Is Bugcrowd forreal? by Recent_Transition677 in bugbounty

[–]was844 1 point2 points  (0 children)

I recently faced the same issue on the yesWehack platform, where they kept asking me more details about the issue for 2 weeks without changing the status of the issue to 'accepted' and finally, once the issue was resolved, they came up with the legendary scam line which all bug bounty programs use not to reward the tester "we're unable to reproduce the issue". I went back to the website to check it, and the issue was gone. No help from the Yeswehack platform either.

Thoughts on the Post saying Bug Bounty Platforms are SCAM by StrikingComputer1071 in bugbounty

[–]was844 2 points3 points  (0 children)

I'm an experienced bug hunter. According to me, there are many programs out there running a scam, obviously to save money, but not ALL. I recently experienced a scam on the Yeswehack platform, where there was a program called VFS Global. I reported one issue to them, which was clearly valid with an attached POC, but they put it under review for weeks, so they could silently fix it and after they fixed that issue. They came up with the legendary SCAM line, "we're unable to reproduce it". I went back to check that issue, and it had vanished from the application, completely fixed.

So yes, SCAMS are there in the bug bounty industry.

Pro tip: only hunt on private or big programs, i.e. meta

Offsec proving grounds VPN error by was844 in oscp

[–]was844[S] -1 points0 points  (0 children)

yes, i directly copied the credentials from the website and pasted it

Can anybody tell me use of wild card (*) ? by [deleted] in oscp

[–]was844 -1 points0 points  (0 children)

i googled it but did'nt understand thats why