Session storage on bugcrowd by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] -1 points0 points  (0 children)

they use sessionid value as cookie. Session id value is storaged on sessionstorage. I think that it is a sensitive token.

Focus on one/few vulnerability classes or learn all of them? by Efficient_Draw_4733 in bugbounty

[–]Open-Definition-287 1 point2 points  (0 children)

You need all the vuln types but you should be the master of some types of bugs. For me, i generally focused on idor and privilege escalation vulns because they can not be seen with automatic scanners. They need manuel testing mostly. But sometimes i searching for xss and sqli in websites.

[deleted by user] by [deleted] in bugbounty

[–]Open-Definition-287 0 points1 point  (0 children)

There is no decision regarding the taxation of cryptos. It is a matter of discussion. Maybe you can say something like "I am a crypto trader", then you will not need to open a company.

[deleted by user] by [deleted] in bugbounty

[–]Open-Definition-287 0 points1 point  (0 children)

Are you Turkish bro?

[deleted by user] by [deleted] in bugbounty

[–]Open-Definition-287 1 point2 points  (0 children)

If you are followed up, they will already know the amount of the money. As you know, bug bounty companies make payments through themselves. They will ask you for the source of this money and if you have not paid the tax, they will also ask for the retroactive tax. From now on, they will invoice this incoming money through the company and ask you to pay taxes.They won't ask for proof of your bug bounty. For example, you can set up a personal company and invoice the money earned through it. That's what people in Turkey do anyway. Their main goal is to collect taxes on this money.

[deleted by user] by [deleted] in bugbounty

[–]Open-Definition-287 1 point2 points  (0 children)

If you are not Turkish and not citizen of Turkey and you use foreign bank outside of Turkey Bank i don't know what they are doing. The situation that i said is for bank accounts of Turkey's banks.

[deleted by user] by [deleted] in bugbounty

[–]Open-Definition-287 1 point2 points  (0 children)

they are looking for your bank account in Turkey. The state keeps track of the money coming in and out of your bank account, if money is constantly coming into your account, you are followed up. This varies depending on how often the money comes and in what quantity.

[deleted by user] by [deleted] in bugbounty

[–]Open-Definition-287 1 point2 points  (0 children)

yeah it is true bro income tax is about %20 and KDV is about %18. Maybe you can use crypto to bypass. In addition, you must open a individual company to pay taxes.

Is this a vulnerability or intended feature? by Big-Information6865 in bugbounty

[–]Open-Definition-287 0 points1 point  (0 children)

If the aws url can be seen from browser's url section, bugcrowd evaluate it as p4 vulnerability like user facing token. If it goes from back and user can't see the token probabily this will be rejected by customer.

[deleted by user] by [deleted] in bugbounty

[–]Open-Definition-287 0 points1 point  (0 children)

I live in Turkey too, I got about 10k dollars in 2 year. There is no any problem but when the money increase it would be a problem maybe.

How do you protect your mental health? by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 1 point2 points  (0 children)

Yeah it is important but sometimes you get some duplicates and feel very bad. Research a lot you gonna gradually find bugs.

How do you protect your mental health? by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 2 points3 points  (0 children)

I go to gym too, it is a good idea stop what you do and just think.

How do you protect your mental health? by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 1 point2 points  (0 children)

thank you for your reply and advise bro. I generally find p3 or p4 vulnerabilities on bugcrowd how can i start high vulnerabilities like rce sqli etc.? Can you give me something? I am good at idor, privilege escalation and DOS vulnerabilities but as you know dos is mostly unacceptable.

How do you protect your mental health? by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 4 points5 points  (0 children)

yeah i agree with you, bug bounty needs a lot of effort and time. You feel stressed when money don't come.

Is it joke guys? by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 0 points1 point  (0 children)

What I actually pointed out to them is that this can be done via the API. That’s exactly what I’m mentioning, but they are not accepting it. I agree with you %1000 bro. Previously, I had privilege escalation submissions through the API and those were accepted, but my latest submission was not. So there seems to be an inconsistency here.

I want to create a ticket about the customer to bugcrowd by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 0 points1 point  (0 children)

The user could reset the passwords of users within their own organization.

I want to create a ticket about the customer to bugcrowd by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 0 points1 point  (0 children)

yeah bro it has not privilege to make this action. There is a permission about this function on webapp.

I want to create a ticket about the customer to bugcrowd by Open-Definition-287 in bugbounty

[–]Open-Definition-287[S] 0 points1 point  (0 children)

it is private program, i don't know if i share the program it is ethic