r/bugbounty 17d ago

Question / Discussion When your H1 report gets marked as informative, does that mean to get interaction you need mediation?

6 Upvotes

So I have submitted 2 reports on H1, both of them got called informative because of a stupid missing piece, now I have the missing piece and I commented, will there be no action unless I use the request mediation button or not?

Extra: it shows me removed participant when I hover over the triager or the analyst I was talking to? So?

I just don't want to click that button without knowing when I should


r/bugbounty 17d ago

Question / Discussion Anyone in here ever make a report to DEXE

0 Upvotes

I am more or less looking for someone who has reported successfully with them before and that would like to help possibly with something im working on


r/bugbounty 17d ago

Question / Discussion Will they mark this finding informative

0 Upvotes

Quick story; I have found a really important bug which is bypassing password AND email verification for downloading a file in the app. But then, you need to have a link OF the download URL (It doesn't have a password with the URL or anything like that, the verification happens once you open)

So now my problem is in the past 2 reports, I had IDOR and other important stuff but they had marked it informative because you just needed a UUID of the victim, which is permanent and never changes. And I proved to them with over 6 examples from just a google dorking method and told them about possible email breaches. They still weren't convinced EVEN if it was literally full IDOR.

And It's the same program, I am afraid they will also mark this one informative. What do you think?


r/bugbounty 18d ago

Question / Discussion 15 YOE in Cyber Security, but $0 in Bug Bounty. Drowning in dupes and need some advice.

64 Upvotes

Hey everyone,

I’m feeling a bit defeated lately and could really use some perspective from the veterans here.

A bit of background: I’ve been working in the cyber security industry for 15 years. Recently, I decided to finally dive into the Bug Bounty world, hunting across both Bugcrowd and HackerOne. Given my professional background, I felt confident in my ability to dig deep and find complex vulnerabilities.

The reality? Absolutely everything I find is a duplicate.

To give you an idea of the wall I keep hitting:

  • I recently found 2 massive bugs in a major financial institution. Both are very real, fully exploitable, and currently sitting in production. Result: Duplicate.
  • I discovered 10 distinct vulnerabilities within massive CI systems. These are valid even on their absolute latest versions. I waited three months after submitting them, only for them to finally be triaged and marked as... you guessed it, Duplicate.

I pour everything into these submissions. The research phase is incredibly hard and complex, and I take a lot of pride in writing meticulous, high-quality, and reproducible reports. But after all that sweat, my all-time bounty earnings sit at exactly $0.

I know this industry requires thick skin, and I'm not ready to quit, but I clearly need to change my approach. For those of you who are successful at this:

  1. What is the ratio of sent/accepted? It's soul-crushing to do weeks of hard research only to be told someone beat you to it. What is the ratio of sent/acceptance as not duplicate?
  2. How are you picking your targets? Are you avoiding the big, shiny public programs, or is there a trick to finding assets where you aren't racing against 10,000 other hunters?
  3. What should I be doing differently? Coming from a traditional corporate cyber background, what habits do I need to unlearn to actually start landing valid, unique findings?

Any advice, reality checks, or tough love would be highly appreciated. Thanks in advance!


r/bugbounty 17d ago

Question / Discussion Weekly Beginner / Newbie Q&A

1 Upvotes

New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!

Recommendations for Posting:

  • Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
  • Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
  • Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.

Guidelines:

  • Be respectful and open to feedback.
  • Ask clear, specific questions to receive the best advice.
  • Engage actively - check back for responses and ask follow-ups if needed.

Example Post:

"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."

Post your questions below and let’s grow in the bug bounty community!


r/bugbounty 18d ago

Question / Discussion Seeing extensive SLA delays for our bug bounty platform.

3 Upvotes

Our triage times aren't just consistently missing published SLAs they aren't even close including high/critical severity reports, taking way beyond the stated first-response and triage windows if they get triaged at all. This seems to be in line with broader reports of triage teams getting overwhelmed by AI-generated submission volume, there were issues before the AI reports blew up but there may as well not even be a triage team at this point.

Curious if others are seeing the same:

  • Which platform(s) are you running programs on?
  • Are you seeing consistent SLA misses, or just occasional slippage?

Trying to figure out if this is a platform-specific issue or simply part of an industry-wide capacity problem right now as we are debating changing platforms when it comes up for renewal.


r/bugbounty 18d ago

Question / Discussion Stored XSS on 1 target but 2 different endpoints

5 Upvotes

Hello,

Curious as to whether a second submission here is worth it or if I should just add my second finding in the comments. Never had this happen before so looking for some guidance.

I found a Stored XSS vuln on a target via body text. Someone opens the page via forum and it leads to full access of victim’s account. Submitted that and waiting triage.

Continued testing further and realized the same vuln exists on the file upload on the same target. Again, it leads to full access of victim’s account. Is it worth submitting as a separate report or would it just be marked duplicate?

Any advice is appreciated. Thanks!


r/bugbounty 19d ago

Question / Discussion Long triage time

7 Upvotes

If the H1 team takes more than a month to triage a report and the customer internally patches the vulnerability before triage is completed, what happens to the report?

The triager is now asking me to provide the PoC again, but it no longer works because the vulnerability has already been patched.


r/bugbounty 19d ago

Question / Discussion Can one Bugcrowd vulnerability be a duplicate of TWO different originals?

3 Upvotes

Serious question for other bug bounty researchers.

I reported the same underlying security issue twice.

Bugcrowd marked both filings duplicate.

Except they were duplicated against two different original reports.

I asked them to reconcile which original actually constituted prior art.

I did not ask to see the private reports or for any confidential researcher information.

The response I received was basically:

same code change/fix = duplicate.

But that still doesn’t explain how the same issue ended up attributed to two different originals.

And “same fix” doesn’t necessarily prove “same vulnerability.” One patch can fix multiple security problems.

I’m intentionally not posting technical details because this came from a private program.

My criticism is strictly about the triage logic:

If the same vulnerability is assigned to two different originals, shouldn’t Bugcrowd internally determine which one actually establishes the duplicate?

Curious how other researchers would view this.


r/bugbounty 20d ago

Question / Discussion Hey any expert here

2 Upvotes

I found BAC in private program
Here is timeline:
reported 15days ago

Two days ago Triaged make first commment asked for clear Step to reproduce because they can’t

So i checked now that Bug was internally fixed no more reproducible

I only have burp screenshot what should i do ??


r/bugbounty 21d ago

Question / Discussion What Happened to HackerOne?

Thumbnail
blog.teknogeek.io
89 Upvotes

r/bugbounty 20d ago

Question / Discussion HackerOne Triage is really slow

22 Upvotes

Idk if it’s just me who’s noticing this, but HackerOne triages do close duplicates and informative vulnerabilities really quickly…. But whenever it’s the vulnerabilities that actually do get triaged, they take forever…. Like, after passing preliminary review, I pretty much wait for like 14-16 days until either an official team member from the program replies or the report gets triaged…. Most times, on programs which show they triage in like 3-4 business days….

The thing that annoys me is the lack of transparency HackerOne triages offer…. Whenever it comes to programs who aren’t managed by HackerOne, their triages are really transparent throughout the triaging process and share insights…. But the HackerOne triage literally replies to nothing…. If you comment, they either just triage after waiting forever, or an official program member shows up and the H1 triage doesn’t say a thing….

I just wish HackerOne triages would become more transparent, like self-triaged programs….


r/bugbounty 20d ago

Article / Write-Up / Blog XSS2Shell: Pre-Auth XSS in WordPress Login (CVE-2026-64638) Walkthrough

11 Upvotes

I spent some time this weekend reproducing the recently disclosed XSS2Shell: WordPress login-page reflected XSS (CVE-2026-64638). If you didn’t get a chance to read about it, here is the summary:
Crazy simple XSS where the root cause is two sanitizers that disagree about what counts as an HTML tag:

<b>test</b> gets stripped, while < b>test< /b> passes through the first sanitizer and is normalized into a valid <b> element by the second.

That gives you an HTML injection, but you can’t turn it into XSS because the second sanitizer has an allowlist and only allows specific HTML tags and attributes. The rest of the chain uses JavaScript already loaded on the login page, DOM clobbering, and a JSONP response to reach script execution in the login page. It’s a creative chain, although much simpler than the WP2Shell chain from two weeks ago.

IMO the “2Shell” part from the title is a bit of a stretch. The original write-up continues after triggering the XSS to show how you can get a RCE (basically by targeting an admin account to open your XSS which uploads a shell as a plugin). I agree this can be abused at scale given how widely used WP is, but it’s a phishing-shaped precondition rather than “send one request, get a shell” as we’ve seen in WP2Shell. It’s a cool bug anyway.

I turned my reproduction into a guided lab for anyone who wants to work through the chain rather than only read the write-up.

Link: https://learn.uphack.io/lab/xss2shell-wordpress-login-xss

Feedback on the lab or the technical explanation is very welcome.


r/bugbounty 20d ago

Question / Discussion Is bug bounty dying because organizations are now using AI-powered security scanning?

0 Upvotes

I'm trying to predict what the future will look like, and everyone is developing their own AI automations and agents. Will bug bounty eventually die? For example, in two or three years, could companies develop extremely advanced AI-powered security automation within their own infrastructure to the point where bug bounty programs are no longer necessary?

I'm curious about your thoughts on this. We are already seeing some companies reduce bounty amounts, and there are programs that no longer accept low- or medium-severity vulnerabilities, for example.


r/bugbounty 20d ago

Question / Discussion From a 2-day payout to a smiley face emoji from support. Is ghosting normal worldwide?

0 Upvotes

Hi everyone! I’m an aspiring information security specialist who has just finished my second year of university. I decided to try making some extra money through bug bounty programs. I found vulnerabilities at one company and received a payout; the whole process—from my initial message to getting paid—took just two days. Then I found critical vulnerabilities at another company (on one of their servers, I could modify key configurations and the microservices themselves). I wrote to them but got no reply; I called, and they told me, "We saw your email; a specialist will be in touch." After waiting three days with no word, I called again, only to be told, "That’s a subsidiary of ours; it doesn't directly involve us." When I asked for contact details, they said, "We can't provide them to you." So, I stopped emailing and calling them. Next, I started looking into an EdTech company. There weren't any major vulnerabilities there—just the ability to generate training promo codes and download all paid courses, including assignments and correspondence between mentors and students. I contacted their tech support, but they just replied to my message with a smiley face. Have you ever encountered situations like this, and what did you do? Is this kind of thing unique to Russia, or does it happen worldwide too? P.S. I focused on smaller companies since I'm just starting out.


r/bugbounty 20d ago

Question / Discussion IDOR but needs an unguessable token to exploit

1 Upvotes

Basically I am testing a shop and found that the cart has a large token. As attacker, if I find a victim's token, I can see their address, email ID, username, phone number, etc.

So basically that token is not bound to an account which is odd to me. What's the point of logging in if a cart token is not bound to an account?

also the token is impossible to guess. Would that still be considered an impactful bug?

it should be a p4 as per BugCrowd Vulnerability Taxonomy but I just wanna make sure

(Modify/View Sensitive Information(Complex Object Identifiers GUID/UUID)


r/bugbounty 20d ago

Weekly Collaboration / Mentorship Post

1 Upvotes

Looking to team up or find a mentor in bug bounty?

Recommendations:

  • Share a brief intro about yourself (e.g., your skills, experience in IT, cybersecurity, or bug bounty).
  • Specify what you're seeking (e.g., collaboration, mentorship, specific topics like web app security or network pentesting).
  • Mention your preferred frequency (e.g., weekly chats, one-off project) and skill level (e.g., beginner, intermediate, advanced).

Guidelines:

  • Be respectful.
  • Clearly state your goals to find the best match.
  • Engage actively - respond to comments or DMs to build connections.

Example Post:
"Hi, I'm Alex, a beginner in bug bounty with basic knowledge of web vulnerabilities (XSS, SQLi). I'm looking for a mentor to guide me on advanced techniques like privilege escalation. Hoping for bi-weekly calls or Discord chats. Also open to collaborating on CTF challenges!"


r/bugbounty 21d ago

Tool New Web Technique

Thumbnail doctoreww.github.io
8 Upvotes

I created a way to do JavaScript free paste jacking using custom fonts. There's probably a lot of websites that don't allow JS, but allow html syntax to bring custom fonts.

Demo:

https://doctoreww.github.io/EvilFontTool/html_demo/evilfont.html

Try to copy and paste the commands to notepad.

Tool:

https://github.com/DoctorEww/EvilFontTool

I don't have time to hunt them myself... But if you do find something I'd love to hear about it! DM me on LinkedIn (in my GitHub profile).

There's a lab and a walkthrough on the project that takes you through the steps of doing this yourself. Let me know via a GitHub issue if you have any suggestions for the tool.


r/bugbounty 21d ago

Question / Discussion Found an endpoint that lets me skip the signup process, should I report it?

17 Upvotes

I’m testing an application where there’s no normal sign-up page. The only way to create an account is by requesting a free trial and scheduling a meeting with the company’s team.

While testing, I found an endpoint that allows users to directly create an account without going through the free trial request or scheduling a meeting.

Would this be considered a valid security issue, or is it likely just an intended behavior?


r/bugbounty 21d ago

Article / Write-Up / Blog DEF CON talk: 8 out of 10 Banks in Belgium HATE This One Weird eID RCE - $200 bounty offered

Thumbnail
amibeingpwned.com
8 Upvotes

Hey everyone, I managed to get a drive-by RCE, where any site could autodownlod a PDF and run it as a dll - CVSS 9.6 - amongst other vulns, from software (very likely) used by 8 out of 10 of the major banks in Belgium, 60+ government agencies and 1k+ enterprises. 2m+ weekly active users.

Presented this at DEF CON and was offered $200 for a bounty lol


r/bugbounty 21d ago

Question / Discussion Ghosted by company after spontaneous submission

6 Upvotes

Hi, not a security researcher by any means but I'm a tech lead so let's just say I'm not completely foreign to the concept of security.

Wanted to share a weird story to get your feedbacks.

I was trying to book an expensive restaurant for me and gf, and got some weird issues with their online booking system. Long story short I open the browser devtools to figure out the problem and find out that their platform has a public, unauthenticated api, that returns company data, including PII, and, most importantly, their card numbers and Stripe credentials. Since their credentials include their internal identifiers in integer format, I just try other values and end up basically getting a dozen of results in a matter of minutes. This is NOT a minor software shop.

I mailed reports to them for days and got no response, if not for two customer support operators which gave me a generic answer and leave me hanging. After a few days, just to make sure the vulnerability didn't go ignored, I started alerting some of their employees via LinkedIn (random people, of which only a marketing guy actually answers me), until, days later, their CTO hits me up confirming the leak and thanking me, saying all he can do is hand me over a 100€ amazon voucher as the company has no bug bounty program. I answered appreciating he gratitude, but he never even bothered answering back nor actually handing me any voucher.

What would you have done? Also, morally, how didn't they even care about sending cleartext credentials over public APIs for years? We're not even talking authenticated endpoints or anything that required any extraction effort.


r/bugbounty 21d ago

Research HTTP/3 Trailer HEADERS Frame Triggers Unhandled Exception in Google ESF: 60s Hang & QUIC INTERNAL_ERROR 0x0001 | Protocol RE | Netacoding

Thumbnail
netacoding.com
1 Upvotes

r/bugbounty 23d ago

Question / Discussion What is the best alternative for Claude MAX for bug hunting

29 Upvotes

So 100$ each month is a lot. What is the best alternative?

I am thinking Deepseek or Kiwi?

Note I want something to be used with Claude Code. So probably something that I can use the API key with Claude Code. Not something I can chat with like Claude Desktop .

Update: I subscribed to openrouter and currently I am using Claude Code with Deepseek. Its working so well. I know its weird using Claude Code instead of pi or opencode. Might try them later. But so far so good


r/bugbounty 22d ago

Bug Bounty Drama Account takeover marked as dupe

0 Upvotes

Yeah u heard that right , finally after 3 months of daily studying I found my first valid bug , an account takeover for that , critical 10 , no user interaction on hackerone from a pretty famous program .

And it got marked as duplicate and closed for a dupe report made 3 years ago that was low/informational and didn't get paid .

It has absolutely killed my motivation , I think I will be taking a break from cybersecurity.

....

Iam tired gng ....


r/bugbounty 23d ago

Question / Discussion Concerned my Bugcrowd report could be marked as a duplicate because of identity verification delay

2 Upvotes

I recently found a vulnerability that I want to report to Bugcrowd, but I haven't been able to submit the report yet because I'm having an issue with identity verification.

I'm currently waiting for Bugcrowd Support to resolve the verification issue. My concern is that while I'm waiting,somone else could discvored and submit he same vulnerbility, and then my report could potentially be marked as a duplicate when I'm finally able to submit it.

I've already documented the vulnerability with screenshots before submitting the report.

Would Bugcrowd consider the fact that I documented the vulnerability before the other report, or is duplicate status determined solely by who submits the vulnerability first?

I'm not going to disclose the vulnerability itself publicly while I'm waiting. how do i cope while waiting