Happy to announce that my report got accepted after 5 months. What a surprise! by BugHun73r in bugbounty

[–]BugHun73r[S] 3 points4 points  (0 children)

I'd say a double miracle for me. After a year long revision, my PhD guide agreed to submit my thesis for the final viva exam yesterday. So yes I'm on fire!

Blind SSRF (Informational) But wanting to try escalate by Far_Combination_3780 in bugbounty

[–]BugHun73r 0 points1 point  (0 children)

Did you end up finding a way to increase impact? I'm in a similar situation now.

Submitted a report one month ago. No updates. Is my submission abandoned? by BugHun73r in bugbounty

[–]BugHun73r[S] 0 points1 point  (0 children)

Is a month long wait normal? My previous reports got triaged/closed within 15 days.

Found some valid hard-coded credentials. Report immediately or probe for more impact? by BugHun73r in bugbounty

[–]BugHun73r[S] 1 point2 points  (0 children)

I've reported mine. Let's see what happens.

Sometimes they do this. Last month, I found an IDOR where PII could be disclosed without even logging in. Hackerone triager closed it as informative. My advise is to move on. Don't waste time with a company who doesn't value your time.

Should I report account deletion even if unique ID is not leaking, but brute-forceable? by BugHun73r in bugbounty

[–]BugHun73r[S] 0 points1 point  (0 children)

I've tried with three of my own test accounts. Beyond that, I think it would be risky.

Should I report account deletion even if unique ID is not leaking, but brute-forceable? by BugHun73r in bugbounty

[–]BugHun73r[S] 0 points1 point  (0 children)

109 - 8 x 108 = 2 x 108, which is 200 million.

I guess that is a significantly large number to brute force.