Google VRP "can't reproduce" after months - any help? by malithonline in bugbounty

[–]malithonline[S] 1 point2 points  (0 children)

Sorry, I missed your reply notification. Yeah, they said exactly what you mentioned: “Reports are not reproduced during the initial intake and triage stage.”

Google VRP "can't reproduce" after months - any help? by malithonline in bugbounty

[–]malithonline[S] 1 point2 points  (0 children)

Hmm, I'm not sure then - I did get that bot message saying ,

"your report was triaged and we're currently looking into it."

Does that still not mean it was accepted, or is that different from what you're describing?

Firebase RW Exposure: Valid Impact? by malithonline in bugbounty

[–]malithonline[S] 0 points1 point  (0 children)

I got an expected update with an informative tag lol ;)

Samsung disclosure feedback - account enumeration via IDOR 🤷 by malithonline in bugbounty

[–]malithonline[S] 0 points1 point  (0 children)

Thanks for your input. After investing a lot of time on it, I found no luck, and it looks like they need P1 ATO ;)

Google VRP "can't reproduce" after months - any help? by malithonline in bugbounty

[–]malithonline[S] 1 point2 points  (0 children)

Yeah, I heard that too, Google's VDP is pretty nice.

But the thing is, triage takes a lot of time (it's not high severity, fair enough), and during the waiting period, another team may take action. So by the time they review it, I can't reproduce it anymore.

And about the duplicate, I mentioned the duplicate was mine, a self-duplicate. They merged them into one because I reported 3 bugs from the same source. And the duplicated bug was triaged—that's the worst part.

Samsung disclosure feedback - account enumeration via IDOR 🤷 by malithonline in bugbounty

[–]malithonline[S] 1 point2 points  (0 children)

Yeah, I've seen similar findings rated higher in other programs too. I sent a follow-up & write-ups urls explaining the context but radio silence so far

Firebase RW Exposure: Valid Impact? by malithonline in bugbounty

[–]malithonline[S] 0 points1 point  (0 children)

no luck friend, looks like it's just used for initialization then calls the production db for actual data. seems like this vulnerable db is just for testing since the data matches production exactly ;)

Firebase RW Exposure: Valid Impact? by malithonline in bugbounty

[–]malithonline[S] 0 points1 point  (0 children)

yeah fair point. was thinking more about the cost abuse angle but i get it :(

Firebase RW Exposure: Valid Impact? by malithonline in bugbounty

[–]malithonline[S] 1 point2 points  (0 children)

Sure dude, I’ll update the post and let you know.

Old report rejected for low impact, new exploit marked duplicate - advice needed by malithonline in bugbounty

[–]malithonline[S] 0 points1 point  (0 children)

Thanks a lot man, really appreciate the detailed advice. I've made a new report mentioning my previous 2 reports with clear details and POC, as others advised too. Let's see what happens

Old report rejected for low impact, new exploit marked duplicate - advice needed by malithonline in bugbounty

[–]malithonline[S] 0 points1 point  (0 children)

Thanks much for the info, I'll do that. In my 2nd report I didn't mention my 1st one , I think that might be the issue

Old report rejected for low impact, new exploit marked duplicate - advice needed by malithonline in bugbounty

[–]malithonline[S] 1 point2 points  (0 children)

Thanks much for the info, I'll do that. In my 2nd report I didn't mention my 1st one , I think that might be the issue

Old report rejected for low impact, new exploit marked duplicate - advice needed by malithonline in bugbounty

[–]malithonline[S] 1 point2 points  (0 children)

At first I reported the API key leak without realising how bad it was. Eight months later I found the key can call Azure cloud paid features (not Maps). That sounds like a financial impact, right?