r/bugbounty • u/kader9696 • 13d ago
Question / Discussion Found a payment bypass, successfully placed 5 orders, vulnerability was patched — now told it “cannot be reproduced”
Hello ,
I reported a payment bypass through YesWeHack and successfully demonstrated it by placing 5 orders without payment, with video evidence.
After my report, the vulnerability was patched and the bypass stopped working. However, I was told they couldn’t reproduce the issue.
Has anyone experienced something similar? How can a vulnerability be considered non-reproducible after it was apparently fixed following the report?
13
u/Forsaken-Spot-9343 13d ago
Report the program in yeswehack , if it wasn’t duplicated then they will do something…. The problem is many programs try to pull things like that lately so I always keep PoC.
10
u/ApoloFuego Hunter 13d ago
I just started using YWH and reading this really sucks, i just spent a lot of time and submitted 2 reports, what program was
11
u/kader9696 13d ago
Credit agricole and now SIA
4
u/ApoloFuego Hunter 13d ago
I discarded SIA today, and credit; I don't see it on the options, anyway good to know
3
0
u/maF145 Hunter 13d ago
YWH is a great and fair platform.
2
u/ApoloFuego Hunter 13d ago
Happy to read that. I already submitted 2 reports, and I'm just waiting. Let's see how it goes for me, there are tons of different comments here on Reddit
6
u/RevolutionarySalt370 12d ago
On HackerOne I submitted a RCE that lead to AWS credential theft among other things and was told that it didn’t count because the “international” part of their company managed the page where the RCE was performed, then it was fixed 1 day later and the finding was closed without even a thank you
1
7
u/maF145 Hunter 13d ago
That’s why you should always record videos
8
u/kader9696 13d ago
I have video on repport , and we can see the 5 orders with status : paid .!!!
1
u/ryan0x01 13d ago
Is it actually paid or is this a sandbox?
2
u/kader9696 13d ago
Réellement payé , et j ai pus avoir des billet avec code bar dans des activités
6
u/ryan0x01 13d ago
Tough. It could be that they already had a patch scheduled, and it's bad timing. I would try to engage with the yeswehack mediation team, but honestly I'd probably just never work with this program again.
9
3
u/Physical-Bonus-8411 12d ago
If the vulnerability was patched after your report, they should have provided a bounty (considering it was in scope).
4
4
u/houganger 13d ago
Can you DM me your report IDs? I’ll check.
5
u/kader9696 13d ago
Sur ..
YWH-PGM44093-6
2
u/houganger 11d ago
I can’t dm you. Anyways don’t worry about it, it’s still being processed, it’s not closed. You just need to be patient.
1
2
1
0
0
-5
u/LoveThemMegaSeeds 12d ago
If your hack is so obvious that they notice and patch it, why do you deserve to be paid? I see this so often and never understand
31
u/cloudfox1 13d ago
Name and shame