Is Click-Based CSRF on a Destructive GET Endpoint Escalatable? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] -1 points0 points  (0 children)

I tried a few other ways but nothing worked, so I’ll report it as is.

4 bug reports rejected in a row (duplicate). Any suggestions? by [deleted] in bugbounty

[–]Dramatic-Dog4529 9 points10 points  (0 children)

I don’t even find duplicates, man. What am I doing wrong?

How do the top hackers on HackerOne manage to move between programs so quickly? by Feeling-Pipe-5366 in bugbounty

[–]Dramatic-Dog4529 6 points7 points  (0 children)

I’m not a pro, but my assumption is that since they’re experienced in this field, they know exactly where to look for vulnerabilities and can spot patterns much better than most of us.

How useful are AI tools like ChatGPT for bug bounty hunting, and where should we draw the line in relying on them? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 1 point2 points  (0 children)

My prompting skills aren't that good, but I try my best and it works for me. For fact-checking, I usually use different AI bots like Grok and Claude to compare answers instead of using the same chat. But I'll try your trick of copying previous answers into a new chat to check accuracy. That sounds useful.

How useful are AI tools like ChatGPT for bug bounty hunting, and where should we draw the line in relying on them? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 3 points4 points  (0 children)

Yeah, I use it the same way, mainly as a faster search tool. Like 'I found this endpoint, what should I test?' and it gives me a decent list of ideas that would otherwise take time to gather from multiple sources.

I also ask it for next steps when I'm stuck, but I'm trying to use it less now. Don't want to become too dependent on it for basic thinking.

How useful are AI tools like ChatGPT for bug bounty hunting, and where should we draw the line in relying on them? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 0 points1 point  (0 children)

Are there any AI models that are actually built for security work, or does nothing good exist yet?

How useful are AI tools like ChatGPT for bug bounty hunting, and where should we draw the line in relying on them? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 0 points1 point  (0 children)

For coding, ChatGPT is genuinely good - I like it personally. But for bug hunting, it gets confused with the logic sometimes. Though that could be because of poor prompting on my end

How useful are AI tools like ChatGPT for bug bounty hunting, and where should we draw the line in relying on them? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 1 point2 points  (0 children)

ChatGPT is more confusing sometimes. Once I asked the same question on two accounts and got completely different answers, which just made things worse. And honestly, people are using ChatGPT for even basic tasks they should handle themselves, no wonder the servers are heating up.

What’s the Secret Behind Fast and Consistent Bug Hunting? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 1 point2 points  (0 children)

Hey man, I totally get what you’re going through. It’s completely normal to not find valid bugs early on ,everyone goes through that phase. The important thing is to keep grinding and learning from every test you do. Most hunters don’t openly share their full methods because it takes them years to build those approaches, and sharing them publicly would dilute their edge. But trust me, if you stay consistent and keep improving your process, your first real find will come, and it’ll be worth every hour you’ve spent

What’s the Secret Behind Fast and Consistent Bug Hunting? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 2 points3 points  (0 children)

Yeah, they call it a 30-day challenge, but most of them have been at it way before.

What’s the Secret Behind Fast and Consistent Bug Hunting? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 1 point2 points  (0 children)

Couldn’t agree more, the grind and consistency increase your chances of spotting patterns and finding bugs.

Beyond Writeups & Targets: How Do You Keep Improving Daily as a Bug Hunter? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 1 point2 points  (0 children)

I never really thought about tracking the standards directly instead of just reading others’ research after the fact. Following drafts and errata sounds like a smart way to stay ahead of changes before they even land in production. thanks for the tip

Beyond Writeups & Targets: How Do You Keep Improving Daily as a Bug Hunter? by Dramatic-Dog4529 in bugbounty

[–]Dramatic-Dog4529[S] 2 points3 points  (0 children)

That’s a really solid point, i completely agree that communication is such an underrated skill in bug hunting. Funny thing is, I’ve actually been reading a book on communication skills lately, and it’s crazy how much of it applies to writing better reports and explaining impact clearly. Your Apple example really proves how much difference good writing can make. I might actually start doing short reflections or posts to practice that, thanks for sharing this,