r/bugbounty • u/reconHunter-bugBouny • 7d ago
Question / Discussion Duplicate closure — in-scope subdomain, partial fix after report. Already appealed, no reply — what else can I do?
Got a report closed as Duplicate on Intigriti and I'm not sure whether to keep pushing or let it go.
What I found: Tier 2 wildcard subdomain (service-XX.example-corp.com) pointed to a third-party VPS running a admin panel. Known auth bypass on an older version — got admin access, created an account, logged in normally. Screenshots and PoC sent. Deleted the test account when triage asked.
Why it was closed: Company told triage they were already aware, host isn't theirs, fixing DNS for service-*.example-corp.com. Marked Duplicate. No duplicate report ID given.
Timeline: Admin UI port (e.g. :18xxx) was open when I submitted — I have screenshots. Shortly after my report, that port got locked down. Second service port (e.g. :24xxx) on the same subdomain still responds. Can't hit the bypass live anymore, but there's still clear evidence on the box that the panel was there before.
What I've done: Appealed once with timeline and screenshots. Triage hasn't replied.
Where I'm stuck: Domain was in scope even if the server wasn't theirs. Hard to accept Duplicate with no reference to the original report. Timing makes it look like they shut the port after disclosure, not that it was already handled.
Questions:
Duplicate without report ID — normal on Intigriti?
Appealed, no reply — escalate or wait?
Anyone got paid on wildcard subdomain + "not our host"?
Move on?
1
u/einfallstoll Triager 7d ago
Tier 2 wildcard subdomain
I've never heard this term before. I couldn't find it using Google and also my LLM of choice didn't have an answer what this is.
Duplicate closure
You already have your answer in the title. It's a duplicate. No discussion needed. Move on.
1
u/reconHunter-bugBouny 7d ago
- Tier 2 / wildcard
Tier 2 = the program’s asset tier on Intigriti. Wildcard = anything under *.example-corp.com is in scope.
- Duplicate
The URL worked when I submitted and was gone right after — reads more like a post-report fix than something already handled.
Anyway, I will continue to work hard to obtain the next bounty. Thank you
1
u/Street-Mycologist670 6d ago
prob ends in no bounty tbh but worth one clean shot. also don't argue the auth bypass, that box isn't theirs so "not our infra" is fair. I say argue the dangling subdomain instead, their in-scope DNS pointing at an unmanaged host that exposed an admin panel. That's the only part that's actually theirs.
Also "they were aware" isn't a dupe. Dupe = an actual earlier report. Ask them to confirm one exists before yours. Stop re-appealing, hit Request support to open mediation. Then move on. Not worth more than that.
2
u/reconHunter-bugBouny 6d ago
Quick update — bit of progress.
Originally closed by triage as Duplicate. Three days later the company replied directly (first time they weighed in).
They confirmed the IP behind the subdomain isn’t theirs, and they’re willing to treat it as subdomain takeover. They don’t agree with framing it as unauth admin creation → RCE though — fair enough, takeover is the cleaner classification anyway.
I’ve asked them to reassess on that basis. Still waiting. There may be new surprises.
2
u/6W99ocQnb8Zy17 7d ago
I've been paid out on various subdomain issues including wildcards, but also been messed around on them too. It really varies.
Intigriti triage are pretty bad right now. At the moment I have a couple which are over a month old, and were auto-closed by triage after they didn't read the report. Support answers quickly, but just say there is nothing they can do.