Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,704,659 coordinated disclosures
1,383,224 fixed vulnerabilities
1,991 bug bounty programs, 3,919 websites
46,998 researchers, 1,651 honor badges

Random_RobbieTop-50 VIP Open Redirect Reporter Top Security Researcher of the Month Top VIP Security Researcher of the Month | Security Researcher Profile


Security researcher Random_Robbie has already helped fix 4187 vulnerabilities.



Researcher reputation:  520

Real name:
Robbie

About me:
Feel free to contact me for information regarding what i have found.

I DO NOT expect anything from you despite the sites name it's just an easy way to report issues i've found.

I will try answer as quick as i can.

I am UK based.

I do mass scanning without causing issues to your website.

If you are using typo3 it is a flash based XSS if this does not matter to you then please ignore the warning.

Contact email:
[email protected] - for fast response email a link to the OBB submission.
Twitter - @random_robbie
https://hackerone.com/txt3rob
https://bugcrowd.com/txt3rob
Love Private BB programs!

Experience in Application Security
1-3 years

Award / Bug Bounty I prefer:
This is only if you WANT to reward me.

Amazon UK vouchers
Paypal
Swag
Toys for the kids - https://goo.gl/ooUJ6A (amazon wish list)

Halls of Fame:
Dell
Cert EU
Century Link
Auto Trader
AOL
Apple

Follow me on:
Twitter

Ethics and Rules:
Robbie is required to abide by the ethics and rules of the Open Bug Bounty project. If you reasonably believe that rules are not respected, please report this to us.

Recommendations and Acknowledgements | Full List:

@wirismath     14 May, 2019
    Twitter wirismath Sonia Gago from WIRIS MATH:
We want to thank you for your vulnerabity report, Random_Robbie! Thanks to your information and collaboration, we could fix a security issue in one of our websites. Thanks again, and great job!
@wirismath     14 May, 2019
    Twitter wirismath Sonia Gago from WIRIS MATH:
We want to thank you for your vulnerabity report, Random_Robbie! Thanks to your information and collaboration, we could fix a security issue in one of our websites. Thanks again, and great job!
@protopigeon     22 October, 2018
    Twitter protopigeon Franz from gooii:
Thanks to Robbie for bringing a security issue to our attention and being very responsive over email.
@euvtechnology     16 October, 2018
    Twitter euvtechnology euvtechnology from Engel & Völkers Technology:
Dear Robbie, Thank you for reporting the XSS vulnerability you discovered on our website and helping us ensuring the security of our webservices.
@uaharoni     5 August, 2018
    Twitter uaharoni uaharoni from WeFix:
Thank you Robbie for raising our attention to the storage permission issues we had.
@uaharoni     5 August, 2018
    Twitter uaharoni uaharoni from WeFix:
Thank you Robbie for raising our attention to the storage permission issues we had.
@Intrepidd     6 July, 2018
    Twitter Intrepidd Adrien from Drivy:
Thanks a lot to Robbie for sharing an issue with us. Very professional researcher.
@SandiSchleicher     5 July, 2018
    Twitter SandiSchleicher SSchleicher from iGive:
Thanks for pointing out the XSS issue. It has been fixed and we appreciate your help!
@eulenberger     24 May, 2018
    Twitter eulenberger Sven from netclusive GmbH:
Thanks for improving the internet!
@kentreez     23 February, 2018
    Twitter kentreez Kasidiss from Lnw:
Thank you Robbie for identifying a XSS-Vulnerability on our website. I'm really thankful for your work.
@IT_Wolve     19 February, 2018
    Twitter IT_Wolve Markus from Pepperl+Fuchs GmbH:
Thank you Robbie for reporting and helping us finding these XSS issues on our website. We fixed it.
@RSwartzer     5 February, 2018
    Twitter RSwartzer Ron Swartzendruber from Western Oregon University:
Professional and helpful; very quick response time.
@FreedomDevs     6 December, 2017
    Twitter FreedomDevs FreedomDevs from Freedom!:
Thanks for bringing the XSS and another security issue to our attention, your help is greatly appreciated!
@UKClimbing     15 November, 2017
    Twitter UKClimbing Paul Phillips from UKClimbing:
Thanks for sharing this issue, all fixed.
@tits4net     29 September, 2017
    Twitter tits4net TiTs from PETZI:
Hey ! Thanks for sharing this issue !
@sirjackery     26 September, 2017
    Twitter sirjackery John Roehrig from TurnItIn:
Kudos for discovering an XSS in a third-party CMS that we use. You helped secure many web properties.
@_devalias     13 September, 2017
    Twitter _devalias Glenn / devalias from N/A:
Just wanted to throw a quick thanks to Robbie for his work pointing out some XSS issues recently. The first one was no longer present, but he followed up with a new one on another subdomain. Appreciate your contribution to making the internet a safer place! :3
@garethholt     18 August, 2017
    Twitter garethholt Gareth Holt from London & Partners:
Thanks to Robbie for spotting a couple of XSS vulnerabilities on visitlondon.com - much appreciated.
@darkera13     17 August, 2017
    Twitter darkera13 Long Tran from HOCMAI:
Thank Robbie for reporting us the vulnerability, we fixed it.
@ISOatUO     27 July, 2017
    Twitter ISOatUO Information Security Office from University of Otago:
Another valuable report from Robbie, he also went out of his way to make sure that incorrect details on OBB's website were corrected.
@supportdi31     17 July, 2017
    Twitter supportdi31 Patrick from Depeche Interactive:
Nice work on notifying XSS on our website, help greatly appreciated !!
@FontPalace     3 July, 2017
    Twitter FontPalace Support from FPalace:
Nice Work, thank you for identifying issue, we fixed it.
@Mehdi_AITHAMMOU     30 June, 2017
    Twitter Mehdi_AITHAMMOU Mehdi AIT HAMMOU from RATP Group:
Thanks Robbie for pointing out a cross-site scripting vulnerability on our website! Mehdi
@seblod     26 June, 2017
    Twitter seblod Sebastien from SEBLOD:
Hey Robbie!
Thank you for finding and sharing the issue with us. Cheers!
@BENsembl     15 June, 2017
    Twitter BENsembl Ben Moore from EBI:
Thanks for helping us with fixing ensembl.org, Robbie. Greatly appreciated.
@bsats     9 June, 2017
    Twitter bsats bsats from enotes:
Thank you Robbie! Appreciated by the whole team here!
@uliw     6 June, 2017
    Twitter uliw Uli from KIT:
Thanks Robbie for pointing out a cross-site scripting vulnerability on our website and offering the time to correct the issue before widely announcing it.
@Goodgamestudios     1 June, 2017
    Twitter Goodgamestudios Jens from Goodgame Studios:
Hey Robbie, Thanks a lot for finding and reporting the bug! Highly appreciated!
@TampereUniTech     1 June, 2017
    Twitter TampereUniTech TUT from Tampere University of Technology:
Thanks Robbie for noticing and reporting us the vulnerability!
@emuparadise     30 May, 2017
    Twitter emuparadise MasJ from EmuParadise:
Helped us spot and fix an XSS vulnerability. Quick response via twitter DMs too! Thanks!
@ubcaaronheck     11 May, 2017
    Twitter ubcaaronheck Aaron Heck from The University of British Columbia:
Thanks for notifying us of the bugs, Robbie, and for responding quickly to our query and testing our patch.
@RedlightsBe     6 May, 2017
    Twitter RedlightsBe Stijn from Redlights:
Thumbs up! Nice find and quick communications. Keep up the good work!
@bontemp     4 May, 2017
    Twitter bontemp Mark from CNPS:
Thanks for the alert, and for the extra help to identify the issue. Keep up the good work!
@hgschulz     3 May, 2017
    Twitter hgschulz Henning Schulzrinne from EDAS Conference Services:
Helpful and quick to respond. Thanks for helping us improve the site.
@itea97137491     3 May, 2017
    Twitter itea97137491 Vincent from n/a:
Thank you Robbie for finding a XSS issue on our website. Good work and very quick response. Thank you very much
@axelesha     25 April, 2017
    Twitter axelesha Aleksey from teenslang.su:
Thanks Robbie, very much appreciate your help!
@MarkDatter     19 April, 2017
    Twitter MarkDatter Jason C from Fluke Calibration:
Robbie found a legitimate XSS vulnerability on our website. I patched it and Robbie confirmed the fix. Thanks for your help!
@ashemaletube     6 April, 2017
    Twitter ashemaletube Vlad from aShemaleTube:
Thanks for reporting us the vulnerability. We were able to make a quick fix. Thanks Robbie.
@woodinblack     25 March, 2017
    Twitter woodinblack Woody Goldsack from ratwarehouse.com:
Thanks for letting us know about the issue on our page so I could get it fixed!
@cokoladasarizom     17 March, 2017
    Twitter cokoladasarizom Mirko Vucicevic from Hyperoptic Ltd:
Thank you Robbie for helping us keep our website secure.
@yepannet     22 January, 2017
    Twitter yepannet Mr. Jeoung from Yepannet:
Thanks for letting us know about security issues with the site.It was a great help . Thanks Robbie!!!
@MrPaulField     16 January, 2017
    Twitter MrPaulField Paul Field from n/a:
Robbie helped us identity some security issues with some of our sites, and provided info so we could fix.

Great help, and very thorough!
@aarmstrong7     10 January, 2017
    Twitter aarmstrong7 Adam from Company:
Provided a great PoC for a reported XSS issue and was easy to work with through the remediation process. Thanks and keep up the great work.
@Willie8Stargell     9 January, 2017
    Twitter Willie8Stargell Jeff Grove from DASH Platform:
Thank you Robbie for finding a security issue for us. We appreciate the information and quick response.
@albummaster     9 January, 2017
    Twitter albummaster albummaster from BestEverAlbums:
Thanks for identifying a possible issue with the site. Greatly appreciated.
@alive_web     9 January, 2017
    Twitter alive_web Tim from Alivenetwork.com:
Thanks for bringing this to our attention. We have taken the relevant steps to fix this issue. Your help is most appreciated! Thanks Robbie
@BerlinOnlineNet     2 January, 2017
    Twitter BerlinOnlineNet Andreas from BerlinOnline:
Thanks for letting us know about the issue on one of our hosts. We appritiate it and fixed the issue immediatly.

Please login via Twitter to add a recommendation

Honor Badges


Number of Secured Websites

10+ Secured Websites Badge
50+ Secured Websites Badge
500+ Secured Websites Badge
Web Security Veteran Badge
10+ Websites
50+ Websites
500+ Websites
WEB SECURITY VETERAN
1000+ Websites

Advanced Security Research

WAF Bypasser Badge
CSRF Master Badge
AppSec Logic Master Badge
Fastest Fix Badge
WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB Badge
OBB Advocate Badge
Improved OBB Badge
Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master Badge
Patch Guru Badge
Patch Lord Badge
Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

REPUTABLE Badge
FAMOUS Badge
GLOBALLY TRUSTED Badge
REPUTABLE
10+ Recommends
FAMOUS
25+ Recommends
GLOBALLY TRUSTED
50+ Recommends

Distinguished Blog Author

Distinguished Blog Author Badge
Distinguished Blog Author Badge
Distinguished Blog Author Badge
1 Post
3 Posts
5+ Posts

Research Statistics



Total reports:22165
Total reports on VIP sites:1106
Total patched vulnerabilities:4187
Recommendations received:47
Active since:15.12.2016
Top Security Researcher Awards:Gold Star Top Security Researcher of the Month Gold Star Top Security Researcher of the Month
Top VIP Security Researcher Awards: Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week

Open Bug Bounty Certificate


Researcher Certificate

Reported Vulnerabilities

All Submissions VIP SubmissionsFeatured Submissions




No posts in blog yet










  Latest Patched

 25.04.2024 xaxim.sc.gov.br
 25.04.2024 lacerdopolis.sc.gov.br
 24.04.2024 tap.mk.gov.lv
 23.04.2024 data.aad.gov.au
 23.04.2024 bitporno.to
 23.04.2024 sys01.lib.hkbu.edu.hk
 23.04.2024 srvm.gov.za
 22.04.2024 stc.edu.hk
 22.04.2024 friv5online.com
 20.04.2024 brandonfowler.me

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    22 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!
    10 April, 2024
    Mars:
Hatim uncovered a XSS bug that we were able to quickly resolve. Thanks very much for your assistance and help.
    8 April, 2024
    Panthermedia:
Thanks to the support of Hatim Chabik, we were able to identify and solve an XSS bug.
    5 April, 2024
    pubpharm:
Pooja found a XSS vulnerability on our website and provided us with the needed Information for replication and fixing the issue. Which she verified afterwards.
We thank her for the reporting and assistance.
    2 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!