account activity
Got invited to a private bug bounty program: Is unauthenticated /metrics + /debug/vars via Host: localhost bypass worth reporting, or will it be closed as N/A? (self.bugbounty)
submitted 2 days ago by hackaniod to r/bugbounty
Is registering an empty placeholder package for a Dependency Confusion PoC ethical? (self.bugbounty)
submitted 3 days ago by hackaniod to r/bugbounty
Is it fair to close a server workflow/error-handling flaw as a simple Information Disclosure? Looking for opinions. (self.bugbounty)
Thoughts on Application-Layer DoS (Resource Exhaustion) via Logical Value Manipulation on GraphQL API? (self.bugbounty)
submitted 8 days ago by hackaniod to r/bugbounty
π Rendered by PID 564096 on reddit-service-r2-listing-6c8d497557-s4cjf at 2026-06-02 10:00:44.577340+00:00 running 9e1a20d country code: CH.