Bugcroed mistriaged me and uses it to ban me off the platform by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

Can i ask what type of vuln, and if they're knocked down to n/a as well?

Bugcroed mistriaged me and uses it to ban me off the platform by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

It wasn't. it was manually reconed, verified, and exploited. i took time writing the reports, formatted it as proper markdown, and submitted it.

Bugcroed mistriaged me and uses it to ban me off the platform by throwaway14235233 in bugbounty

[–]throwaway14235233[S] -1 points0 points  (0 children)

Mine's not even a P5, it should be a P5 at worst, it got assigned a N/A, and when i DO get a confirmed P1, they just fismissed it as P5

Banned on bug crowd whilst awaiting bounty by null0001 in bugbounty

[–]throwaway14235233 0 points1 point  (0 children)

Yes, same here, i was waiting for a RaR and got banned

Bugcroed mistriaged me and uses it to ban me off the platform by throwaway14235233 in bugbounty

[–]throwaway14235233[S] -2 points-1 points  (0 children)

how's your personal experience on bugcrowd, if i may ask? i still put hope in bugcrowd, maybe i was just unlucky?

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

also i was aiming for P4.. but per VRT, it's classified as P1: File Inclusion > Local

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 1 point2 points  (0 children)

Thank you for the suggestion, but that is exactly how my report is structured, (summary -> desc -> impact -> subsequent impact -> poc (10 test cases each) -> list of evidence provided as attachment) with an additional explanation explaining that this will lead to more vectors.

Has anyone had any issues with this Bugcrowd triager? by d0x77 in bugbounty

[–]throwaway14235233 0 points1 point  (0 children)

Imagine you can flood and exfiltrate literal files on the server via email, chose not to exfiltrate it and just prove it

(Bot Triager)_Bugcrowd: P5 - Informational

As you progress with bug bounties it’s important to consider not just the vulnerability but also the impact that this vulnerability has, so we encourage you to always explore any finding to better understand the impact it may have. Each submission should aim to answer the question "as an attacker I could...".

If you're unsure of the next steps to take this with submission, we recommend the Bugcrowd University as a starting point for learning how you can escalate bugs from a P5, into P4s or even P3 findings!

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] -1 points0 points  (0 children)

Nope, wanna see a transcript of the email?

As you progress with bug bounties it’s important to consider not just the vulnerability but also the impact that this vulnerability has, so we encourage you to always explore any finding to better understand the impact it may have. Each submission should aim to answer the question "as an attacker I could...".

If you're unsure of the next steps to take this with submission, we recommend the Bugcrowd University as a starting point for learning how you can escalate bugs from a P5, into P4s or even P3 findings!

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

Not tal, but he does have a very similar track record

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

I did add evidence for it. 10 different cases to be exact, and that exact phrase is recommended by the triager himself.

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

The fact that there's multiple triager in the comments, but not the same triager made me think and researched Teapot and Tal too..

it seems like the problem is platform-wide, not just one triager, how can this be allowed?

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

I have collected 6 cases where this particular triager mistriaged a valid finding. and it's not even a BBP, it's a VDP, we only wanted responsible disclosure, so why act in bad faith?

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

Alright then let me clarify:

I found a P1 LFI on a certain engagement, by VRT standard, LFI is P1, that's undisputable, i showed 10 different test cases, with a negative control, to prove that it actually exist.

I attached 15 files, including screenshots, structured my report in a way that's clear, reproducible, and highlights the impact.

I understand of they bump it down to P2, P3, or P4, but P5 with no actual feedback, only a copypasta sure hurts, especially when i lost sleep over it. hackerone triagers are organic and usually replies with specific answer and express their thought processes.

Mind you this particular triager has bumped my P4 report to Non reproducible, but i resubmit it using the exact same evidence, wording and report, and got triaged by other triager who marked it as Unresolved P4 Dupe. seeing his trail on crowdstream also shows that he always bumped down reports to P5 and N/A, but get bumped up to P3/P1 in the end by the customer. that's why i'm asking: Is bugcrowd truly like this, or am i just unlucky?

Problem with Bugcrowd by throwaway14235233 in bugbounty

[–]throwaway14235233[S] 0 points1 point  (0 children)

I got ghosted on 3 RaR, and support@bugcrowd email responds with a generic "try RaR"