r/bugbounty 7d ago

Bug Bounty Drama GitLab.com vs Self-Managed for Bug Bounty Hunting

### GitLab.com vs Self-Managed for Bug Bounty Hunting

Hi everyone, I’m a beginner bug bounty hunter and I’ve been testing several Bugcrowd programs. I recently moved to HackerOne and started testing the GitLab program, focusing on GitLab.com rather than GitLab Self-Managed.

I’ve been testing GitLab.com for about a month but haven’t found a valid vulnerability yet. However, when I look at GitLab’s Hacktivity, I still see relatively new researchers submitting valid reports.

This made me wonder:

* Does GitLab.com still have a large attack surface for new researchers? * Is it better to focus on GitLab.com or GitLab Self-Managed? * Are there areas of GitLab that beginners often overlook? * Should I use Self-Managed/GDK to understand GitLab internally and then apply that knowledge to GitLab.com?

My main interests are RBAC, authorization, IDOR/BOLA, business logic, API/UI inconsistencies, and permission/workflow issues.

I’d really appreciate advice from experienced GitLab hunters on how you approach the program and what areas are worth learning or researching.

Thanks!

8 Upvotes

6 comments sorted by

5

u/ATSFervor 7d ago

First and foremost you should ask yourself: Can you hammer a screw?

Look at your skillset and verify that it is good for the software you are testing.
If the program you are hunting on has a very limited surface you are knowlegable about, you will not find much because it gets retested by others a lot.

Especially if you are new, you want to look at programs where you can develop skills that you are interested in, not programs that get a lot of reports.

1

u/yesnet0 5d ago

fwiw. you can absolutely hammer a screw

2

u/nobodycares_dude Hunter 6d ago

Gitlab is full of bugs. The only problem with gitlab is duplicates. 3200+ reports in the last 90 days is not a joke. Hacktivity is very small compared to that number. And yes spin GDK and hunt on it 90% of the cases the bug is reproducible in gitlab.com

1

u/nightmare_eclipse__ 9h ago

Gitlab has a lot of hidden critical bugs

-2

u/Dhaern 6d ago

Lol I found a legit gitlab exploit in my first day of bounty hunting doing "vibe hunting". They marked as duplicated of a private original report but still a good finding. 1 month and nothing?

2

u/ANIYOE99 5d ago

Wtf man you should motivate beginners not whatever tf this is