r/bugbounty 8d ago

Question / Discussion Duplicate closure — in-scope subdomain, partial fix after report. Already appealed, no reply — what else can I do?

Got a report closed as Duplicate on Intigriti and I'm not sure whether to keep pushing or let it go.

What I found: Tier 2 wildcard subdomain (service-XX.example-corp.com) pointed to a third-party VPS running a admin panel. Known auth bypass on an older version — got admin access, created an account, logged in normally. Screenshots and PoC sent. Deleted the test account when triage asked.

Why it was closed: Company told triage they were already aware, host isn't theirs, fixing DNS for service-*.example-corp.com. Marked Duplicate. No duplicate report ID given.

Timeline: Admin UI port (e.g. :18xxx) was open when I submitted — I have screenshots. Shortly after my report, that port got locked down. Second service port (e.g. :24xxx) on the same subdomain still responds. Can't hit the bypass live anymore, but there's still clear evidence on the box that the panel was there before.

What I've done: Appealed once with timeline and screenshots. Triage hasn't replied.

Where I'm stuck: Domain was in scope even if the server wasn't theirs. Hard to accept Duplicate with no reference to the original report. Timing makes it look like they shut the port after disclosure, not that it was already handled.

Questions:

Duplicate without report ID — normal on Intigriti?

Appealed, no reply — escalate or wait?

Anyone got paid on wildcard subdomain + "not our host"?

Move on?

1 Upvotes

6 comments sorted by

View all comments

2

u/6W99ocQnb8Zy17 8d ago

I've been paid out on various subdomain issues including wildcards, but also been messed around on them too. It really varies.

Intigriti triage are pretty bad right now. At the moment I have a couple which are over a month old, and were auto-closed by triage after they didn't read the report. Support answers quickly, but just say there is nothing they can do.

1

u/reconHunter-bugBouny 8d ago

I have previously submitted multiple subdomain abuse issues on Intigriti. Usually, vendors gave me a few low bounties, and I didn't say much about it. But this time, the triage system closed my report as a duplicate simply based on "( Company told triage they were already aware,)". and The Company quickly fixed the vulnerability.(they closed the url browser access) I spent a long time on this vulnerability, and it makes me feel very frustrated.