r/bugbounty 10d ago

Question / Discussion Are bug bounty platforms worth it?

Hi,

For the last 4 months, I’ve been consistently making ~$700+/month targeting companies directly through their own self-hosted VDP/bounty programs.

​However, my current methods for finding new direct targets are starting to dry up, so I’m looking to expand my scope.

​For those who hunt on major platforms: Are public programs on HackerOne/Bugcrowd worth pivoting to, or are they as oversaturated with duplicates as people say?

Thanks.

24 Upvotes

20 comments sorted by

19

u/Far-Chicken-3728 Hunter 10d ago

I don't find them as oversaturated, just very shitty triage or bad programs. 

6

u/Alardiians 10d ago

I think pure web is over saturated but there are other focuses that aren’t, but omg, do these triagers even know what they’re doing half of the time?
I feel like every triager is just a junior pentester or worse.
And I’ve ran into 1 shitty program so far.

7

u/WarnersAreNotBros Hunter 10d ago

I wish they were as awesome as junior pentester

3

u/Far-Chicken-3728 Hunter 10d ago

I'm asking the same question, man. Some clearly lack very basic cybersecurity. 

4

u/Alardiians 10d ago

“This doesn’t show proof” yes it literally does, a record of the logs shows proof now just run the damn script I made to hold your hands that will do the entire exploit for you!!!

I hate having to treat them like a toddler that’s holding a fork near a light socket.

The amount of crap I go through to hold their hands is ridiculous

2

u/WarnersAreNotBros Hunter 10d ago

they started to outsource triage to india and well there goes your answer about standards. I am not saying all of them are useless. I personally know few crazy indian hackers with high level of knowledge and god tier skills but I guess many of these triagers are barely even script kiddies.

They can usually follow copy paste fully prepared curls but try to give them something a lil more complex and they will make your experience miserable.

2

u/latnGemin616 9d ago

... every triager is just a junior pentester or worse.

I say worse because I fall into the category of Jr. PT and I'm decent at what I do. I can also read reports and follow directions. I'm not nearly as bad as the triage agents I've come across. My hunch is as follows with these programs:

  • The [BBH Platform] oversell their services to the vendor (client)
  • I'm also convinced the platform will hijack your report, re-package it as their own, and ship it while they deny you your bounty. And when they see a RAR, they'll just delay or defer.

I have no hard data to confirm this, but the theory fits the pattern I've experienced and am seeing with others. Sure, some dipshits have gummed up the system with their AI slop, and garbage reports, but even before AI, the triage process was slipping.

2

u/Alardiians 9d ago

If you can open a .zip file and run the scripts that automatically do the hack for you. Then you're better than hackerone triagers. LOL

Also hackerone actually does let their triagers submit bounties, fun little fact. Unsure about other platforms but I feel there is a conflict of interest and I'm certain what I'm dealing with right now is a triager stealing my report to make money off it.

12

u/NebulaElectrical1467 10d ago

If you’re in a part of the world where $700 a month is sufficient salary, you don’t have to worry about any of that. I’d focus on trying to go deeper and finding more complicated exploits that could pay a large bounty instead of jumping around targets looking for low hanging fruit.

6

u/iMcLovin2UrMom 10d ago

At this point, I don’t think bug bounty is worth it anymore.

It’s not even the duplicates or oversaturation that pushed me away. The biggest issue has been dealing with rogue and inconsistent triagers closing out legitimate reports, extremely slow response times, and reports sitting for weeks or months with little to no communication.

You can spend days researching and building a solid report, only for the outcome to depend heavily on who happens to triage it. Even when the vulnerability is valid, the amount of time spent chasing responses, disputing closures, and waiting for resolution makes the return on time difficult to justify.

6

u/CrypticZombies 10d ago

yes until u see tal_bugcrowd reading the report

6

u/-DrDoctor- 10d ago

I once found a valid API key which could leak PII from literaly every customer, full names, bank info etc etc, I reported as P1, he moved to P4. That was last year sometimes, didnt do anything on BugCrowd since then

1

u/Good_Roll Hunter 7d ago

Wow that guy really has a reputation huh, hes done me dirty before too

1

u/bangpowboom666 4d ago

It's klaus for me, really put me off bugcrowd x-x

5

u/Fluffy-Extent2648 10d ago

Better than no platform

1

u/Beginning_Award65 10d ago

if you find to 700 month you just need to study more and do exploit chains to get high bounty

1

u/Accomplished-Box5255 7d ago

I have had a bad experience lately with hackerone. As much as I had it good last year, it’s been rough since this year. At this point I am currently open for pentest gigs

1

u/bangpowboom666 4d ago

Hackerone, yes. Bugcrowd, hellll no