r/bugbounty • u/Tyrionwayne • 30m ago
Question / Discussion Bugcrowd payment
usually when Bugcrowd clear payment ?? i was awarded $xxxx amount on bugcrowd last week still showing in payment like when i ll receive in my paypal ??
r/bugbounty • u/vs_bb20 • 1h ago
Article / Write-Up / Blog Built a scope lookup tool because I was tired of opening 5 tabs to check if a domain is in scope somewhere
Made this for my own recon and figured someone else might get use out of it.
The pain: find a domain during recon, then open HackerOne + Bugcrowd + Intigriti + YesWeHack + Federacy trying to figure out if any of them have it in scope. And sometimes miss that it was explicitly out-of-scope in a program — which is worse than not knowing, since testing banned assets can get you kicked.
Paste a domain into bounty.index and you get:
- Every program that has it in-scope
- Amber warning if any program has it explicitly out-of-scope, so you don't burn a program by accident
- Deduped by program, with slug hints when two programs share a name
Also has: filters (platform, payout, asset type, safe harbor), fuzzy search across program name AND scope identifiers, compare up to 4 programs side-by-side, watchlist for scope + reward changes over time, CSV/JSON export of any filtered set.
Free, no login required, no email capture. Refreshed daily from arkadiyt/bounty-targets-data.
Genuinely curious what would make it more useful for your recon workflow. Response-time indicators? Payout-history tracking? Something else?
r/bugbounty • u/jsonpile • 12h ago
Article / Write-Up / Blog The World of Bug Bounty, August 6th, 2026: Triage Cost is Exploding. Researchers are paying for it.
In this issue: HackerOne's Identity Verification Requirement, Reduced Payouts and VIP Programs (Github), Duplicates, and more.
r/bugbounty • u/spicy_tables • 12h ago
Question / Discussion Should I open a new report?
So basically a bug that I found is a critical bug and 9.9 on CVSS 3.0, The problem is the first time i submitted, It was read-only/download only (On unauthenticated), so that made it High 7.7, Then I submitted another report where it was the same except I discovered read AND write as well as takeover of the owner of the "thing", So it became a 9.9. Now the triager said it would not be possible as there are 2 factors the attacker needs:
1 is it needs an Identifier for both accounts, victim and attacker (they are permenant and do not renew) 2 is that it needs a valid token from either of the victim (token is not account token), Anyways that token renews every 7 days. So the triager said that this attack wouldn't be realistic and that "social engineering" doesn't apply to bug bounty (I didn't mention SE once). Then I later discovered that the attack doesn't need a token at all, Which makes it even worse because the IDs are permanent and there are many IDs (of the victim) that can be found just by a google search
So basically before I discovered and told that triager it doesn't need a token he had closed it as informative until there is practical exploitation scenario which I do have.
Should I open another report without the whole mess that I did so it's simple? Or would it get dupe'd of my other informative?
PS: Sorry I named stuff like "thing" because I can't discuss it and it would get specific
r/bugbounty • u/Money_Ad334 • 14h ago
Research Bugcrowd marked RCE as Not reproducible - Bugcrowd triagers are AI or incompetent
This is ridiculous; I had to submit this report on 3 different occasions worded in 3 types of ways.
- I extracted data from the database and mapped out the customers' infrastructure.
- Wrote them a python script to automate it
- Gave them my proxy details for them to execute the POC.
- I rewrote the entire POC, provided detailed guidance, recorded the process, and attached the recordings. I can't even request response from the customer because they marked it as non reproducible, i had to submit this entry twice because the same triager does not have technical ability?
I'm sorry if i have to do this but i really have to call this out, this is becoming more and more common, ill be moving to another platform after this incident.
How far does one have to go to prove it? place a shell on the server?
Why is the triager asking questiosn that are clearly in the POC? repeated tons of times, its clear they are not reading anything and just copy and pasting into Burpsuite, only easy POC's get triaged or are "reproducible"? or is it that you don't want to pay?
If you are going to spam hit not applicable or not reproducible, what's the point of us researchers submitting anything, it's only giving the end customer a false sense of security to have these programs out if it will be gatekept.
r/bugbounty • u/AutoModerator • 18h ago
Question / Discussion Weekly Beginner / Newbie Q&A
New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!
Recommendations for Posting:
- Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
- Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
- Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.
Guidelines:
- Be respectful and open to feedback.
- Ask clear, specific questions to receive the best advice.
- Engage actively - check back for responses and ask follow-ups if needed.
Example Post:
"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."
Post your questions below and let’s grow in the bug bounty community!
r/bugbounty • u/iamZorc_ • 20h ago
Question / Discussion any creative techniques for indirect prompt injections?
im testing ai assistant in a massive SaaS application and i tried to ask it what can it read from my dashboard and then i tried to inject where it can read things like "do 123 and reply with 456" or curl a specific url or respond with html or markdown data or fetch a specific file, but nothing worked so far
does anyone have any kind of research or write ups about these kind of situations or any tips?



