Page 1 of 1

real.de OBB program silently patches.

Posted: Thu Apr 18, 2019 8:10 am
by rootpentesting
Hey Team,

I was participating in the OBB program of https://www.openbugbounty.org/bugbounty/itsecop/
i found XSS in their main domain real.de Underneath here is the timeline of the submission.

Vulnerability Reported: 4 April, 2019 23:39 GMT
Vulnerability Verified: 4 April, 2019 23:55 GMT
Website Operator Notified via Bug Bounty: 4 April, 2019 23:55 GMT

They never reached out to me, so i got some of their direct contacts send them an email about it and.
Today on 18-4-2019 i checked again and my vuln was silently patched, now this is not good behaviour for a OBB program.
and brings us researchers down in motivation.

Their policy clearly states : Possible Awards:

- PayPal donation
- voucher
- good rating

So i would like to receive this. As i did my work :roll:

Re: real.de OBB program silently patches.

Posted: Thu Apr 18, 2019 8:45 am
by Geek_Pwn
Same here.
I reported a XSS some months ago and it's silently fixed now.

Re: real.de OBB program silently patches.

Posted: Thu Apr 18, 2019 8:57 am
by rootpentesting
That sucks man it appears we both get ripped.

Re: real.de OBB program silently patches.

Posted: Thu Apr 18, 2019 9:04 am
by x1admin
We can't guarantee bounty from website owners but you can rate any program

Re: real.de OBB program silently patches.

Posted: Thu Apr 18, 2019 9:07 am
by Geek_Pwn
Sadly yes.

Re: real.de OBB program silently patches.

Posted: Thu Apr 18, 2019 9:25 am
by secuninja
x1admin wrote:
Thu Apr 18, 2019 9:04 am
We can't guarantee bounty from website owners but you can rate any program
but you could change the rules for program owners and make a response to the researcher the minimum requirement for participation on OBB.

I agree that you cannot guarantee a bounty but a reply is in my eyes the very least.