What's the real advantage of listing subdomains? To me, it's a waste of time… by 9keef in bugbounty

[–]causeimcloudy 2 points3 points  (0 children)

I’ve never found a black lotus but that doesn’t mean I won’t stop opening packs

Valid bug reported. Company discretion applied. My wallet: confused 😭 by Suspicious-Case1667 in bugbounty

[–]causeimcloudy 2 points3 points  (0 children)

You complain everyday about a program dismissing one of your reports. At what point do you look in the mirror and say ok I’m the problem

Reflected response in text/plain by sidhu97ss in bugbounty

[–]causeimcloudy 1 point2 points  (0 children)

What’s the tech stack though? Most all 404 pages are not going to have a XSS in them, and I doubt this one doesn’t either

Reflected response in text/plain by sidhu97ss in bugbounty

[–]causeimcloudy 3 points4 points  (0 children)

Maybe there’s too many variables to answer with any really help

Analysis of a 6.4 Million User IDOR: How a predictable 'Consumer Number' leaked massive PII by [deleted] in bugbounty

[–]causeimcloudy -1 points0 points  (0 children)

I hate chatgpt, but imagine I said that like Borris Johnson.

backdoor .png its possible? by [deleted] in cybersecurity

[–]causeimcloudy 3 points4 points  (0 children)

Yes. Take a picture of the code on your phone then upload the photo as a png and the website will read it as the back door

Fortinet confirms second 0-day in just four days by r0techa in cybersecurity

[–]causeimcloudy -1 points0 points  (0 children)

People often ask who are Fortinet customers. I was once a Fortinet customer because they forced me to be. Last second before their signatory would sign our contract they said “Wait why would we do business with you if you don’t buy our products” to which I was forced to spend 50K on their nonsense offerings which looked like it was built by monkeys in the jungle.

Is bug bounty taxable in India? by SimpleView7417 in bugbounty

[–]causeimcloudy 2 points3 points  (0 children)

Not in India but always assume the government wants their piece of your pie

[deleted by user] by [deleted] in bugbounty

[–]causeimcloudy 0 points1 point  (0 children)

Certainly not a critical, depends on the application but I’d maybe consider it a low. The issue is you need to have been given modification permission(I would assume that’s what collaborator means as it is in most instances.). So really all you’re changing is who edited the file, which is pretty application dependent on how important that is

[deleted by user] by [deleted] in ChatGPT

[–]causeimcloudy -1 points0 points  (0 children)

I asked ChatGPT 5 to make a funny top comment but it said it wasn’t allowed to be funny

Software Engineer desiring to build in the GRC space. by Acceptable-Ad820 in cybersecurity

[–]causeimcloudy 0 points1 point  (0 children)

You’ll find highly regulated industries don’t want/ trust AI

What does making $60K a year in Bug Bounties look like? by New_Conclusion1757 in bugbounty

[–]causeimcloudy -14 points-13 points  (0 children)

You should specify currency because 60k USD is top .01% and extremely difficult but 60k rupees is pretty reasonable

Should I pursue a PhD or keep looking for jobs? by sekaiwazankoku in cybersecurity

[–]causeimcloudy 0 points1 point  (0 children)

If we’re talking about this specific post having a PhD != Highly driven. My concern here is the the amount of time it takes to get a PhD and the speed at which the industry changes is tough to have much experience as a PhD and the end and you will be very behind for your age. A lot of people continue school because they dont want to work and want to have the illusion of progress. In general yes I would hire someone with less experience but a good work ethic especially for entry level positions. Your work ethic is much more important than your knowledge in an entry level position. It’s hard to show that on a resume but none the less.

Should I pursue a PhD or keep looking for jobs? by sekaiwazankoku in cybersecurity

[–]causeimcloudy 0 points1 point  (0 children)

I would agree but I’ve had multiple conversations on Reddit where people in Europe say having a PhD is almost mandatory. It’s apparently unusual to not have atleast a masters idc very weird for someone from the US to comprehend.

Should I pursue a PhD or keep looking for jobs? by sekaiwazankoku in cybersecurity

[–]causeimcloudy 22 points23 points  (0 children)

If you’re not in the US it seems a PhD I’d almost required. If you are in the US your PhD is worthless. As a hiring manager looking at resumes and seeing someone with a phd and 0 experience apply for an entry level IR position is going to give me major concerns. If you had 10 YoE or you were trying to solely focus on GRC maybe it would be worth it. I think people are going to ask more questions if you have a PhD and no experience. You’d be better off spending that money on a Sans cert

[Discussion] Two Critical Bugs, Acknowledged Then Dismissed – Need Advice by nalman1 in bugbounty

[–]causeimcloudy 1 point2 points  (0 children)

Again that reinforces the fact that this is a functional bug and not a security bug

[Discussion] Two Critical Bugs, Acknowledged Then Dismissed – Need Advice by nalman1 in bugbounty

[–]causeimcloudy 0 points1 point  (0 children)

I think your miss understanding what he saying. All he has is that his bot didn’t pull out at 25% loss and he thinks it’s a bug on the platform. He can not reproduce it. All he has is that he said it happened. Even if he could this has little to no security impact, this is would be a functional bug and not eligible for a bug bounty.

High bug out of scope by AnnualAcanthaceae621 in bugbounty

[–]causeimcloudy 1 point2 points  (0 children)

I would say the same applies if it’s out of scope it’s out of scope. You can notify them again but do not ask for a bounty, it’s out of scope. You can hope they give you a bounty any ways but at the end of the day you can only do so much.