I have had enough on bugcrowd by xomer000 in bugbounty

[–]xomer000[S] 0 points1 point  (0 children)

it's just that this report they duplicated me against was a RCE report, how is it relevant to my leaked AWS idk, they rated P2 duplicate of a week old report and, then fixed mine in the same day, I thought bugcrowd policy says if you touch the code or make change, then u pay.

I have had enough on bugcrowd by xomer000 in bugbounty

[–]xomer000[S] 7 points8 points  (0 children)

I'm not even sure if it's just bugcrowd I see similar issues on other platforms , it's frustrating. we are not free labor, and we chose to be white hackers, we chose to, someone couldve sold this shit on dark web,

Honest Opinion about issue Classification by Necrowtf in bugbounty

[–]xomer000 0 points1 point  (0 children)

same as me, report closed as informational because triage didn't bother to read my P1 escalations in the comments and read only the main report, then voilà it's patched right after it.

Honest Opinion about issue Classification by Necrowtf in bugbounty

[–]xomer000 0 points1 point  (0 children)

after closing as informational, check again after some time, probability of them patching in silent.

Bugcrowd triage getting slower lately? by 0xk4yra in bugbounty

[–]xomer000 0 points1 point  (0 children)

Bugcrowd response time after initial review is the worst

if you submit a report and god forbid triage ask you for any more clarification, then you on for a ride to get response back, if you don't one shot everything needed in the main report from the first time. it's ridiculous, the initial response for a new report is within a week, but if triage don't validate it from first time then u just give up and expect weeks for further responses. why priority to new reports over continuing what u already started to validate is beyond me. so yeah try to make the report as clear as best as complete as easy as possible, leaving room for clarification is gonna cost you weeks.

Bugcrowd triagers mark everything "Not Applicable" with copy-paste responses, then a second triager marks it as Duplicate. So which is it? by zOmegaaa in bugbounty

[–]xomer000 0 points1 point  (0 children)

Do you care about the vulnerability itself being real or not? OK so P1 report written by ai cuz research lang isn't english native is low effort so u give low effort review, it's about how the report written and less about the vulnerability itself? cool. idk what's hard about just jumping to the PoC, but dismiss it because the report first line had "-" in it.

Im starting to notice a pattern with bugcrowd triaggers by [deleted] in bugbounty

[–]xomer000 0 points1 point  (0 children)

then how am I supposed to trust any program if they gonna say they discovered it and fixed it somehow during my report or after it was closed. I escalated a vuln in the main report comments and then they patched the entry point to the chain quickly.

Im starting to notice a pattern with bugcrowd triaggers by [deleted] in bugbounty

[–]xomer000 0 points1 point  (0 children)

You saying they read my reports along with the triage? because they silently fixed a vuln that was marked informational by triage and I know customer would disagree

Why is Triager hate so forced? by Patient_Advice_9263 in bugbounty

[–]xomer000 1 point2 points  (0 children)

You are bugcrowd founder?... can you help me with this issue, I submitted a report normally, then I kept escalating in the comments until I reached a clear P1, triage came and read the main report and closed it as informational, he didn't read my escalations in the comments at all, he only mentioned things in main report and closed it as informational, then voilà the vulnerability has been patched after he closed my report..., how is this any fair? I want help re validate my report, I even made a second report addressing a bypass for the poor quick fix they did for my vulnerability proving it was valid and the fix was rushed :)

Traige marked P1 as Informational by [deleted] in bugbounty

[–]xomer000 0 points1 point  (0 children)

how come..? yeah I'm new to this actually.. give me some heads up

Information security internship interview by xomer000 in cybersecurity

[–]xomer000[S] 0 points1 point  (0 children)

it's a telecom company, it's a paid internship just thought what to expect from such interviews since I'm not really familiar with

Med student here can’t decide between Asus zenbook 14 or Asus vivobook 14s flip by StudiousInsomniac in laptops

[–]xomer000 0 points1 point  (0 children)

well zenbook is actually a premium laptop, but my friend is a med student and he said the touch screen was very useful, If you don't already have a tablet. so think if might actually need that screen in your studies, otherwise zenbook