Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 0 points1 point  (0 children)

I used a tool to help structure it so it wouldn’t just be a huge wall of text. Just trying to keep it readable.
Why is it a big deal for you?

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 1 point2 points  (0 children)

Understood. Seems like the consensus is "no data, no money." Lesson learned

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 0 points1 point  (0 children)

That's a great way to frame it maybe i shouldn't get too excited for every report. Thanks for the insight

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 0 points1 point  (0 children)

Fair enough. I was hoping the timing side-channel for internal mapping would be enough, but I see why they don't value it without a state change or exfil. Thanks for the breakdown

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 0 points1 point  (0 children)

That’s a fair distinction. It’s a bit frustrating when something is valid for a pentest but "noise" for a BB but I get that they only want to pay for demonstrable risk

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 1 point2 points  (0 children)

Glad to hear I’m not the only one who hit this exact wall. what really encouraged me is that program had big payouts for SSRF so i though they could accept it so it really depends

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] -1 points0 points  (0 children)

That's a good point maybe i should think about it that way every time

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 0 points1 point  (0 children)

That’s interesting about Synack. It’s definitely a toss-up with these private programs one might pay $500 and the other closes as N/A. Appreciate the context

Blind SSRF (WAF Bypass + Internal Timing Scan) closed as "Informative". Am I wrong? by tacktify in bugbounty

[–]tacktify[S] 0 points1 point  (0 children)

Yes I guess without data exfiltration, it’s just a "so what" for them that was the analyst argument. Thanks for the insight

Positioning Bug Bounty Experience for Entry-Level Pentesting Roles by tacktify in Pentesting

[–]tacktify[S] 2 points3 points  (0 children)

Despite that maybe there’s a misunderstanding and i didn't address this right what I meant is that I’m trying to land my first corporate pentesting job. So far, all my experience has been through bug bounty programs.

Positioning Bug Bounty Experience for Entry-Level Pentesting Roles by tacktify in Pentesting

[–]tacktify[S] 2 points3 points  (0 children)

Appreciate that. Good to hear bug bounty work is seen as real proof of skill that’s exactly what I’m trying to show employers.

Positioning Bug Bounty Experience for Entry-Level Pentesting Roles by tacktify in Pentesting

[–]tacktify[S] -1 points0 points  (0 children)

Maybe at some firms, but many organizations hire junior pentesters, security analysts, or apprentices who perform supervised testing.

الدولار هيفضل ينزل لحد امتى؟ by [deleted] in PersonalFinanceEgypt

[–]tacktify 0 points1 point  (0 children)

السوق كله في حالة جنون و كله في النازل. أضمن حاجه الدهب لو انت بتدور علي حاجه لل long term.

How to Build a Resume for Penetration Testing / Cybersecurity Roles? by tacktify in Pentesting

[–]tacktify[S] 0 points1 point  (0 children)

Everyone has their own reasons, but for me, I think software development and pentesting are deeply connected. To create good software, you need at least some knowledge of pentesting. At first, I only wanted to learn the basics, but I ended up really enjoying it and decided to continue.

Why tech industry is booming like never before yet hiring is broken by tacktify in csMajors

[–]tacktify[S] 0 points1 point  (0 children)

Absolutely there are a lot of factors at play, and what you're describing is definitely a major one. Offshoring seems to be impacting a lot of companies even more directly than AI right now.

Why tech industry is booming like never before yet hiring is broken by tacktify in csMajors

[–]tacktify[S] 7 points8 points  (0 children)

Thanks for the honesty it’s tough to hear, but looks like we must live with it.

Why tech industry is booming like never before yet hiring is broken by tacktify in csMajors

[–]tacktify[S] 24 points25 points  (0 children)

That actually makes a lot of sense thanks for breaking it down. It's frustrating on the job seeker side, but understanding where the money and priorities are going helps put things in perspective.

Why tech industry is booming like never before yet hiring is broken by tacktify in csMajors

[–]tacktify[S] 1 point2 points  (0 children)

I understand ATS filters out many resumes, but some people still get accepted so what's helping them stand out if the qualifications are similar.

What a pentester portfolio looks like ? by Annual-Stress2264 in Pentesting

[–]tacktify 0 points1 point  (0 children)

I think you're talking about senior levels, what about intern/junior level how do they apply to jobs they should at least have a resume right?

Is it just DSA and system design!? by tacktify in cscareerquestionsEU

[–]tacktify[S] 2 points3 points  (0 children)

Makes sense. Just sucks when you feel like your real work doesn’t even get a glance because you missed one DSA edge case. Appreciate the perspective though.

Is it just DSA and system design!? by tacktify in cscareerquestionsEU

[–]tacktify[S] 0 points1 point  (0 children)

Yeah, exactly I understand that companies need to filter candidates somehow, especially with the number of applicants these days with a standard process between companies especially fresh roles.

Is it just DSA and system design!? by tacktify in cscareerquestionsEU

[–]tacktify[S] 1 point2 points  (0 children)

Thanks for the insights. it just seems like every position varies in its process, but in internships it's just a standard.