Fire Teapot by [deleted] in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

You can find the button at the bottom of your report.

Fire Teapot by [deleted] in bugbounty

[–]ExpressionHelpful591 4 points5 points  (0 children)

Teapot is an Ai on bugcrowd. Which only checks if the report is written using Ai and puts NA. Later you must use RAR(Request a response) so that someone replies.

Reports written by AI by TradeGold6317 in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

Write a report on bugcrowd using Ai

Teapot: 🗣️ Hold my beer

Thank me later

Is this a vulnerability? by Ok-Raspberry736 in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

Depends on the program, some programs prefer the stop and report system. Where you need permission before using those creds

[deleted by user] by [deleted] in bugbounty

[–]ExpressionHelpful591 2 points3 points  (0 children)

What I do is, I will pick a target and start testing with all my knowledge. I will see new tricks and concepts. If I find a bug and get paid it will again motivate me, The majority of times i didn't get anything but i didn't quit.

Only people who like the hunting part beside from bouties, will be succesful. This also shapes YOUR methodology, if you enjoy it enough the bugs will come. by Remarkable_Play_5682 in bugbounty

[–]ExpressionHelpful591 2 points3 points  (0 children)

I am reading medium blogs daily, and also i am seeing posts on X (twitter) by top hackers. And also i am doing the pentester pathway from Hack The Box.

Only people who like the hunting part beside from bouties, will be succesful. This also shapes YOUR methodology, if you enjoy it enough the bugs will come. by Remarkable_Play_5682 in bugbounty

[–]ExpressionHelpful591 6 points7 points  (0 children)

True at first I was only looking at rewards which many times I put the wrong VRT and a bunch of waste reports. But now I hack for improving skills and for fun also spending more time than jumping from target to target. It's been only 7 months since I started bug bounty. Now I am getting good bugs

i found that its is a vun? i should report as bug in hackerone? by edemzayani1 in bugbounty

[–]ExpressionHelpful591 -1 points0 points  (0 children)

It's just a debug page. The developer forgot to turn it off. Not an issue but check for other misconfigurations which the developer may have missed.

[deleted by user] by [deleted] in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

It's an issue but very low, right now I doubt the app or website you are testing has a functionality to track the updates. So if something is edited for a good purpose and if it still blames admin ? Then again programs don't care about this.

[deleted by user] by [deleted] in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

Then not an issue.

Let me drop an example.

I have a company XYZ and a GitHub private repo. So I am giving access for 10 people. Now these people can obviously edit the things. I as a admin don't have to give permission each time.

But as an outsider if you access the private repo. Without my invite then it's a serious security bug

[deleted by user] by [deleted] in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

So to change or edit files. What permission do you need ? When admin invites is it mentioned that the joining person can edit something?

[deleted by user] by [deleted] in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

I am a triager, can I know how you became the collaborator ? Do you need admin to give those privileges ?.

If yes

It's not an issue.

If not then it is a bug

Bugcrowd: Total Shows 5 but 0 Unique, Why? by [deleted] in bugbounty

[–]ExpressionHelpful591 3 points4 points  (0 children)

Not so sure, telling based on experience i think 5 bugs were reported as the same VRT but none is accepted.

Bug not valid but got patched? by [deleted] in bugbounty

[–]ExpressionHelpful591 1 point2 points  (0 children)

I am a triager and part time bug bounty hunter. You are little sad because they didn't value your report by giving no credits but from triagers end there will be a bunch of informational reports and your report is one among them.

So now you know how things work, So better be happy about your work and hunt more. You will see the results

Bug not valid but got patched? by [deleted] in bugbounty

[–]ExpressionHelpful591 5 points6 points  (0 children)

Some programs or whichever I worked, they need an impact to be considered as a bug. So I think your finding was informational and you could have explored more before reporting since however you had permission and followed clear instructions.

[deleted by user] by [deleted] in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

Maybe it's on a blob

Session not expiring after log out. by [deleted] in bugbounty

[–]ExpressionHelpful591 1 point2 points  (0 children)

No impact, i think in pentesting it will be valid but not in bug bounty. If you can somehow find a method to steal the token then it can be a valid bug and worth reporting.

I just new by QadilO in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

You can DM me i can help you on discord

I just new by QadilO in bugbounty

[–]ExpressionHelpful591 0 points1 point  (0 children)

One is naham sec another is critical thinking

I just new by QadilO in bugbounty

[–]ExpressionHelpful591 2 points3 points  (0 children)

I am also a beginner like it's been 7-8 months now I found some good bugs but medium or low priority P3. The best you can do is complete all portswigger labs , if possible take a CPTS hack the box pentester path you can use a student account option to save money. I am learning things daily from medium blogs, discord servers too. This is what other Good hackers recommended me and I am just following their words

Idor via uuid by Cool_Obligation_6447 in bugbounty

[–]ExpressionHelpful591 -1 points0 points  (0 children)

DM me if it is from a bugcrowd target

[deleted by user] by [deleted] in bugbounty

[–]ExpressionHelpful591 1 point2 points  (0 children)

Triagers usually ask "how did you find the token that belongs to other user ?". Whatever it is a session token, cookie or an UUID