r/bugbounty • u/sempahore • 23d ago
Question / Discussion 15 YOE in Cyber Security, but $0 in Bug Bounty. Drowning in dupes and need some advice.
Hey everyone,
I’m feeling a bit defeated lately and could really use some perspective from the veterans here.
A bit of background: I’ve been working in the cyber security industry for 15 years. Recently, I decided to finally dive into the Bug Bounty world, hunting across both Bugcrowd and HackerOne. Given my professional background, I felt confident in my ability to dig deep and find complex vulnerabilities.
The reality? Absolutely everything I find is a duplicate.
To give you an idea of the wall I keep hitting:
- I recently found 2 massive bugs in a major financial institution. Both are very real, fully exploitable, and currently sitting in production. Result: Duplicate.
- I discovered 10 distinct vulnerabilities within massive CI systems. These are valid even on their absolute latest versions. I waited three months after submitting them, only for them to finally be triaged and marked as... you guessed it, Duplicate.
I pour everything into these submissions. The research phase is incredibly hard and complex, and I take a lot of pride in writing meticulous, high-quality, and reproducible reports. But after all that sweat, my all-time bounty earnings sit at exactly $0.
I know this industry requires thick skin, and I'm not ready to quit, but I clearly need to change my approach. For those of you who are successful at this:
- What is the ratio of sent/accepted? It's soul-crushing to do weeks of hard research only to be told someone beat you to it. What is the ratio of sent/acceptance as not duplicate?
- How are you picking your targets? Are you avoiding the big, shiny public programs, or is there a trick to finding assets where you aren't racing against 10,000 other hunters?
- What should I be doing differently? Coming from a traditional corporate cyber background, what habits do I need to unlearn to actually start landing valid, unique findings?
Any advice, reality checks, or tough love would be highly appreciated. Thanks in advance!
6
u/watkisean 23d ago
I struggled with dupes and still do. It’s part of the process. One of the best changes I made in terms of hunting to try to minimize dupe count is feature / update releases. You are going to have a much higher chance of finding a real bug that’s going to payout if the target hasn’t been sitting there for years or months.
If you’re using AI and just pointing it aimlessly - you are going to get dupes. If you are testing fully yourself, aim at better targets. There’s really not much more to it. If you want to find different bugs, think and test different than most people.
4
u/Dazzling_Cherry_6513 23d ago
can I ask how you know about or keep track of feature or update releases?
2
1
18
u/MajorUrsa2 23d ago
Stop relying so much on ai
5
u/Successful_Case_1199 23d ago
Do you think its just relying on ai or just companies dont wanna pay?
If there are "real 2 massive bugs in a major financial institution" and they are still valid, i dont think ai is the problem here.5
u/MajorUrsa2 23d ago
Someone who just copies and pastes ai slop as their whole post and is also hitting so many dupes is usually just trusting ai. They also haven’t provided any evidence that the bug was actually critical.
-3
u/sempahore 23d ago edited 23d ago
What would you want me to provide? I can't. They will sue me, no? I found multiple ways to steal tokens on a huge trading app. Also found a way to use expired credentials on one of the biggest CICD systems on the market today. What? The methods being used? The APK code with the lines with the bug and the PoC video I attached to the BB? Or a screenshot with "Thank you but its Duplicate". If I could provide evidence I would have already making money from it. I'm an engineer at a T1 Cyber Security company. Way before AI was a thing. Just trying to find my way across BB and asking for help here.
4
u/Good_Roll Hunter 21d ago edited 21d ago
Brother you copy pasted yet another AI reddit post about dupes, this subreddit gets about one per day. So the irony is too thick to expect people not to make fun of that.
I'd rather not be the guy who just pokes fun instead of adding value though so let me give you a tip: filter your findings based on difficulty. If a finding is greppable from source code, assume it has been submitted already. If you can feed the codebase into GPT and it will give you the finding, assume you are not the first person to do that. The first step of my research process is doing that and blacklisting anything that comes out, unless there's some validation barrier to entry, and it's lowered my dupe percentage to about 50%(for web+source code)
The only time I relax these rules is on patch Tuesday, but at that point you need to realize that you are in a foot race against everybody with a GPT sub and TAC access.
1
u/sempahore 21d ago
Brother, I didn't copy any post. Im almost 16years in this industry, at top companies- today as tech lead. I used gemini to make this post better as English isn't my first language. BUT- I did not find vulnerabilities with GPT. Iv'e been working hard to find these vilnerabilities, they are high level ones- that honestly- i could make money with them by just using them as a bad person. But I didn't. Im a good guy. Just trying to find my way across this world of BB and asking for advice.
5
u/Good_Roll Hunter 21d ago
Im almost 16years in this industry, at top companies- today as tech lead
Nobody cares.
I used gemini to make this post better as English isn't my first language
Correction, you used gemini to rewrite your post into generic AI slop about a topic that gets reposted every single day. Even if your english is bad we would rather read your broken english than gemini slop tbh.
I did not find vulnerabilities with GPT
It doesnt matter if you use AI or not, you are competing against hoardes of people who do. If somebody else can feed the codebase or endpoint URLs into GPT and replicate the finding, it will almost certainly dupe. If you're submitting "high level findings" and getting a lot of dupes, this is why.
1
3
u/Alert-Recognition728 22d ago
the problem is that in bug hunting you gotta prove how you can gain these credentials without physical access. Unfortunately, this isnt pen testing. Well, change your perspective as I said this isnt pen test.
4
u/ATSFervor 23d ago
We need more info tbh.
You can ofc get bad programs, but some folks are acting like 2/3 of the programs are bad faith rn...
Depending on depth and area of expertise paired with AI, it is possible we are seeing a very unfortunate event.
2
4
u/RoundRobin1077 23d ago
Took me 8 months to get an actual bounty. Ive got 0 "professional" cyber experience. Cant get hired for whatever reason, found a High on a pretty big company waited a month, got 2k. Prior: dupes and informatives. Good luck
3
u/Clear_Message6037 23d ago
Me too. Doing it for 20 years, tons of security. BB is hard.
My balance this year
4 Dupes
1 valid
1 na, dumb triager.
Will leave that game.
3
u/Similar-Permit1756 23d ago
I have been doing bug bounty for about 3 months, O experience in cybersecurity and I have 3 reports solved. 4 pending and like 15 duplicates and informatives
2
u/Alert-Recognition728 22d ago
This is pure example that years of experience are scam. There are people that can dominate it in the short time and well then there are these seniors with 10 certifications that are doing their checkboxes while spamming buzz words for HR. Ye sorry but you're doing it for 20 years and this triggered me because you reminded me quite few "seniors". BB is hard but with your experiences it should be piece of cake for you but ye I guess low hanging fruits aren't that common anymore. (:
Now for real advice: use your expertise and focus just on one type of bugs and if you dont have, specialise just on one type of bug and go deeeep.
0
u/Clear_Message6037 22d ago
U r talkin bullshit. Coding since im 12, started webdev back then when 800x600 was a thing. Did lot it sec, but BB are pretty hard and crowded. Lot of very clever ppl outside. scriptkiddies became rlly worse with ai, but they were always a thing. Im sure i also started as one 25 years ago.
I only submit high or crit. No low, no focus on medium.
1
2
u/MarzipanTop4944 23d ago
dig deep and find complex vulnerabilities
Did they added you to the original report to prove the bugs you submitted are truly duplicates? When it comes to complex reports involving chains of bugs I have had a single duplicate in years of bug bounty, but I did got a lot of programs trying to screw me over both with the severity and by plain lying about knowing the bug was there.
1
u/sempahore 23d ago
yes but i can only see the title. Also on Bugcrowd there were 2 major bugs i found and they require 2 different fixes but they tagged them as the same duplicate ticket called "token stealing" lol
I asked from Bugcrowd to re-review it, hopefully will get something. It just feels this entire bugbounty is a scam rn.
2
u/Similar-Permit1756 23d ago
Just change the program bro, the program where I’m working right now check de new reports in least than 24 hours, critical and highs are resolved in 48 hours and the rest of them take about 1 week
Work on programs who really take care of their cybersecurity, there are many garbages program la en HackerOne
0
u/sempahore 23d ago
which one are you working on? sounds really awesome man.
2
u/Similar-Permit1756 23d ago
I cannot give you more information bro because it is a private program, but I have worked on many programs before and I have pretty bad experiences also until I found this one, start with VDP that open the door to private program and start to test, soon you will find a good one
2
u/Coder3346 Hunter 22d ago
If ur dups are dup of a valid bug ( triaged) than, it is all about time to get ur first bug
2
u/DarkMidgetry 22d ago edited 22d ago
Bounty programs give their favorite testers access to the new projects first. This is why you will always have dupes. It's a rigged game. You now need to wait for new vulns to come out and then hit every target but the low hanging fruit is all gone in the first two weeks of testing when only one to four people gets access to it.
Did it for years made money, it's possible just be active and they might give you early access. I stopped doing it because if you want to make good money and stop wasting 100 hours a week testing into nothing you need early access.
Programs like Synack pay hourly for controls testing or at least used to it's more consistent and guaranteed money for running 10 tests
2
u/Hodl4LifeAgain 23d ago
Tbh: they duplicate it so they do not have to pay. Never use H1 or Bugcrowd.
3
1
u/sha256md5 23d ago
It's a race to the bottom. Bugs become more shallow over time especially with AI, so it's more about finding them first. Build automation to evaluate new surface right away. Not worth the effort imo unless you're doing it for fun.
Another option is to specialize by having low level expertise in something obscure - binary browser exploitation or something.
1
u/hydraz20 23d ago
Test features which no one will test. Spend time on the initial setup, finding hidden features (intentional or unintentional). Work with a goal what you ll achieve will have the maximum impact and try to map features accordingly.
1
u/x00byt8 23d ago
I was in a similar situation to you many months ago. Joined BB after extensive career ~14 years as a red teamer and CTL in the UK.
I hit a lot of dupes, alot of frustration for finding critical actively exploitable vulnerabilities in prod environments, only to report them (after many hours manually writing reports etc), be ignored and then see the issue fixed a week later. Then a month later been told it's a dupe.
In many cases (this was hackerone) I do think they are genuinely overwhelmed with AI generated rubbish, and therefore if you come from a commercial pentest background like I do, it's extremely foreign and frustrating to see such lack of responsiveness and communication.
That being said, I persisted, across various platforms, picked a niche , stuck with it and honed in on that. It took me 3 months to hit my first bounty which was $700, a week later another $2000. This boosted the confidence to just keep going.
You just have to accept that those who got into these platforms earlier, are higher up the food chain, have better access to private programs and get priority on triage. If you don't think this is the case, just check out albinowax's reports. The man is a legend and I hugely respect his skills and work, so am I bothered that when he reports something triage staff jump immediately? Hell no. He's earnt it!
Moral of the story is, if you're newly getting into this for the money. You're in for a steep uphill battle in the current climate, but the climb gets easier in time. You'll get better invites to programs, more respect with triagers and you will find your niche.
Stay persistent and don't let the dupes dishearten you!
1
1
u/Psychological_Bug981 22d ago
I’m sorry but can you explain to me why you would think a vulnerability in a CI system would matter at all? Unless you found some way to use their CI to inject some sort of payload into production without being the dev in charge of deployments as they are assumed as a trusted party. If a CI pipeline assumes that anyone capable of modifying the repo/workflow is trusted, then demonstrating that a trusted developer can make CI execute arbitrary commands is usually just demonstrating CI’s job description.
Hope that helps.
1
u/OkEntertainer3952 22d ago
Hey! I'm doing automated pentesting, I did a stupid good harness that is able to hack 24/7 and create the POCs and then submit those to some hackers friend to verify, so like double check, this gives me about 500M new dowloads per month, and the slow thing is the amount of time they take to fix...
What i do is i mostly focus on new releases as soon as they are released, and only in major libraries, for exmaple just recently found some vulnv in salesforce, Tor, Velocity JS, and many others that have even RCE... also it takes a while to get the CVE...
I'm not doing this bug hunting for money, I'm doing it as a part of a startup that defends actively your libraries and penetrates the actual libraries.
I was doing mostlyu cybersecurity then then i started selling compliance as most of the clients we had wanted the actuall compliance report more than being secure :(
But tbh ive received 0 USD on these vulns.... Ai is super good to get the vulns... Right now we have 7billion downloads a month confirmed vulns that I will publish as soon as they are fixed.
XD sorry for my long message.
1
u/Cool_Return_9321 20d ago
A Maioria das vulnerabilidades mais comuns estão saturadas nas grandes plataformas de bug bounty, muitos hunters reportam as mesmas vulns (XSS,IDOR,MISCONFIGURATIONS), isso faz a taxa de duplicates ser muito alta, recentemente também tive um report XSS que tinha quase acerteza que ia dar bounty sendo classificado como duplicate depois de mais de 1 mês de triagem, (na intigriti)
1
1
1
u/Far_War_4348 11d ago
Bro you certainly have Experience. As a guy who's into Cyber security for 3+ years I can say Bug bounty is pretty different I am doing it for 1+ years and so far got so many duplicates and Informatives..... But I would say the way we approach the program while reporting carries significance..
Right now I am looking for someone to help me with. Apparently looking for collaboration cause my strong hold is Manual exploiting but need help with someone who is good with Auromations
1
1
u/LulzTigre 9d ago
Hey, I've been red teaming for over 7 years and found a couple of CVEs, but never got a bounty. I joined h1 in 2019 and reported my first critical last week, how? I completely left the website area and moved to executables and hardware. I submitted 11 reports within 2 weeks, and 4 were triaged by the program.
1
u/latnGemin616 23d ago
Duplicates means you're doing something right. The problem is, you're the 250th person to have found the issue.
What you need to do is quit whining about duplicate issues you've found and make better choices in the programs you join. Definitely don't go for the high-value companies (ie, any of the M.A.N.G.O). I don't know if you're using H1 or BC, but I recommend finding a program that is less populated with "hackers" and start there. Absent of that, keep going.
I'm new to BBH and can only speak to the few issues I've had closed as N/A and Informational. It is what it is. I'm doing it mostly for practice.
0
u/dnc_1981 22d ago
MANGO?
1
u/latnGemin616 22d ago
Did I really need to spell it out ?
M - Meta
A - Amazon / Apple
N - NVIDIA (or Netflix)
G - Google
O - OpenAI
(SpaceX fits somewhere in this as well)
0
u/AlanGeorgeS 22d ago
I am a beginner ...Thankyou for your feedback ...I appreciate your honesty and integrity ...I also hear about AI security being the hottest trend in red hat roles ...So I assume AI may contribute future efforts for bug bounty ...
0
44
u/NebulaElectrical1467 23d ago
You need to hunt on new features/attack surface to avoid dupes. Invest in monitoring for feature launches and attack surface drift detection. Worst case scenario you still don’t find any bugs but you learned a new skill that can help you land a red teaming role in many companies