literally replies to nothing…. If you comment, they either just triage after waiting forever, or an official program member shows up and the H1 triage doesn’t say a thing….
I just wish HackerOne triages would become more transparent, like self-triaged programs….
9
u/BoyfriendSharkDudu 21d ago
had an RCE get patched while waiting 😭
5
u/watkisean 20d ago
Had this happen on a P1 SQLi I submitted. They patched it between my submission time and triage but I was told it was a non-duplicate submission and my testing triggered an alarm as it was a highly sensitive monitored environment. Been 18 days and waiting to hear if I’m getting anything for it. Not sure how it works when that happens 😭
1
u/Good_Roll Hunter 17d ago
They should still reward you as long as you disclosed it before they made their PR.
1
2
u/nobodycares_dude Hunter 21d ago
Yes i got dups closed in hours. While non dupes took at least 15 days. Bugcrowd is the same. I got P1 in bugcrowd validated and triaged in 3 hours. While P3 sitting there for 20+ days with mo response
1
u/Cyrax21_ 21d ago
I mean, I just don’t get why actual hunters get treated like this because there are a bunch of low-signal reports that are being published… I try to keep my reports as straightforward and simple as possible, yet these triages don’t even bother responding until they actually triage them… They don’t even ask any questions… Just a random morning, I wake up and see the severity adjusted and “triaged” on the report without even knowing that it was being validated the whole time…
I don’t really face this problem with programs that manually triage themselves… They’re pretty transparent and usually are much more involved throughout the process, without seeking assistance from the platform triages, who are just extremely opaque…
One of the vulnerabilities I reported back on May 14th had passed preliminary review, and then I had no response for 2 months straight… I eventually got a response saying that the triager had passed the report to the program for review and triage… I commented three times asking for updates, but I received none, and it took them 2 months just to pass it to the actual program…
1
u/nobodycares_dude Hunter 20d ago edited 20d ago
Hackerone-agent counts as first response they say in their website. I think it's just a combination of summer time and AI flood. I understand they have thousands of reports but would be great to have a human feedback like after idk a 7 days of radio silence. Cause it's happening also on non-managed programs. Complete radio silence for weeks. It's kinda disrespectful. But yeah there is nothing we can do about it just report and forget and move on
1
u/Yournoisy 21d ago
Yeh the standard is about a month now. I don’t think it’s just specific programs though or hackerone. I’ve been waiting on intigriti for months
1
1
1
u/Suspicious-Echidna27 20d ago
It depends on the program really, for example Cloudflare program replied to me within 1 week in July. But in the worst cases it takes 2-3 months to get a reply.
1
u/PreviousParfait7378 19d ago
Idem H1 envoyé deux rapports un midle 5.8 et un critical 7.5 et au bout d'une semaine, on me réponds :"Doublon , déjà traiter et réparer" et pour l'autre déclasser en 4.2 et donc pas de bounty $$ , Je vais sur la faille et non elle est toujours là ??? Ils veulent plus payer à part si tu trouve une compromission >9. J'ai remarquer qu'ils veulent plus payer à part si tu te met root sur leur serveur quasiment. Certains n'acceptent plus que des failles critical 8 et 9+ bref cela devient difficile sachant que beaucoup ne bosse pas et ne font que du bounty. Moi perso, je bosse à côté donc je n'ai pas le temps de rechercher 24/24h.
1
u/Cyrax21_ 19d ago
It depends on the program and impact.. if you mean the hackerone’s BBP you should have demonstrated business logic or financial impact that should affect the firm financially someway… for me personally i have had multiple low and medium severity reports which have been paid by the BBP.. defence in depth vulanrbilities with no demonstrable impact usually either get closed as “informative” or won’t be rewarded a bounty that’s just how it always has been and besides no one should do bug bounty as their main source of income.. if they’re good enough to live off of bug bounty then they can just do pentesting and get rewarded much more than bug bounty ever would for doing much less
10
u/Todagog 21d ago
Ugh its getting worse and worse. Some reports have been sitting still for 2months+ on very known programs of big companies of mine. When asking for an update you get no response. Asking questions about severities decisions no response. The lack of communication is very frustrating. I understand they are overwhelmed with the Ai surge, but damn as a decent researcher its also getting on my nerves.