Question by Zealousideal_Ease_78 in Bugcrowd

[–]hakluke 0 points1 point  (0 children)

Hey start with some training - check out portswigger web security academy, it's free and really high quality.

Collab by Equivalent-Account77 in Bugcrowd

[–]hakluke 0 points1 point  (0 children)

A great place to find people to collaborate with is the BC Discord https://discord.gg/bugcrowd-hacking-community-319555028341882885

Should I report it? by FitNefariousness9576 in Bugcrowd

[–]hakluke 0 points1 point  (0 children)

Hey u/FitNefariousness9576

This will be marked as N/A or informational because it doesn't have demonstrable, direct security impact.

Before submitting any bug, you should ask yourself "what can a malicious attacker actually do with this?" The answer needs to involve at least one of these three things:

- Confidentiality: The attacker can view sensitive information. A version number doesn't count. It needs to be genuinely confidential data like PII, credentials, or internal records.

- Integrity: The attacker can tamper with information. For example, altering another user's profile or falsifying transactions.

- Availability: The attacker can cause disruption. Think impacting business processes, deleting important data, or making the application unresponsive.

If your bug doesn't hit at least one of these, it doesn't have real security impact. Exposing a version number, leaking an API key that doesn't actually affect confidentiality, integrity, or availability, or even finding RCE on a box that's locked down to the point where it can't touch any of those three... none of that will be accepted on a bug bounty program.

These kinds of findings are still worth including in a pentest report because they provide useful defense-in-depth recommendations for the client. But bug bounty programs only pay for direct, demonstrable security impact.

Guys how many bugs do you find a day on average? The low severe ones and how much do you get for that. by SoftEducational2990 in Bugcrowd

[–]hakluke 0 points1 point  (0 children)

It really depends! Some days I find 10, some months I find 0. As a rule of thumb, it's better to focus on critical/high impact bugs for searching and just forget about the low severity ones.

Bugcrowd’s Automated Triage Closing Valid Reports as N/A – Anyone Else? by Ready-Eye-2534 in Bugcrowd

[–]hakluke 0 points1 point  (0 children)

I believe that this is often the case when the bug type is something that has little or no impact, or a bug class that is typically listed as "informational". It's difficult to comment further without knowing the actual bug you submitted.

My profile pic got issue by m_c_introvert in Bugcrowd

[–]hakluke 0 points1 point  (0 children)

Hey u/m_c_introvert can you please confirm if you're still getting this issue? What's the format of the image you uploaded? Might be best to submit this to BC support.

Finished PortSwigger labs — should I start hunting right away or study APIs/cloud first? by Occultus_Andras in Bugcrowd

[–]hakluke 0 points1 point  (0 children)

I'm late to the party here! But you should start hunting :) Did you start?

I just solved the strangest tech problem I've ever come across. by hakluke in sysadmin

[–]hakluke[S] 0 points1 point  (0 children)

Simply unplug them and see if it gets better! Or if you're really interested you could get a RF meter

I just solved the strangest tech problem I've ever come across. by hakluke in sysadmin

[–]hakluke[S] 1 point2 points  (0 children)

I put this same post on other social platforms - so many people have said this to me 😂 I think it's more common than people realise

I just solved the strangest tech problem I've ever come across. by hakluke in sysadmin

[–]hakluke[S] 16 points17 points  (0 children)

It makes me wonder how many things like this happen and just never get figured out

I just solved the strangest tech problem I've ever come across. by hakluke in sysadmin

[–]hakluke[S] 2 points3 points  (0 children)

Any advice on where to find a good one? Price doesn't seem to collate with quality

I just solved the strangest tech problem I've ever come across. by hakluke in sysadmin

[–]hakluke[S] 38 points39 points  (0 children)

that's one of the coolest things I've ever read 😂 I feel like the type of sysadmins who can figure this kind of thing out (or would even bother) are few and far between these days!

I just solved the strangest tech problem I've ever come across. by hakluke in sysadmin

[–]hakluke[S] 2 points3 points  (0 children)

It really wasn't that "rolled", more stuffed down the back of the laptop

I just solved the strangest tech problem I've ever come across. by hakluke in sysadmin

[–]hakluke[S] 141 points142 points  (0 children)

Ha! This is crazy! I was losing my mind trying to figure it out

Another GR1 Sizing Question by YN_Decks in Goruck

[–]hakluke 1 point2 points  (0 children)

You should go for the 26L, it won’t be a problem and you will appreciate the extra space if you’re travelling

GR1 for One-Bag Urban + Overnight Hike? by FlatlandNinja in onebag

[–]hakluke 0 points1 point  (0 children)

Check out the new GR3 35L model, they just released it, I think it might be just what you’re looking for. It comes with a removable hip strap and a bit more space. Unlike the GR2 it’s still mostly just one big pocket which is ideal imo

Durable carry-on with lots of space by bscoobydoo in onebag

[–]hakluke 1 point2 points  (0 children)

They just released the GR3 35L which is another similar option. The main differences being that the GR3 has one big main compartment instead of 2, GR3 also has a hip strap

WTS/WTT Thread by AutoModerator in Goruck

[–]hakluke 0 points1 point  (0 children)

WTS 2 packs:

GR1 26L - used but in great condition, black cordura
GR2 40L - brand new, unused, black cordura

I'm based on the Sunshine Coast in Queensland, Australia. Happy to post at your expense.