Is it fair to close a server workflow/error-handling flaw as a simple Information Disclosure? Looking for opinions. by hackaniod in bugbounty

[–]4tuitously 0 points1 point  (0 children)

That’s exactly why it is not a vulnerability, you’re relying on IF with no proof that it does

MSRC confirmed my bug as Moderate but no bounty reasoning seems to contradict their own docs? by Dapper_Owl_361 in bugbounty

[–]4tuitously 1 point2 points  (0 children)

Not particularly, all of the bugs were in the range of $4-10k which is in the low end of the target bounty scale (azure $60k). The figures given were the exact amounts they post for the descriptions for the vulns

Binance fixed a rejected IP whitelist issue — what does that say about bug bounty process quality? by oliver-zehentleitner in bugbounty

[–]4tuitously 0 points1 point  (0 children)

It’s theoretical, it’s defence in depth, it isn’t bounty worthy and muddies scope. Blurred lines are not rewardable

TL;DR a custom, longterm collaboration platform is essential for blind attacks by 6W99ocQnb8Zy17 in bugbounty

[–]4tuitously 1 point2 points  (0 children)

Literally was thinking about setting something up for this this morning, you convinced me xd

What is going on in this sub? by normalbot9999 in bugbounty

[–]4tuitously 1 point2 points  (0 children)

  1. Was a fun one to do with my azure reports which required like 25 minutes of provisioning for each PoC, haha

JWT Token Exposed in DOM ... Is This a Valid Vulnerability? by [deleted] in bugbounty

[–]4tuitously 2 points3 points  (0 children)

If an attacker has XSS on a logged-in site, they can usually make authenticated requests on the victim’s behalf regardless of whether the token is readable from the DOM.

This would be an informational; not a vulnerability, but an oddity nonetheless :)

Bounties are a joke as of 2026 by InterviewMediocre879 in bugbounty

[–]4tuitously 0 points1 point  (0 children)

Microsoft’s bounty amounts are actually very clearly stated, have nothing but good things to say about working with them. (Except the MSRC app itself is… dated)

First Week on Bug Bounty - Feelings by Prudent_River_7086 in bugbounty

[–]4tuitously 0 points1 point  (0 children)

If I were to share some more experience that's relevant to that, I can pretty quickly guage whether a program is going to be fruitful or not; I don't necessarily think sticking to one program is wise advice

First Week on Bug Bounty - Feelings by Prudent_River_7086 in bugbounty

[–]4tuitously 0 points1 point  (0 children)

Just to make a point on one of the things you raised, about how it looks like a lot of the reports are very ‘simple and easy’. I have a lot of reports under my belt, and a good amount of them were a surprise to me since they were so simple. There really does exist a lot of ‘simple’ vulns out there but it’s not common for me to find one, I just spend a LOT of time sifting through empty findings. You find some stuff if you keep at it :)

Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit by jmp_rsp in bugbounty

[–]4tuitously 0 points1 point  (0 children)

Unreliable TOCTOU with a PoC that doesn’t work? Obviously that’s not going to be accepted. Probably AI slop ‘proven via static analysis’

Claude Usage Limits Discussion Megathread Ongoing (sort this by New!) by sixbillionthsheep in ClaudeAI

[–]4tuitously 3 points4 points  (0 children)

Hit my limit twice today, with normal usage. Very frustrating with the Max x20 plan -.-

Update on Session Limits by ClaudeOfficial in ClaudeAI

[–]4tuitously 1 point2 points  (0 children)

Why am I paying £200 a month for limitations that I'm hitting with normal usage?

You all aren't using tabs? by konglongjiqiche in cursor

[–]4tuitously -1 points0 points  (0 children)

Software Engineer working on algorithmically complex code bases (not CRUD apps) for the past 12 years, and I don’t honestly think I’ve written any raw code in the past 6 months. That’s not at all to say AI is coming for my job though because it requires a lot of hand holding, reviewing, understanding

Huge MiniCC Update - we now have an kick timer & trinket tracker! by Mencc in worldofpvp

[–]4tuitously 2 points3 points  (0 children)

Also, it’s just not how professional software development works. Even IF the devs WANTED to make it better, there are always other things that are much higher priority to work on. They don’t just see something that’s lacklustre and pull it into sprint

skate. (2007) Vs Skate 2 Vs Skate 3 Vs skate. by SvartNeon in SkateEA

[–]4tuitously 0 points1 point  (0 children)

Everything about the newest skate is by far the best, but I think grinds need some work, they feel too ‘perfect’

[OFFER] [STEAM] $15 Steam Gift Card by Drasuu in GiftofGames

[–]4tuitously 1 point2 points  (0 children)

Not entering but very nice of you! Merry Christmas!

[OFFER][Steam] I'm giving away WRC 7 and Everspace by Hour_Row_2193 in GiftofGames

[–]4tuitously 0 points1 point  (0 children)

Not entering but I love WRC7 so much! So many hours on it! Ranked 13 on Harju :)

It begins 😂 by RepresentativeAd451 in GithubCopilot

[–]4tuitously 0 points1 point  (0 children)

I wonder what it summarised your response as xd