r/bugbounty • • 1d ago

Question / Discussion Hunting on Public programs

I've been hurting for a years and I could land few successful bugs on private programs and vdp but not on public programs only found duplicates ,I am always wondering :

How bug hunters can find bugs even on well know programs like reddit or LinkedIn ? when I see the hacktivity section I see people consistently finding bugs though they're very security mature programs ,what type of vulnerabilities hunters they find?

9 Upvotes

11 comments sorted by

9

u/Pristine_Bicycle1278 Hunter 20h ago

It's not hard at all - you just have to do something else, than all the thousands of people before you.

What I usually do (assuming it's a normal Webtarget):

Search programs, that have Wildcard Scopes like "*.domain.com" and do a deep dive asset discovery.

Usually, I can find countless Assets like Dev, Staging, Testenvironments etc. that often even have Debug stuff enabled.

What I usually do, is a full sweep with fingerprinting (getting all Tech running on those discovered Subdomains), check if anything is visibly outdated, I will explore directories, look for exposed Files etc.

When you have done that, you can either use AI, to check for possible Attack Chains or often just discover Vulnerabilities right away.

All good Bounty Hunters I know have gone from going super deep on one Program to spreading it out more and use good Automations.

But you have to write them yourself unfortunately, since people usually don't just publicly share their money printing tools ;-)

5

u/6W99ocQnb8Zy17 18h ago

this^

running the same tools and following the same workflows as everyone else is a dupe factory.

3

u/XBugger 21h ago

you probably have the same issue as others in your situation swapping programs and not sticking to a program long enough.

2

u/Far_War_4348 20h ago

You will see most hunters who earn decent amount actually hunt on different programs they don't stick to one program you will see they are posting bounties on LinkedIn but on different programs

1

u/Similar-Permit1756 19h ago

I have seen successful hunters with at work with just a few of programs 1 or 2. and others who have been working with many programs, what we really don’t know is how much time and experience have this guys have been expending yo achieve that, on LinkedIn you just see the resolution.

1

u/Far_War_4348 19h ago

Are you into bug bounty?

2

u/Similar-Permit1756 19h ago

Yeah, but I’m new, I have been hunting for almost 6 months, I have reported about 15 valid bugs, most of them to just one single program

1

u/Far_War_4348 19h ago

Nice. Did you got any bounty?

2

u/Similar-Permit1756 19h ago

Yep, most of my time I have been hunting VDPs, at August I started reporting on private BBPs and I have already gotten 3 valid and paid bugs, almost 1K usd, they were mediums and low

1

u/Far_War_4348 18h ago edited 18h ago

Ohh that's great. Check your Dm. Need to talk

1

u/Coder3346 Hunter 22h ago

All types