21/08/2025
๐๐ก๐ซ๐๐ ๐๐ข๐ฉ๐ฌ ๐๐จ๐ซ ๐๐ฎ๐ ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐๐๐ฉ๐จ๐ซ๐ญ๐ฌ ๐
If you struggle getting your bugbounty vulns accepted (quick reject/duplicate or N/A)
-> it might be that the triager doesn't want to deal with your report
๐๐ง ๐๐๐๐ญ ๐ญ๐ก๐๐ฒ ๐๐จ๐ง'๐ญ ๐ฐ๐๐ง๐ญ ๐ญ๐จ ๐๐๐๐ฅ ๐ฐ๐ข๐ญ๐ก ๐๐๐๐๐๐ ๐๐๐๐๐๐๐ ๐ซ๐๐ฉ๐จ๐ซ๐ญ๐ฌ
As a triager myself who did this job for 3+ years and reviewed over 2500 reports, here are 3 tips I have for everyone who plans to submit a report
-----
1. ๐
๐จ๐ซ๐ฆ๐๐ญ/๐๐๐๐ฎ๐ญ๐ข๐๐ฒ
โข If you report includes code snippets -> use indentation
โข If your report has JSON/XML snippets -> use a beautifying tool
โข Verbose HTTP headers? -> remove the irrelevant ones
2. ๐๐๐ง๐ฌ๐ข๐ญ๐ข๐ฏ๐ ๐๐๐ญ๐
โข Remove passwords/tokens/JWTs/API keys
โข If they are relevant-> obfuscate them
โข Last thing that you is to create one more security hole
3. ๐๐ข๐ ๐ก๐ฅ๐ข๐ ๐ก๐ญ ๐ญ๐ก๐ ๐๐ฌ๐ฌ๐ฎ๐
โข When you work onreport -> it's where the problem is
โข You submit a picture/video and you say "see the attached"
โข But for someone who just read -> is not where to look
โข Highlight with circles/squares/arrows what exactly you want to point out