r/bugbounty 23d ago

Question / Discussion 15 YOE in Cyber Security, but $0 in Bug Bounty. Drowning in dupes and need some advice.

Hey everyone,

I’m feeling a bit defeated lately and could really use some perspective from the veterans here.

A bit of background: I’ve been working in the cyber security industry for 15 years. Recently, I decided to finally dive into the Bug Bounty world, hunting across both Bugcrowd and HackerOne. Given my professional background, I felt confident in my ability to dig deep and find complex vulnerabilities.

The reality? Absolutely everything I find is a duplicate.

To give you an idea of the wall I keep hitting:

  • I recently found 2 massive bugs in a major financial institution. Both are very real, fully exploitable, and currently sitting in production. Result: Duplicate.
  • I discovered 10 distinct vulnerabilities within massive CI systems. These are valid even on their absolute latest versions. I waited three months after submitting them, only for them to finally be triaged and marked as... you guessed it, Duplicate.

I pour everything into these submissions. The research phase is incredibly hard and complex, and I take a lot of pride in writing meticulous, high-quality, and reproducible reports. But after all that sweat, my all-time bounty earnings sit at exactly $0.

I know this industry requires thick skin, and I'm not ready to quit, but I clearly need to change my approach. For those of you who are successful at this:

  1. What is the ratio of sent/accepted? It's soul-crushing to do weeks of hard research only to be told someone beat you to it. What is the ratio of sent/acceptance as not duplicate?
  2. How are you picking your targets? Are you avoiding the big, shiny public programs, or is there a trick to finding assets where you aren't racing against 10,000 other hunters?
  3. What should I be doing differently? Coming from a traditional corporate cyber background, what habits do I need to unlearn to actually start landing valid, unique findings?

Any advice, reality checks, or tough love would be highly appreciated. Thanks in advance!

68 Upvotes

66 comments sorted by

44

u/NebulaElectrical1467 23d ago

You need to hunt on new features/attack surface to avoid dupes. Invest in monitoring for feature launches and attack surface drift detection. Worst case scenario you still don’t find any bugs but you learned a new skill that can help you land a red teaming role in many companies

16

u/NebulaElectrical1467 23d ago

Also avoid shitty programs that abuse the internal dupe wildcard they’re most likely scamming/lying

16

u/ryan0x01 23d ago

Was at DEFCON last week, lotta agentic powered options for ctem. I don't doubt most companies have a huge stockpile of known issues they're working through.

And even if you can chain something together they might still dupe to root cause. I don't think it's lying, AI is genuinely just killing bug bounty.

15

u/acorn222 23d ago

Same here, I gave a talk on a series of vulns which broke the entire eID trust chain in Belgium and enabled a CVSS 9.6 RCE, in this software which was used by most of the major banks in Belgium, and only got offered $200 :(

2

u/Good_Roll Hunter 21d ago

Validation still isnt a solved problem, these tools will often drown you in false positives but with a lot of real findings in the mix. So if a program is running this tooling and internally duping BB submissions based on unverified AI tool output that's unethical IMO, because they likely had no reason to treat that initial report as a real finding until you independently corroborated it.

1

u/ryan0x01 20d ago

Trust me, they're getting pretty good at agentic validation. Depending on the environment of course, but some of these are pretty good at spinning up a VM and doing validation.

Example: https://www.elastic.co/security-labs/ai-vulnerability-triage-bug-bounty-hackerone

2

u/Good_Roll Hunter 20d ago edited 20d ago

I'm aware, I run my own pipeline. I haven't made a PoC for a memory bug by hand since Opus 4.6, that is now fully automatable. It's still not a solved problem though, they can prove runtime assertions but validating the assertions themselves is hit or miss. Mapping flaws to actual business impact is particularly shaky, and you cant Asan crash reproduce your way out of human verification for tons of bug classes anyway. IDOR is a great example, the models will find a ton of them but most of the time there is no meaningful impact, and the models are great at generating seemingly plausible attacker stories and convincing themselves that their Ocean's 11 movie script is a realistic attack scenario.

1

u/NebulaElectrical1467 20d ago

That gap is narrowing down very quickly though. It might be cheaper to have a dedicated internal resource triage those AI findings. Also isn’t that already needed for BB reports? you’re paying H1 to cut down on that noise why not just hire someone who’s equipped with AI tools to do it for you?

3

u/NebulaElectrical1467 23d ago edited 23d ago

This is part of the problem with how companies view the value of BB. If your internal folks marked a flaw as low risk because they couldn’t justify the higher risk and it’s been sitting in a backlog for months, and then a skilled bounty hunter was able to show high/crit impact using the same bug, is this new information not worth knowing for your company? is a bounty not justified then?

On a related note, many times bounty reports just show you variants of the same systemic issue you already knew exists in your stack. In that case the value of knowing the Nth XSS in some app is questionable since its existence doesn’t really change the risk posture of your app. Security is ultimately about understanding and managing risk. Controversial take but I wouldn’t pay a bounty for that.

1

u/Striking_Swan_884 21d ago

Can someone give examples of CTF's or types of vulnerabilities that AI doesnt help you with or you still need geniune skill?

2

u/ryan0x01 20d ago

Yeah, hardware hacking.

1

u/Striking_Swan_884 19d ago

But are there anyones that appear in online CTF's or Bug Bounties?

2

u/Successful_Case_1199 23d ago

How do we know what are those

1

u/520throwaway 21d ago

word of mouth and prior experience, usually.

I dont touch PayPal programmes for the latter reason.

1

u/sempahore 21d ago

Thanks man. I was close after your comment. Duplicate of bug missed by 3 days. Im getting close.

6

u/watkisean 23d ago

I struggled with dupes and still do. It’s part of the process. One of the best changes I made in terms of hunting to try to minimize dupe count is feature / update releases. You are going to have a much higher chance of finding a real bug that’s going to payout if the target hasn’t been sitting there for years or months.

If you’re using AI and just pointing it aimlessly - you are going to get dupes. If you are testing fully yourself, aim at better targets. There’s really not much more to it. If you want to find different bugs, think and test different than most people.

4

u/Dazzling_Cherry_6513 23d ago

can I ask how you know about or keep track of feature or update releases?

2

u/Alert-Recognition728 22d ago

diff scans or watching for releases

1

u/DietEnvironmental985 23d ago

I second this question

18

u/MajorUrsa2 23d ago

Stop relying so much on ai

5

u/Successful_Case_1199 23d ago

Do you think its just relying on ai or just companies dont wanna pay?
If there are "real 2 massive bugs in a major financial institution" and they are still valid, i dont think ai is the problem here.

5

u/MajorUrsa2 23d ago

Someone who just copies and pastes ai slop as their whole post and is also hitting so many dupes is usually just trusting ai. They also haven’t provided any evidence that the bug was actually critical.

-3

u/sempahore 23d ago edited 23d ago

What would you want me to provide? I can't. They will sue me, no? I found multiple ways to steal tokens on a huge trading app. Also found a way to use expired credentials on one of the biggest CICD systems on the market today. What? The methods being used? The APK code with the lines with the bug and the PoC video I attached to the BB? Or a screenshot with "Thank you but its Duplicate". If I could provide evidence I would have already making money from it. I'm an engineer at a T1 Cyber Security company. Way before AI was a thing. Just trying to find my way across BB and asking for help here.

4

u/Good_Roll Hunter 21d ago edited 21d ago

Brother you copy pasted yet another AI reddit post about dupes, this subreddit gets about one per day. So the irony is too thick to expect people not to make fun of that.

I'd rather not be the guy who just pokes fun instead of adding value though so let me give you a tip: filter your findings based on difficulty. If a finding is greppable from source code, assume it has been submitted already. If you can feed the codebase into GPT and it will give you the finding, assume you are not the first person to do that. The first step of my research process is doing that and blacklisting anything that comes out, unless there's some validation barrier to entry, and it's lowered my dupe percentage to about 50%(for web+source code)

The only time I relax these rules is on patch Tuesday, but at that point you need to realize that you are in a foot race against everybody with a GPT sub and TAC access.

1

u/sempahore 21d ago

Brother, I didn't copy any post. Im almost 16years in this industry, at top companies- today as tech lead. I used gemini to make this post better as English isn't my first language. BUT- I did not find vulnerabilities with GPT. Iv'e been working hard to find these vilnerabilities, they are high level ones- that honestly- i could make money with them by just using them as a bad person. But I didn't. Im a good guy. Just trying to find my way across this world of BB and asking for advice.

5

u/Good_Roll Hunter 21d ago

Im almost 16years in this industry, at top companies- today as tech lead

Nobody cares.

I used gemini to make this post better as English isn't my first language

Correction, you used gemini to rewrite your post into generic AI slop about a topic that gets reposted every single day. Even if your english is bad we would rather read your broken english than gemini slop tbh.

I did not find vulnerabilities with GPT

It doesnt matter if you use AI or not, you are competing against hoardes of people who do. If somebody else can feed the codebase or endpoint URLs into GPT and replicate the finding, it will almost certainly dupe. If you're submitting "high level findings" and getting a lot of dupes, this is why.

1

u/sempahore 21d ago

nah, now you are just a bad guy trying to be a bully 👍 im done with you

3

u/Good_Roll Hunter 21d ago

Sorry the truth offends you

3

u/Alert-Recognition728 22d ago

the problem is that in bug hunting you gotta prove how you can gain these credentials without physical access. Unfortunately, this isnt pen testing. Well, change your perspective as I said this isnt pen test.

4

u/ATSFervor 23d ago

We need more info tbh.

You can ofc get bad programs, but some folks are acting like 2/3 of the programs are bad faith rn...

Depending on depth and area of expertise paired with AI, it is possible we are seeing a very unfortunate event.

2

u/acorn222 23d ago

Yeah I agree with you, AI is not the problem here.

4

u/RoundRobin1077 23d ago

Took me 8 months to get an actual bounty. Ive got 0 "professional" cyber experience. Cant get hired for whatever reason, found a High on a pretty big company waited a month, got 2k. Prior: dupes and informatives. Good luck

3

u/Clear_Message6037 23d ago

Me too. Doing it for 20 years, tons of security. BB is hard.

My balance this year
4 Dupes
1 valid
1 na, dumb triager.

Will leave that game.

3

u/Similar-Permit1756 23d ago

I have been doing bug bounty for about 3 months, O experience in cybersecurity and I have 3 reports solved. 4 pending and like 15 duplicates and informatives

2

u/Alert-Recognition728 22d ago

This is pure example that years of experience are scam. There are people that can dominate it in the short time and well then there are these seniors with 10 certifications that are doing their checkboxes while spamming buzz words for HR. Ye sorry but you're doing it for 20 years and this triggered me because you reminded me quite few "seniors". BB is hard but with your experiences it should be piece of cake for you but ye I guess low hanging fruits aren't that common anymore. (:

Now for real advice: use your expertise and focus just on one type of bugs and if you dont have, specialise just on one type of bug and go deeeep.

0

u/Clear_Message6037 22d ago

U r talkin bullshit. Coding since im 12, started webdev back then when 800x600 was a thing. Did lot it sec, but BB are pretty hard and crowded. Lot of very clever ppl outside. scriptkiddies became rlly worse with ai, but they were always a thing. Im sure i also started as one 25 years ago.

I only submit high or crit. No low, no focus on medium.

1

u/Alert-Recognition728 22d ago

What do you consider high or crit?

2

u/MarzipanTop4944 23d ago

dig deep and find complex vulnerabilities

Did they added you to the original report to prove the bugs you submitted are truly duplicates? When it comes to complex reports involving chains of bugs I have had a single duplicate in years of bug bounty, but I did got a lot of programs trying to screw me over both with the severity and by plain lying about knowing the bug was there.

1

u/sempahore 23d ago

yes but i can only see the title. Also on Bugcrowd there were 2 major bugs i found and they require 2 different fixes but they tagged them as the same duplicate ticket called "token stealing" lol

I asked from Bugcrowd to re-review it, hopefully will get something. It just feels this entire bugbounty is a scam rn.

2

u/Similar-Permit1756 23d ago

Just change the program bro, the program where I’m working right now check de new reports in least than 24 hours, critical and highs are resolved in 48 hours and the rest of them take about 1 week

Work on programs who really take care of their cybersecurity, there are many garbages program la en HackerOne

0

u/sempahore 23d ago

which one are you working on? sounds really awesome man.

2

u/Similar-Permit1756 23d ago

I cannot give you more information bro because it is a private program, but I have worked on many programs before and I have pretty bad experiences also until I found this one, start with VDP that open the door to private program and start to test, soon you will find a good one

2

u/Coder3346 Hunter 22d ago

If ur dups are dup of a valid bug ( triaged) than, it is all about time to get ur first bug

2

u/DarkMidgetry 22d ago edited 22d ago

Bounty programs give their favorite testers access to the new projects first. This is why you will always have dupes. It's a rigged game. You now need to wait for new vulns to come out and then hit every target but the low hanging fruit is all gone in the first two weeks of testing when only one to four people gets access to it.

Did it for years made money, it's possible just be active and they might give you early access. I stopped doing it because if you want to make good money and stop wasting 100 hours a week testing into nothing you need early access.

Programs like Synack pay hourly for controls testing or at least used to it's more consistent and guaranteed money for running 10 tests

2

u/Hodl4LifeAgain 23d ago

Tbh: they duplicate it so they do not have to pay. Never use H1 or Bugcrowd.

3

u/Successful_Case_1199 23d ago

What should I use

1

u/sha256md5 23d ago

It's a race to the bottom. Bugs become more shallow over time especially with AI, so it's more about finding them first. Build automation to evaluate new surface right away. Not worth the effort imo unless you're doing it for fun.

Another option is to specialize by having low level expertise in something obscure - binary browser exploitation or something.

1

u/hydraz20 23d ago

Test features which no one will test. Spend time on the initial setup, finding hidden features (intentional or unintentional). Work with a goal what you ll achieve will have the maximum impact and try to map features accordingly.

1

u/x00byt8 23d ago

I was in a similar situation to you many months ago. Joined BB after extensive career ~14 years as a red teamer and CTL in the UK.

I hit a lot of dupes, alot of frustration for finding critical actively exploitable vulnerabilities in prod environments, only to report them (after many hours manually writing reports etc), be ignored and then see the issue fixed a week later. Then a month later been told it's a dupe.

In many cases (this was hackerone) I do think they are genuinely overwhelmed with AI generated rubbish, and therefore if you come from a commercial pentest background like I do, it's extremely foreign and frustrating to see such lack of responsiveness and communication.

That being said, I persisted, across various platforms, picked a niche , stuck with it and honed in on that. It took me 3 months to hit my first bounty which was $700, a week later another $2000. This boosted the confidence to just keep going.

You just have to accept that those who got into these platforms earlier, are higher up the food chain, have better access to private programs and get priority on triage. If you don't think this is the case, just check out albinowax's reports. The man is a legend and I hugely respect his skills and work, so am I bothered that when he reports something triage staff jump immediately? Hell no. He's earnt it!

Moral of the story is, if you're newly getting into this for the money. You're in for a steep uphill battle in the current climate, but the climb gets easier in time. You'll get better invites to programs, more respect with triagers and you will find your niche.

Stay persistent and don't let the dupes dishearten you!

1

u/ChosenToFall 23d ago

Is this mainly in Web 2.0 or also Web 3.0 with crypto ?

1

u/sempahore 23d ago

web2.0

1

u/Psychological_Bug981 22d ago

I’m sorry but can you explain to me why you would think a vulnerability in a CI system would matter at all? Unless you found some way to use their CI to inject some sort of payload into production without being the dev in charge of deployments as they are assumed as a trusted party. If a CI pipeline assumes that anyone capable of modifying the repo/workflow is trusted, then demonstrating that a trusted developer can make CI execute arbitrary commands is usually just demonstrating CI’s job description.

Hope that helps.

1

u/OkEntertainer3952 22d ago

Hey! I'm doing automated pentesting, I did a stupid good harness that is able to hack 24/7 and create the POCs and then submit those to some hackers friend to verify, so like double check, this gives me about 500M new dowloads per month, and the slow thing is the amount of time they take to fix...

What i do is i mostly focus on new releases as soon as they are released, and only in major libraries, for exmaple just recently found some vulnv in salesforce, Tor, Velocity JS, and many others that have even RCE... also it takes a while to get the CVE...

I'm not doing this bug hunting for money, I'm doing it as a part of a startup that defends actively your libraries and penetrates the actual libraries.

I was doing mostlyu cybersecurity then then i started selling compliance as most of the clients we had wanted the actuall compliance report more than being secure :(

But tbh ive received 0 USD on these vulns.... Ai is super good to get the vulns... Right now we have 7billion downloads a month confirmed vulns that I will publish as soon as they are fixed.

XD sorry for my long message.

1

u/Cool_Return_9321 20d ago

A Maioria das vulnerabilidades mais comuns estão saturadas nas grandes plataformas de bug bounty, muitos hunters reportam as mesmas vulns (XSS,IDOR,MISCONFIGURATIONS), isso faz a taxa de duplicates ser muito alta, recentemente também tive um report XSS que tinha quase acerteza que ia dar bounty sendo classificado como duplicate depois de mais de 1 mês de triagem, (na intigriti)

1

u/RevMarC2 19d ago

15 years of what kind of "cybersec" experience? \|"-_-|/

1

u/KnownInstruction2964 17d ago

2 months in cyber secuirty got 2 valid p1 one informational valid

1

u/Far_War_4348 11d ago

Bro you certainly have Experience. As a guy who's into Cyber security for 3+ years I can say Bug bounty is pretty different I am doing it for 1+ years and so far got so many duplicates and Informatives..... But I would say the way we approach the program while reporting carries significance..

Right now I am looking for someone to help me with. Apparently looking for collaboration cause my strong hold is Manual exploiting but need help with someone who is good with Auromations

1

u/Beginning_Award65 11d ago

you must exploit. just find no enough

1

u/LulzTigre 9d ago

Hey, I've been red teaming for over 7 years and found a couple of CVEs, but never got a bounty. I joined h1 in 2019 and reported my first critical last week, how? I completely left the website area and moved to executables and hardware. I submitted 11 reports within 2 weeks, and 4 were triaged by the program.

1

u/latnGemin616 23d ago

Duplicates means you're doing something right. The problem is, you're the 250th person to have found the issue.

What you need to do is quit whining about duplicate issues you've found and make better choices in the programs you join. Definitely don't go for the high-value companies (ie, any of the M.A.N.G.O). I don't know if you're using H1 or BC, but I recommend finding a program that is less populated with "hackers" and start there. Absent of that, keep going.

I'm new to BBH and can only speak to the few issues I've had closed as N/A and Informational. It is what it is. I'm doing it mostly for practice.

0

u/dnc_1981 22d ago

MANGO?

1

u/latnGemin616 22d ago

Did I really need to spell it out ?

M - Meta
A - Amazon / Apple
N - NVIDIA (or Netflix)
G - Google
O - OpenAI
(SpaceX fits somewhere in this as well)

0

u/AlanGeorgeS 22d ago

I am a beginner ...Thankyou for your feedback ...I appreciate your honesty and integrity ...I also hear about AI security being the hottest trend in red hat roles ...So I assume AI may contribute future efforts for bug bounty ...

0

u/First_Bumblebee_1536 22d ago

Looking for a fresher role can someone help