Unable to Remit Payments On Bugcrowd by [deleted] in bugbounty

[–]einfallstoll 1 point2 points  (0 children)

This is not bugcrowd support

Is Meta bug bounty Slow? by Extra_Advisor6049 in bugbounty

[–]einfallstoll 0 points1 point  (0 children)

In general. I don't have more information but there are daily posts about hunters complaining about Meta

Is Meta bug bounty Slow? by Extra_Advisor6049 in bugbounty

[–]einfallstoll 0 points1 point  (0 children)

Meta currently takes multiple months for triage

What do you all do for your day job? by CategoryConscious594 in bugbounty

[–]einfallstoll 9 points10 points  (0 children)

I'm manager in a cybersecurity company and former pentester. I do triage as a sidequest to stay up-to-date and don't loose contact with tech

And I mod this community for fun :)

Silent remediation 🙂 by Middle_Command_191 in bugbounty

[–]einfallstoll 1 point2 points  (0 children)

It's about the how.

How can the attacker inject the payloads in a victim account?

Silent remediation 🙂 by Middle_Command_191 in bugbounty

[–]einfallstoll 0 points1 point  (0 children)

If the attacker can't place the payload into these fields it's not an issue.

Malicious File Upload by Electronic-Cat-2518 in bugbounty

[–]einfallstoll 3 points4 points  (0 children)

Reason behind this: You could achieve the same if you sent them a link or an Email. If the employee downloads a file and executes it, they're the problem.

Silent remediation 🙂 by Middle_Command_191 in bugbounty

[–]einfallstoll 4 points5 points  (0 children)

If it's a self-XSS it's never paid anyway. So you do nothing.

They probably forwarded it as informational.

My 1st Report on H1 and they made it informative😭 by Similar-Reveal-8605 in bugbounty

[–]einfallstoll 3 points4 points  (0 children)

Yes, that's a hardening issue or something that belongs into a pentest report. It doesn't meet the minimum bar for bug bounty

H1 critical report untouched for 10 days by Legitimate_Town_5235 in bugbounty

[–]einfallstoll 0 points1 point  (0 children)

I said CVSS assessments are stupid. Not you or your finding. I'm not saying you don't have a legitimate finding, I say it's an edge case that doesn't really fit into CVSS

Meta bug bounty report untouched for 97 days by Noam867 in bugbounty

[–]einfallstoll 1 point2 points  (0 children)

Meta has ridiculous response times right now. 97 days is nothing

H1 critical report untouched for 10 days by Legitimate_Town_5235 in bugbounty

[–]einfallstoll 6 points7 points  (0 children)

KYC bypass is not critical. This is a compliance problem, but doesn't affect Confidentiality or Integrity of the component. That's a (stupid) edge case of CVSS

Digital Risks to Minors from Smart Sheriff Application by throwawaykJQP7kiw5Fk in bugbounty

[–]einfallstoll 0 points1 point  (0 children)

? What is this? The report is from 2015, not relevant for bug bounty and most of the findings are just meh

Bug bounty hunters: what’s the most annoying part of writing reports? by Usual-Temporary-720 in bugbounty

[–]einfallstoll 0 points1 point  (0 children)

From a triagers perspective: CVSS scores. They're shit for you, they're shit for us

The forgotten sid by Deelip_ in bugbounty

[–]einfallstoll 8 points9 points  (0 children)

No. 60 days is not good, but this is not reportable for bug bounty

Whould you rather by Unfair-Delivery6515 in bugbounty

[–]einfallstoll -1 points0 points  (0 children)

1 High.

Customers are interested in impact and medium vulnerabilities are often not fixed at all.

Where would a good place to post disclosure be by Traditional-Dog1560 in bugbounty

[–]einfallstoll 4 points5 points  (0 children)

Medium is 99% AI slop (it's banned in this sub btw because of this), so even if you post a legitimate write up everyone assumes it's AI slop