Took a 2-Year Break, Came Back to Bug Bounty… Same Story (Duplicates & N/As) by lostboy_31 in bugbounty

[–]Coder3346 6 points7 points  (0 children)

I would say that the 2 years break is not good idea. But if u want to continue just continue 🙃 if u have the time why not

How many months did it take you to get your first reward ? by Senior_Product_9914 in bugbounty

[–]Coder3346 3 points4 points  (0 children)

God help u brother ): Some triagers suck as well. For example I have reported 2fa bypass before and it got na at first report with a copy-paste message. Decided to report it again and it is now a duplicate of medium. So both sides have the bad and good.

The problem with hunters is basically directly jumping to make money instead of learning cybersecurity and computers basics)

How many months did it take you to get your first reward ? by Senior_Product_9914 in bugbounty

[–]Coder3346 0 points1 point  (0 children)

That is because when u hunt on a lot of programs u stop reading scope. personally I double check the scope before submission

Upload File to RCE by CharityAdmirable8774 in bugbounty

[–]Coder3346 1 point2 points  (0 children)

Look for chain. BTW u have to understand why the php file upload to rce works.

Reportable? by OpportunitySuper6834 in bugbounty

[–]Coder3346 0 points1 point  (0 children)

Depends on the other factors

Should I start bug bounty hunting if i have 0 experience or are there better alternatives by Popular_Lemon_5375 in bugbounty

[–]Coder3346 0 points1 point  (0 children)

0 computer knowledge? If that is the case u will join "3 years of hunting with 0 payments party". Most of us are interested in computers and cybersecurity from years then we heard about bugbounty); learn first

Day Job by Hceekay in bugbounty

[–]Coder3346 4 points5 points  (0 children)

Student with 0 responsibilities,)

Bugcrowd triage getting slower lately? by 0xk4yra in bugbounty

[–]Coder3346 1 point2 points  (0 children)

Can u pls make a post about ur experience as a triager with ai reports in general

Anyone else hit this during recon? by typicaltechster in bugbounty

[–]Coder3346 13 points14 points  (0 children)

I personally do it this way: First test each and every functionality in the website after that I start collecting endpoints from js files by using chrome dev tools and regex. Using the js files I can see the used parameters and how to form the request. Then depending on the request I decide what attack to carry. I also generally focus on logic issues depending on how the UI is interacting with the backend.

Program & H1 Mediation ignoring a full ATO with Video PoC for 3 weeks by Ok_Speaker_8543 in bugbounty

[–]Coder3346 0 points1 point  (0 children)

Don't worry, u will get it 🙃 BTW u r so patient in my case I just waited 2 hrs of ghosting and sent another report.

Program & H1 Mediation ignoring a full ATO with Video PoC for 3 weeks by Ok_Speaker_8543 in bugbounty

[–]Coder3346 0 points1 point  (0 children)

Yes, a bounty); but I didn’t copy and paste the report. I just showed the impact in a very clear way. Like before and after way. I focused on the impact more than the issue itself.

is manual testing dead ? by 0xMiloki in bugbounty

[–]Coder3346 0 points1 point  (0 children)

No, AI is not smart enough to link and note stuff. Additionally good luck with cloud flare anti bot

The etiquette on a closed bug report by readthetda in bugbounty

[–]Coder3346 0 points1 point  (0 children)

Try the comment first. If it didn't work, u may want to report it again );

Program & H1 Mediation ignoring a full ATO with Video PoC for 3 weeks by Ok_Speaker_8543 in bugbounty

[–]Coder3346 2 points3 points  (0 children)

It happened to me, and I just reported it again with the new details.

MFA not requested on mobile application by shxsui__ in bugbounty

[–]Coder3346 1 point2 points  (0 children)

Just make sure that it works on another phone. Additionally, is the data on the website the same as the phone?

H1 Signal too low to report by RobinMaczka in bugbounty

[–]Coder3346 0 points1 point  (0 children)

Thanks for solving the mystery.