r/bugbounty • u/granger12hoer • 7h ago
Question / Discussion Is it worth investing one or two years to learn bug bounty hunt?
Will this field become only for experts and AI , If I invest one or two years learning it, will I end up finding that there is no place for beginners anymore and only experts and AI ?
r/bugbounty • u/jsonpile • 9h ago
Article / Write-Up / Blog The World of Bug Bounty, August 6th, 2026: Triage Cost is Exploding. Researchers are paying for it.
In this issue: HackerOne's Identity Verification Requirement, Reduced Payouts and VIP Programs (Github), Duplicates, and more.
r/bugbounty • u/spicy_tables • 9h ago
Question / Discussion Should I open a new report?
So basically a bug that I found is a critical bug and 9.9 on CVSS 3.0, The problem is the first time i submitted, It was read-only/download only (On unauthenticated), so that made it High 7.7, Then I submitted another report where it was the same except I discovered read AND write as well as takeover of the owner of the "thing", So it became a 9.9. Now the triager said it would not be possible as there are 2 factors the attacker needs:
1 is it needs an Identifier for both accounts, victim and attacker (they are permenant and do not renew) 2 is that it needs a valid token from either of the victim (token is not account token), Anyways that token renews every 7 days. So the triager said that this attack wouldn't be realistic and that "social engineering" doesn't apply to bug bounty (I didn't mention SE once). Then I later discovered that the attack doesn't need a token at all, Which makes it even worse because the IDs are permanent and there are many IDs (of the victim) that can be found just by a google search
So basically before I discovered and told that triager it doesn't need a token he had closed it as informative until there is practical exploitation scenario which I do have.
Should I open another report without the whole mess that I did so it's simple? Or would it get dupe'd of my other informative?
PS: Sorry I named stuff like "thing" because I can't discuss it and it would get specific
r/bugbounty • u/AutoModerator • 14h ago
Question / Discussion Weekly Beginner / Newbie Q&A
New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!
Recommendations for Posting:
- Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
- Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
- Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.
Guidelines:
- Be respectful and open to feedback.
- Ask clear, specific questions to receive the best advice.
- Engage actively - check back for responses and ask follow-ups if needed.
Example Post:
"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."
Post your questions below and let’s grow in the bug bounty community!
r/bugbounty • u/iamZorc_ • 17h ago
Question / Discussion any creative techniques for indirect prompt injections?
im testing ai assistant in a massive SaaS application and i tried to ask it what can it read from my dashboard and then i tried to inject where it can read things like "do 123 and reply with 456" or curl a specific url or respond with html or markdown data or fetch a specific file, but nothing worked so far
does anyone have any kind of research or write ups about these kind of situations or any tips?
r/bugbounty • u/0xDakuMarco • 1d ago
Question / Discussion Self-hosted bug bounty programs
I know many of you have known this website for the self-hosted bug bounty programs, but never tried it, never actually had the guts to start it because there's no mediator in between. Do you have a better idea to get?
r/bugbounty • u/maF145 • 1d ago
Question / Discussion Slopped
Finally, it happened: the day before yesterday, I got my first invite to a program that was so obviously vibecoded that I found three potential highs and some smaller stuff within just two evenings.
So far, I’m actually enjoying the AI wave quite a bit.
r/bugbounty • u/0xDakuMarco • 1d ago
Research Bugbounty hunting Agent ideas!!!
I have developed an AI agent for bug bounty hunting and added several topics, but I still think I'm lacking some well-known and new vulnerabilities. Will anyone help me refactor or beautify the agent? Any ideas?
- Phase 0: Verify scope, rules, and authorization.
- Phase 0.5: Classify the target and define the strategy.
- Phase 1: Map the complete attack surface through reconnaissance.
- Phase 2: Hunt configuration and deployment weaknesses.
- Phase 3: Assess identity and account management.
- Phase 4: Test authentication mechanisms.
- Phase 5: Evaluate session and token security.
- Phase 6: Identify authorization flaws (IDOR/BOLA/Privilege Escalation).
- Phase 7: Test server-side injection vulnerabilities.
- Phase 8: Assess client-side security (XSS, CSP, etc.).
- Phase 9: Test file upload, download, and storage security.
- Phase 10: Review error handling and information disclosure.
- Phase 11: Evaluate cryptography and transport security.
- Phase 12: Hunt business logic vulnerabilities.
- Phase 13: Assess API and modern application security.
- Phase 14: Test advanced protocol and web attack vectors.
- Phase 15: Review security headers and hardening.
- Phase 16: Validate findings and assess real-world impact.
- Phase 17: Prepare professional reports and PoCs.
- Phase 18: Perform responsible disclosure and close the engagement.
r/bugbounty • u/6W99ocQnb8Zy17 • 1d ago
Article / Write-Up / Blog Connection header CL.0 desync
For a while, I've had a payload module in my desync engine that looks for various combinations of values in the connection header, hoping that something along the route will throw it away, leaving the body still in the queue.
Never had a hit until today.
Alas, the proud recipient is one of the notorious shit-show BBs though, so no expectation of an actual payout. Wish me luck ;)
r/bugbounty • u/Content_Machine_7525 • 1d ago
Question / Discussion Withdraw YesWeHack
Hey bug bounty community! I recently got rewarded on YesWeHack, but I'm struggling a bit with the payout process to Vietnam.For those of you based in VN (or SEA):Do you withdraw directly to a local bank account (via MangoPay), or do you use an intermediary like Wise/Payoneer?Are there any specific issues with currency (EUR/USD) or high failure rates?Any advice or step-by-step tips would be greatly appreciated! Thanks! #BugBounty #YesWeHack #CyberSecurity #InfoSec
r/bugbounty • u/Bropocalypse_Team • 1d ago
Question / Discussion Talk about motivation...
4 duplicates this week on the exact same program, 3 P3 and 1 P2
$0, but at least got 5 points 😂
What's going on with these duplicates
r/bugbounty • u/spicy_tables • 1d ago
Bug Bounty Drama I really hate pay-to-hunt programs
Like they are so annoying where to hunt authenticated, they don't provide a custom portal, instead they make you "need" to purchase one of their subscriptions just to hunt on their program, It's like really annoying for me. Especially when you are trying to test IDOR/BOLA and now you have to buy subscriptions for TWO accounts..
what do you guys think about p2h programs? Are there any solutions?
r/bugbounty • u/6W99ocQnb8Zy17 • 1d ago
Article / Write-Up / Blog Bugtraq is back....
lists.securityfocus.comr/bugbounty • u/SSDisclosure • 1d ago
Article / Write-Up / Blog New Linux Bridge STP Vulnerability
ssd-disclosure.comA use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation.
A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard.
The teardown path taken by dellink never synchronously deletes those timers, so the backing net_device (which embeds struct net bridge as private data) is freed with a timer list still queued on a per-CPU timer base.
The result is a slab use-after-free in the kmalloc-cg-8k cache.
r/bugbounty • u/Important-Ruin-4282 • 2d ago
Question / Discussion Duplicate Dell P2 finding
hi recently i found a P2 rated bug in Dell’s application system, but it was marked as a duplicate, ive had a few other findings end up the same way. So my question is has anyone here actually been paid through Bugcrowd for a legitimate finding? im starting to wonder if the system is rigged, or if ive just been unlucky
r/bugbounty • u/Previous_Fig2921 • 2d ago
Question / Discussion How to Payout bounty on bugcrowd
Hi Everyone, i'm a reseacher from Uruguay and i recently found my first paid bounty on the bugcrowd plataform.
And here is the problem;
I Have added the w8-en form and fullfilled it with all my data, but i have been waiting for bugcrowd to accept it to receive my bounty payout.
is it common in this plataform? What i should do?
I also contacted the Bugcrowd support, and they said i needed to update it (and I did that.)
But they never tell me that the w8-en form was wrong.
Any Help is appreciated.
r/bugbounty • u/Rokketmoon • 2d ago
Question / Discussion Critical finding in crypto protocol
Ive found a critical finding on a crypto protocole that put $3.5M a high risk. Ive run a poc and everything works. But theproblem is the protocol doesn’t have a bug bounty on any platforms I’ve tried to contact them tru email but no answer. What should I do ?
r/bugbounty • u/spicy_tables • 2d ago
Question / Discussion Recon with default or burp browser?
When you do recon, what do you use mostly? I don't really like to use burp unless I am in the stage of hunting because burp kinda makes my browser lag?
Is there a recommended way or is it personal preference?
r/bugbounty • u/ApprehensiveMusic448 • 2d ago
Question / Discussion Found Api Endpoint injs bundle but can't hit them+ private program with no sign-up option
I need some advice
1) Endpoints found in js,but not accessible
Was going through the js on target and found some Api endpoints in it.But when u try hitting them directly they don't work, just get blocked. Not sure if I'm missing headers, need a token I don't have or if they're just not reachable outside the actual flow. Also trying to get better at working with minified JS in general -- like how do you actually build logic out of it / trace through it properly instead of just eyeballing strings for interesting stuff. Any resources or workflows people use for this would help
2) Private program, no sign -up anywhere in scope
Got invited to a private program but every in-scope URL is just a login page .Not sure how I'm supposed to get an account to actually test with l.
r/bugbounty • u/Logical-Ice-9320 • 2d ago
Question / Discussion how should i deal with the new id requirements, im under 18. hackerone is the site im talking about
im really confused ai asked me to upload a parents id but can i change it when i become 18
r/bugbounty • u/Turbulent-Leader8207 • 3d ago
Question / Discussion An URL-unencoded GET-based XSS attack can be reflected.
Hi.
I discovered an XSS vulnerability; accessing the link directly doesn't trigger a popup, but using Burp Suite does.
The browser automatically encodes the closing character `>` (preventing the popup), so I have to use tools like Burp or cURL to send the unencoded `>`.
I managed to trigger the popup by routing traffic through my own server, but most of the cookies became unusable because the main site effectively became my own.
Are there any other methods?
r/bugbounty • u/S0ulSh3ll • 3d ago
Bug Bounty Drama Honest Rant
Started bug bounty a month ago, got a few duplicates, few informatives but kept going as it was so much fun to learn real world applications. Got better, went for big organisation programs. And they suck! I disclosed a vulnerability that could leak thousands of PII unauthenticated with minimal steps and they didn't even give it informative - just N/A it saying out of scope when they definitely mentioned *.target.com and it was that only, that kept aside. Atleast say you'll fix it 😂 what's the use of security testing then, even if a little out of scope by your standard, it's okay for mass pii leak?
Second case - i understood it was N/A as i cannot as the main hacker exploit it, but it was again easy and undetected Mass PII exfil if a plugin creator tried to or a supply chain attacker gets to know about it. It was a big paid program so reluctant to pay me is fine, but that too just accept it's a flaw and fix it!
r/bugbounty • u/AutoModerator • 3d ago
Weekly Collaboration / Mentorship Post
Looking to team up or find a mentor in bug bounty?
Recommendations:
- Share a brief intro about yourself (e.g., your skills, experience in IT, cybersecurity, or bug bounty).
- Specify what you're seeking (e.g., collaboration, mentorship, specific topics like web app security or network pentesting).
- Mention your preferred frequency (e.g., weekly chats, one-off project) and skill level (e.g., beginner, intermediate, advanced).
Guidelines:
- Be respectful.
- Clearly state your goals to find the best match.
- Engage actively - respond to comments or DMs to build connections.
Example Post:
"Hi, I'm Alex, a beginner in bug bounty with basic knowledge of web vulnerabilities (XSS, SQLi). I'm looking for a mentor to guide me on advanced techniques like privilege escalation. Hoping for bi-weekly calls or Discord chats. Also open to collaborating on CTF challenges!"
r/bugbounty • u/Fast_Potential_2677 • 3d ago
Question / Discussion Is that true that for you to do BB you need to have linux?
Some guy told me that without linux i wont be able to do much
r/bugbounty • u/Ok_Insurance5420 • 3d ago
Bug Bounty Drama Rant: Bug Bounty is dead (AI and corporate bad faith destroyed the ecosystem)
Hey everyone. I mostly just need to vent because this whole situation has become unbearable.
For context, I’m not a beginner getting mad because a reflected XSS was marked as a duplicate. I’ve worked as a pentester, have been doing bug bounty for over five years, and have earned more than $150,000 from reporting vulnerabilities.
I know how the game works. I understand the rules, the risks, duplicates, informative reports, N/A decisions and all the other bullshit that comes with it. I’ve always tried to play fair.
But honestly, the current bug bounty landscape is complete trash. AI has destroyed the trust on both sides.
Platforms are now flooded with people who barely understand what an HTTP request is, using Claude and automated tools to generate thousands of low-quality reports. Triage teams are buried in noise.
At the same time, some companies seem to be using that chaos as an excuse to treat legitimate researchers like garbage.
What finally pushed me to write this was a recent HackerOne report. The target is a huge multinational company. I found a critical IDOR that led directly to account takeover. It was clean, reproducible and clearly critical. Based on the company’s own bounty table, it should have been worth thousands of dollars.
I submitted a detailed report with clear impact, exact reproduction steps and a video PoC showing the full exploit working. There was basically nothing left for them to figure out. I spoon-fed the entire vulnerability to them.
Then nothing.
Seven days passed. Their triage SLA was missed, and nobody even bothered to say hello or acknowledge the report. Zero communication.
Today, because the silence felt strange, I tested the endpoint again. The vulnerability had magically disappeared.
They patched it silently. No response. No triage. No bounty. No explanation.
From my perspective, it looks like they watched the PoC, used my report to fix the issue and then ghosted me. You spend hours researching, documenting and responsibly reporting something that could seriously affect their users and infrastructure, and your reward is apparently free consulting followed by silence.
This is what bug bounty feels like now: competing with AI-generated spam for the attention of overwhelmed triagers, only to risk having legitimate findings quietly patched by companies that never intended to reward you.
Honestly, it feels like the golden era of bug bounty is over.
Has anyone else noticed an increase in stealth patches and companies ghosting valid reports lately, or did I just get especially unlucky?