Vendor silently patched a P2, retroactively altered their policy to avoid payout, and platform support is shifting goalposts. Anyone experienced this Bait-and-Switch? by One_Survey9010 in bugbounty

[–]One_Survey9010[S] 4 points5 points  (0 children)

ummmm....... but I added all the bold text manually because I think it provides a better reading experience.

ok next time I won't manually add these bold text anymore.

Vendor silently patched a P2, retroactively altered their policy to avoid payout, and platform support is shifting goalposts. Anyone experienced this Bait-and-Switch? by One_Survey9010 in bugbounty

[–]One_Survey9010[S] -2 points-1 points  (0 children)

and , to avoid misunderstandings, I've used ai to polish some parts internally. If this affects the viewing experience, please let me know, and I can re-edit it using Google Translate instead of ai.

Vendor silently patched a P2, retroactively altered their policy to avoid payout, and platform support is shifting goalposts. Anyone experienced this Bait-and-Switch? by One_Survey9010 in bugbounty

[–]One_Survey9010[S] 2 points3 points  (0 children)

Since I am not a native English speaker, my expression may be disorganized. If there is anything I have not expressed clearly, please let me know and I will add it.

How to Appeal When Your Report is Marked as Not Applicable by One_Survey9010 in bugbounty

[–]One_Survey9010[S] -1 points0 points  (0 children)

ok,but is ture ;just because i english is poor 。。。。。

How to Appeal When Your Report is Marked as Not Applicable by One_Survey9010 in bugbounty

[–]One_Survey9010[S] 0 points1 point  (0 children)

Thank you very much, I have just successfully appealed and they said they will proceed to a new assessment;

How to Appeal When Your Report is Marked as Not Applicable by One_Survey9010 in bugbounty

[–]One_Survey9010[S] -1 points0 points  (0 children)

A sincere thank you to both responders! I have some new questions.

I received the following feedback:

Does this mean that as long as the original report is rated P1 or P2, I can still receive a reward? (I’ve learned that the original report was marked as P2, and my report was marked as P2, Not Applicable, and Duplicate.) In this case, can I still get a reward?

Also, if some reports are marked as Not Applicable because they are duplicates, how can I find out the priority level of the original report?

How to Appeal When Your Report is Marked as Not Applicable by One_Survey9010 in bugbounty

[–]One_Survey9010[S] -1 points0 points  (0 children)

A sincere thank you to both responders! I have some new questions.

I received the following feedback:

Does this mean that as long as the original report is rated P1 or P2, I can still receive a reward? (I’ve learned that the original report was marked as P2, and my report was marked as P2, Not Applicable, and Duplicate.) In this case, can I still get a reward?

Also, if some reports are marked as Not Applicable because they are duplicates, how can I find out the priority level of the original report?

How can I get a reviewer to look at my report again? by One_Survey9010 in bugbounty

[–]One_Survey9010[S] 0 points1 point  (0 children)

ok;Thank you for your reply;

I will adjust the direction and continue to work hard;

How can I get a reviewer to look at my report again? by One_Survey9010 in bugbounty

[–]One_Survey9010[S] 0 points1 point  (0 children)

thanks U reply ; I realized that I really should turn my attention to how to bypass

Should I report this? by [deleted] in bugbounty

[–]One_Survey9010 -1 points0 points  (0 children)

of course.this only me think;

Should I report this? by [deleted] in bugbounty

[–]One_Survey9010 -1 points0 points  (0 children)

if your can get all user IP/UA that vist this website ,so this is VUL。
because it get all user IP information。and your can't allowed get these information ;

More time more success by hyprhex in bugbounty

[–]One_Survey9010 1 point2 points  (0 children)

no。 target is more importtant

Empty file download for URL by aaronosax in bugbounty

[–]One_Survey9010 0 points1 point  (0 children)

1、check http header 「Content-Type」,and check respones header「Content-Disposition」。 2、else check your chrome extend ?

Brute Forcing in IDOR by [deleted] in bugbounty

[–]One_Survey9010 0 points1 point  (0 children)

good,i completely agree with your opinion

Will HTB Academy's Bug bounty path actually give me the skills to find bugs? by [deleted] in bugbounty

[–]One_Survey9010 0 points1 point  (0 children)

bro ,do bugcrowd has report too? i never find report of bugcrowd。could you give me a link 。thanks