{"id":563,"date":"2022-05-24T12:04:25","date_gmt":"2022-05-24T12:04:25","guid":{"rendered":"https:\/\/devbrain.com.br\/?p=563"},"modified":"2022-05-24T12:04:25","modified_gmt":"2022-05-24T12:04:25","slug":"impact-awareness-bounty-submission","status":"publish","type":"post","link":"https:\/\/devbrain.com.br\/index.php\/2022\/05\/24\/impact-awareness-bounty-submission\/","title":{"rendered":"Impact Awareness &#8211; bounty submission"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<p>Given the fact that your bounty report might change your finding from being &#8220;accepted&#8221; and even your reward over a particular program, it&#8217;s essential to provide enough information such as the impact and what\/how it can be accomplished (including combinations with different attacking vectors) with examples\/pocs. If possible, providing solutions to mitigate the problem can also be helpful as the person who&#8217;s reading your report might not have an advanced knowledge across the area you&#8217;re exploring. <\/p>\n\n\n\n<p>As an example, I&#8217;ll share one of my findings here that I was expecting a small bounty (e.g., USD ~100,00) for disclosing information due to a misconfiguration within the application I was assessing and it turned out that my focus on the report totally made the difference as it was even rewarded with an additional of $130 bonus (besides $477.20). Kindly refer to the following where I&#8217;m just obfuscating a few details due to a Synack&#8217;s private program:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Description<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"316\" src=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/desc-1024x316.png\" alt=\"\" class=\"wp-image-608\" srcset=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/desc-1024x316.png 1024w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/desc-300x93.png 300w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/desc-768x237.png 768w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/desc-1536x474.png 1536w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/desc-2048x631.png 2048w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/desc-600x185.png 600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Impact<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"754\" src=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/impact-1024x754.png\" alt=\"\" class=\"wp-image-611\" srcset=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/impact-1024x754.png 1024w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/impact-300x221.png 300w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/impact-768x566.png 768w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/impact-1536x1131.png 1536w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/impact-600x442.png 600w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/impact.png 1572w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">PoC<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"852\" src=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/validation-1024x852.png\" alt=\"\" class=\"wp-image-615\" srcset=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/validation-1024x852.png 1024w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/validation-300x250.png 300w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/validation-768x639.png 768w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/validation-600x499.png 600w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/validation.png 1534w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended Fix<\/h3>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"680\" data-id=\"618\" src=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix-1024x680.png\" alt=\"\" class=\"wp-image-618\" srcset=\"https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix-1024x680.png 1024w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix-300x199.png 300w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix-768x510.png 768w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix-1536x1020.png 1536w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix-600x398.png 600w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix-720x478.png 720w, https:\/\/devbrain.com.br\/wp-content\/uploads\/2022\/05\/fix.png 1542w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">References<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>Writing bug bounty reports:<ul><li>https:\/\/blog.yeswehack.com\/yeswerhackers\/tips-write-report-bug-bounty\/<\/li><li>https:\/\/dewcode.medium.com\/how-to-write-a-good-bug-bounty-report-in-just-10-minutes-980a0a1b1b18<\/li><\/ul><\/li><li>More about the finding above:<ul><li>https:\/\/medium.com\/@logicbomb_1\/bugbounty-nasa-internal-user-and-project-details-are-out-2f2e3580421b<\/li><\/ul><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Summary Given the fact that your bounty report might change your finding from being &#8220;accepted&#8221; and even your reward over&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-563","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/posts\/563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/comments?post=563"}],"version-history":[{"count":55,"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/posts\/563\/revisions"}],"predecessor-version":[{"id":623,"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/posts\/563\/revisions\/623"}],"wp:attachment":[{"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/media?parent=563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/categories?post=563"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devbrain.com.br\/index.php\/wp-json\/wp\/v2\/tags?post=563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}