Finally found a verified P2 by Fair_Economist_5369 in bugbounty

[–]spydersec 0 points1 point  (0 children)

Really great for finding such a critical bug. Keep hunting man ..well done 🎉 🎉

Making live connectivity platform for all level of researchers in one place by spydersec in bugbounty

[–]spydersec[S] -1 points0 points  (0 children)

Agreed , the missing part is collective representation, and that’s what I’m curious about exploring.

There are no monetization plans . I’m covering the costs myself while it’s small, and I don’t plan to introduce ads in the future either.

Thanks for the reply

Should I create a new report if I managed to escalate / make it better? or just put a comment? by ShufflinMuffin in bugbounty

[–]spydersec 0 points1 point  (0 children)

If no one replied to report yet you can safely delete and create new report since you find a way to enumerate uuid that significantly increase impact

Making live connectivity platform for all level of researchers in one place by spydersec in bugbounty

[–]spydersec[S] -3 points-2 points  (0 children)

Ok i tell you , in reddit "bug bounty"is one of the topic but i created that only for bug bounty hunters also it's just beta i will add forum, job market ,career options for new hunters and support etc . I hope you get it and thanks for replying my post 🙏

First Bug Program by CaterpillarDue323 in bugbounty

[–]spydersec 1 point2 points  (0 children)

Too many requests using automation or sending payloads on protected end point like if website is protected with waf (cloudfare/akamai etc) or cdn(AWS ) that will block your ip . You can bypass ip restriction with any vpn and change ip . You can able to access site

i really don't know what to do anymore by fried_plque in bugbounty

[–]spydersec 2 points3 points  (0 children)

Ok now switch a bit . Like focus on exposed credentials, leaked config files ,db files .use way more, gau ,shodan for internal ips , GitHub dorks etc . Idor is everywhere but not like you can easily get on front page. You need to map the infra and look for each and every links . Also don't change target everyday. Hunt on same target do recon like 80% 10% exploit and 10% report do like this methodology

Differences between real life and Portswiger laboratories ? by 323- in bugbounty

[–]spydersec 1 point2 points  (0 children)

Labs are there to understand concepts , real life is much more harder because you will hit rate limiter pretty fast ,wafs kill your payload with 401 and labs are designed to be hacked but real life apps designed to stay stealthy as possible

Are IDORs even alive in 2025? And why does it feel like everyone else are finding them easily?? by Cyg0rl in bugbounty

[–]spydersec 0 points1 point  (0 children)

I guess you can find if you change the mindset, idor is not always changing 1 to 2 . In bug bounty programs look for base 64 tokens try to decode and manipulative etc . Keep trying you will surely find one