kudos to @intigriti for stepping in and raising this to the company, which finally re-reviewed the issue and rewarded the remaining bounty aligned with Medium severity, as I initially reported.
@intigriti I already did, but also support team is not being much helpful with automated responses.
I'm just hoping that Intigriti's triage team gets back to what it used to be, it was amazing the triage times in the past, but now it's become the slowest one in the space...๐
Few weeks ago, I found a High severity #IDOR vulnerability on @Bugcrowd platform that led to ATO!
Once again, developers messed up by returning the session access token of the victim, allowing me to gain full access to the user's account.
#BugBounty#Hacking
@JoaoGomes12243@Hacker0x01 Seems they're speeding up as they used to take very long time for the first triage. Looking forward to seeing more improvements coming up!
I keep progressing on @Hacker0x01
bug bounty platform as this weekend I reported 3 valid cross-tenant IDOR #vulnerabilities (1 High, 2 Medium).
Less than 4 days and I got them all triaged - quite surprised but glad to see such speedy work of H1 triage team!
Digging through #JavaScript source code often reveals juicy endpoints not (intentionally?) exposed in the UI. Theyโre often highly vulnerable, specially when those are developed for internal use or potentially 'trusted' users. Cheers to the developers!๐ค
I've officially entered the overall Top 100 (currently ranked #98) on the @intigriti Bug Bounty platform โ 120+ valid vulnerabilities, and Top 1 in 3 private programs!
Looking forward to growing further & climbing even higher in the rankings.
#BugBounty#Intigriti#hacking
Sweet High vulnerability on @Bugcrowd , breaking personal record!
IDOR allowed low-priv. user to change payment configurations of other companies ๐ค
#bugcrowd#hacking#bugbounty
Reporting is the hardest and most boring part of #BugBounty, but sometimes it's just worth it when companies appreciate good quality reports - kind bonus received on @intigriti platform!
#hacking#pentesting
@intigriti Thank you Intigriti - specially the entire triage team! You all provide the best experience for researchers.
Keep it up! Looking forward to more gifts coming from Bug Bounty and a successful 2025 ๐
Kudos to @intigriti's triage team - you guys make our research experience amazing with your speedy response times.
Always happy to help triaggers by making easy-to-follow reports ;)
#bugbounty#intigriti