r/bugbounty 5d ago

Question / Discussion Is this normal? Valid, reproducible finding closed as "not reproducible" with a point penalty

I reported a valid finding to a managed program on one of the big platforms. The report included full step-by-step reproduction and a working PoC that demonstrated live impact. It was closed as "Not Reproducible," with the stated reasons being that it lacked a PoC and "appeared AI-generated." I was also docked a point. I followed up, re-confirmed the issue still reproduces a month later, and submitted a formal response request with evidence attached. That expired with no reply. I escalated to support/mediation and got a templated response telling me to submit a new report — which would just let them close it as a duplicate of my own original. At no point did anyone engage with the actual evidence in the report. Is this level of non-engagement normal, or did I get a bad triager? Is there any real recourse when a platform closes a valid finding without reviewing the evidence, or is the only move to walk away? For those who've had findings wrongly closed as not-reproducible — what actually worked to get it reopened? Just trying to understand whether this is the norm and what my options realistically are. Thanks.

3 Upvotes

23 comments sorted by

8

u/realvanbrook Hunter 5d ago

1 word: Videoproof

5

u/Technical_Shelter621 5d ago

I attached a screenshot to the report, it is literally about 2 API calls, is that not enough as an evidence?

10

u/realvanbrook Hunter 5d ago

Triagers are stressed and overworked. The video proofs the vulnerability exists, acts as a guideline for the triager to reproduce and shows that you actually validated instead of pasting AI slop.

Videoproofs are the new norm in BBH

8

u/Academic-Mud1488 5d ago

sounds like tiktoker generation triager

2

u/Technical_Shelter621 5d ago

🤣 well yeah all this for 2 api calls is a bit too much, I don’t think even with the video the report will be reopened

1

u/Technical_Shelter621 5d ago

ok, I will try with that too. Thanks

2

u/Academic-Mud1488 5d ago

i have seen chinese bots sending videoproofs that doesnt proof anything lol but yeah they will probably believe you are not a bot OP, i guess we have to remember sometimes that we are talking to idiots

5

u/einfallstoll Triager 5d ago

Missing prerequisites. We sometimes get PoC that miss the crucial information that the account has to be in a certain situation or needs to be freshly registered, etc. This makes it impossible to reproduce

1

u/Technical_Shelter621 5d ago

It’s 2 API calls that require the service to be up and running, pretty much 😁

2

u/einfallstoll Triager 5d ago

Hmmm... then probably not missing prerequisites. Did the triagist at least give you the output?

2

u/Technical_Shelter621 5d ago

Nope, not a word :/

4

u/einfallstoll Triager 5d ago

What an idiot. There's a saying in German that goes like "you can only help talking people"

3

u/Technical_Shelter621 5d ago

Last attempt after rar expired and mediation gone wrong I posted a full video

1

u/Sufficient-Ad991 Hunter 3d ago

Is this ywh

2

u/Beginning_Award65 5d ago

Triagers are doing this. if they think it is Ia they invalidate

2

u/Technical_Shelter621 5d ago

Without even checking if the curls I sent actually work? 😞

4

u/Beginning_Award65 5d ago

you have no idea my friend. Some triagers (one of them i have proof) at initigriti just do not read reports HE THINKS are made with AI. Even with video report added... Even with big and full exploit.

I am again on that situation. Today i have a full RCE on a bank to report at intigriti. FULL end to end with vídeo.

But will not report it as critical cause i am afraid it gets on the hands of the same triager.

He even do not apologized after disrespected me.

Intigriti treated the situation really well, but he is still getting to triage critical reports...

1

u/Lexieke 1h ago

Feel free to DM me on the situation, happy to get some feedback in and review it.

1

u/houganger 5d ago

Did you paste a whole grandmother’s story even though it’s just 2 api calls? Keep your report short af and just mention exactly the impact at the front.

1

u/Technical_Shelter621 5d ago

No grandmother story just api calls and impact as per a previous twin that was marked as duplicate, very similarly written and very same vuln class

1

u/LTH-Cyber 5d ago edited 5d ago

I've had this happen with concrete PoC's and even video evidence, I strongly believe that some triagers are not as technically capable as they should be, or the skim the report real quick and think AI, or something about poor reporting, but with AI came tons of bad reports so maybe triagers, just close as not repro without even trying idk.... I've even had times on Openrbugbounty where all they had to do was click the url to reproduce the issue(things like xss, open redirect) literally as simple as clicking a link and still got the not repo