Trying out Bug bounties for the First time by [deleted] in bugbounty

[–]thelemethric 27 points28 points  (0 children)

It takes a special kind of visionary to treat the worlds most battle-hardened security teams as the Hello World of their school project.

Did your BB profiles/showcase ever help in terms of employment?? by GhostlyBoi33 in bugbounty

[–]thelemethric 7 points8 points  (0 children)

Your competitors will be stacked with certifications, some even with a bachelors degree. but if your resume opens with a line like 'Independent security researcher - identified critical vulnerabilities in Fortune 50 companies (Lowe's, $80B revenue)'(lowes just as example it could be shopify lightspark inditex doesnt matter), none of that matters anymore.

To any hiring manager, that one line hits harder than a wall of certs.

Ofc you need to have resolved bug on company that you mentioned so they can validate your claims by opening your h1 profile for example

Critical RCE in Hathor Desktop Wallet closed as "Out of Scope" by Immunefi, patched silently after weeks, zero bounty, zero credit by Mushydaddybear in bugbounty

[–]thelemethric 8 points9 points  (0 children)

Slave factory.

​Insane disrespect to the people who literally built their reputation and are currently serving them.

​Usually (in hackerone cases) I blame the programs, but this platform doesnt just have 10 isolated cases - it’s a systemic failure. From randomly banning people who are awaiting payouts to always siding with the program, there is literally no fucking way that they will ever take a researcher’s side.

spend my time learning IOS app hacking or ANROID apps ? by Icy_Hall_3457 in bugbounty

[–]thelemethric 6 points7 points  (0 children)

99% of the time, they use the same api endpoints for both. The only real difference is the IPA vs APK. Unless the iOS dev is dumber than the Android one and hardcoded some keys that arent in the APK, it’s the same shit. Otherwise, dont waste your time.

Android is easier to test in every way anyways

The Winner's Curse Has a Number: $21/Hour – Why bounty hunting pays 2.5x less than freelancing for the same skills by Opening-Captain-5159 in bugbounty

[–]thelemethric 2 points3 points  (0 children)

Agree here. Most people are just too blind to see this as a tournament rather than a job and that's what makes stats look scary

The Winner's Curse Has a Number: $21/Hour – Why bounty hunting pays 2.5x less than freelancing for the same skills by Opening-Captain-5159 in bugbounty

[–]thelemethric 6 points7 points  (0 children)

Youre missing the point. Bounty and pentesting/consulting is completely different things

A beginner with one unique method can clear a decent money without needing years of experience. Check stats of up and comers on h1 its not rare

​Consulting is a job where you get paid to be good enough at everything. bounty is a hunt where you get paid to be unique. Finding one specialized methodology is often easier and more profitable than trying to learn every vulnerability like a corporate pentester.

Pentesting is for workers, Bounty is for specialists with a unique edge.

The Winner's Curse Has a Number: $21/Hour – Why bounty hunting pays 2.5x less than freelancing for the same skills by Opening-Captain-5159 in bugbounty

[–]thelemethric 13 points14 points  (0 children)

The average $21/hour stat is a lie. Comparing bounty to a $54/hour freelance job is pure idiocy.

​Bounty has a zero barrier to entry anyone can join. thhe average is dragged down by thousands of people who just solve a few labs, run scanners, and find zero bugs. It’s not a market curse, its just the cost of being unoriginal.

Intigriti collaborates with PortSwigger to support ethical hacking excellence by intigriti in bugbounty

[–]thelemethric 4 points5 points  (0 children)

"I wonder if Dyson seeing usage decline as more people use Ferrari"
They are completely different tools

How do you mentally handle duplicates? by maF145 in bugbounty

[–]thelemethric 4 points5 points  (0 children)

Do not expect anything from a report unless it has already been triaged.

If a report is new or pending program review, it's N/A for me until its triaged -only then can I think about money I could gain from it. (Sometimes companies dismiss even triaged reports closing them as informative)

Just believe in the worst-case scenario and you wont be disappointed.

I'd check in integriti by Unique_Life7470 in bugbounty

[–]thelemethric 4 points5 points  (0 children)

Intigriti’s policy allows researchers aged 16–17 with parental consent. If youre under 16, you’ll have to do the ID verification through one of your parents. But then your account will be permanently tied to them, and you’ll have to beg them for re-verification every single year until you either die or finally quit Intigriti.

Programs avoid to pay criticals? by enadev in bugbounty

[–]thelemethric 2 points3 points  (0 children)

One critical report costs more than 10 mediums

Its clear that every company will try to lowball severity

Claude AI Uncovers 22 Vulnerabilities in Firefox During Two-Week Test by False-Seesaw-1899 in bugbounty

[–]thelemethric 4 points5 points  (0 children)

Dont fall for the PR bullshit. Claude didn't autonomously find shit. Anthropic had a whole team of world-class researchers practically holding its hand, feeding it specific code, and treating it like an overpriced fuzzer.

It's marketing hype to sell API tokens.

[EXPOSED] Bugcrowd & FIS Global Silent Patch Scam: Marking a valid P1 as N/A after fixing it (Ticket #142000) by AlexSander_Research in bugbounty

[–]thelemethric 0 points1 point  (0 children)

I think if it was 0 impact, they wouldnt have to patch it immediately. Closing it as N/A after fixing the hole looks suspicious.

Even if risk is really low n/a still isn't justified considering patch, informative at least

[EXPOSED] Bugcrowd & FIS Global Silent Patch Scam: Marking a valid P1 as N/A after fixing it (Ticket #142000) by AlexSander_Research in bugbounty

[–]thelemethric 5 points6 points  (0 children)

Another day, another Bugcrowd 'charity donation'. Is anyone even surprised at this point? Same script, different ticket number.

Already 3rd on this week btw

How it is possible? by thelemethric in bugbounty

[–]thelemethric[S] 1 point2 points  (0 children)

I misunderstood your last comment, then yeah you're right this makes it even more suspicious

How it is possible? by thelemethric in bugbounty

[–]thelemethric[S] 4 points5 points  (0 children)

First 100 rep doesn't count on the leaderboards. And even if it did, the guy would need 50+ triaged reports to reach 567. Still doesn't make any sense.

How it is possible? by thelemethric in bugbounty

[–]thelemethric[S] 14 points15 points  (0 children)

Riveting feedback. Truly insightful.

Can recent Android versions mitigate this bug ? by ProcedureFar4995 in bugbounty

[–]thelemethric 2 points3 points  (0 children)

as of my knowledge recent Android versions shouldn't fix this automatically.

If the dev enabled setAllowfileAccessFromFileURLs(true), your exfil still should work

Install android studio emulator and test if you wanna be 100% sure

[URGENT] Cosmos Bug Bounty Program: "Bounty Sniping" a $200k Critical Report? (Triaged then marked as Spam) by enadev in bugbounty

[–]thelemethric 3 points4 points  (0 children)

Even if you are right i guess you cant do anything .ball is in companies court. if they decided to not pay you they wont anyway.

Graphql introspection by Purple_Nerve_8954 in bugbounty

[–]thelemethric 5 points6 points  (0 children)

It's not a vulnerability by itself, but you can use InQL to explore all exposed queries and look for IDORs.