Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,704,661 coordinated disclosures
1,383,263 fixed vulnerabilities
1,991 bug bounty programs, 3,919 websites
47,026 researchers, 1,651 honor badges

My Profile | puchaty

Recommendations and Acknowledgements | Full List:

@lgmorand     16 January, 2023
    Twitter lgmorand LG M from can't tell:
Krystian alerted me to an .git exposition vulnerability on my small non-profit website, which I was then able to quickly remedy. Very grateful for this!

Thanks Krystian !
@mailslate     21 November, 2022
    Twitter mailslate Paul Hopkins from Cheshire Moth Charts:
Krystian alerted me to an OWASP high risk vulnerability on my small non-profit website, which I was then able to quickly remedy. Very grateful for this!
@sindreij     21 October, 2022
    Twitter sindreij Sindre from Iterate:
Thank you for reporting a issue with our website in a thoroughly and professionally way!
@popperz0r     14 April, 2023
    Twitter popperz0r Tiago Silva from CM:
Thank you for your report on our website!
@coder5r3     8 April, 2023
    Twitter coder5r3 Pablo from CDC:
Krystian professionally reported an error that he found within our system, we thank him very much for his help and his ethics
@vonandraste     6 April, 2023
    Twitter vonandraste Nicci from Private:
Thank you for taking the time to highlight to me a common vulnerability left open on my small site. Much appreciated that you took the time to let me know.
@AKudashkin     7 March, 2023
    Twitter AKudashkin Alex from Trendigo:
Many thanks to Krystian for an alert on website misconfiguration, appreciate the transparency, detailed instructions on mitigation and general attitude to help.
@madanus     9 February, 2023
    Twitter madanus Madan U S from Confidential:
Krystian, thank you for reporting the OWASP vulnerability on our client's website. Appreciate the discretion. Thanks a ton.
@MartCous     21 December, 2022
    Twitter MartCous Martin Cousineau :
Thanks a lot for reaching out and letting me know of the vulnerability on my website. You are a good person!
@saucylondon     9 December, 2022
    Twitter saucylondon Harry from Saucy:
Thank you very much for your report. Much appreciated!
@DesiZoneRadio     7 December, 2022
    Twitter DesiZoneRadio FaF from DesiZone Network:
Thank you for your report on our website!
@FoenBox     5 December, 2022
    Twitter FoenBox Foen Box from Dinner Time Podcast:
Thanks for the heads-up about the misconfiguration! You reported it professionally and discreetly. :)
@rensi_arteaga     25 November, 2022
    Twitter rensi_arteaga Rensi from Kplian:
Gracias por encontrar el bug y reportarlo
@Kwalitiv     7 November, 2022
    Twitter Kwalitiv Joep from Kwalitiv:
Thank you so much for extensively reporting the issues with some of our sites!
@willysr2804     6 November, 2022
    Twitter willysr2804 WillySR from KNASTIK:
Thank you for reporting such misconfiguration to us!!!
@najcrnjidjordje     4 November, 2022
    Twitter najcrnjidjordje Djordje Dokic :
Thanks for detecting a vulnerability and reporting it to us.
@ArnaldoBorsa     2 November, 2022
    Twitter ArnaldoBorsa Arnaldo Borsa from Accomazzi.net:
Thank you for your report!
@tomekjarosik     29 October, 2022
    Twitter tomekjarosik tomekjarosik from tomasz.jarosik.online:
Thank you for reporting a vulnerability on my website very professionally and securely.
@OkujavaShota     28 October, 2022
    Twitter OkujavaShota Shota from isento:
Thank you for the hint!
@fakofbiciz     27 October, 2022
    Twitter fakofbiciz Aleksandar from Saniva:
Thanks for detecting a vulnerability and reporting it to us, such a man!
@OskarParad     21 October, 2022
    Twitter OskarParad Oskar from Gophery:
Thanks for your recommendation ;)
@antoniorosado     18 October, 2022
    Twitter antoniorosado Antonio from Waveweb:
Thanks for your recommendation on a vulnerability and reporting it to us :)
@karimj     11 October, 2022
    Twitter karimj Karim from Happylab:
Thanks for detecting a vulnerability and reporting it to us!
@S1awek1     27 September, 2022
    Twitter S1awek1 Slawek from wellmade.online:
Krystian found a bug on my e-store website. Thanks Krystian :)

Please login via Twitter to add a recommendation

Honor Badges


Number of Secured Websites

10+ Secured Websites Badge
50+ Secured Websites Badge
500+ Secured Websites Badge
Web Security Veteran Badge
10+ Websites
50+ Websites
500+ Websites
WEB SECURITY VETERAN
1000+ Websites

Advanced Security Research

WAF Bypasser Badge
CSRF Master Badge
AppSec Logic Master Badge
Fastest Fix Badge
WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB Badge
OBB Advocate Badge
Improved OBB Badge
Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master Badge
Patch Guru Badge
Patch Lord Badge
Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

REPUTABLE Badge
FAMOUS Badge
GLOBALLY TRUSTED Badge
REPUTABLE
10+ Recommends
FAMOUS
25+ Recommends
GLOBALLY TRUSTED
50+ Recommends

Distinguished Blog Author

Distinguished Blog Author Badge
Distinguished Blog Author Badge
Distinguished Blog Author Badge
1 Post
3 Posts
5+ Posts

Research Statistics



Total reports:3
Total patched vulnerabilities:1
Recommendations received:24
Active since:16.10.2022

Reported Vulnerabilities

All Submissions




No posts in blog yet










  Latest Patched

 25.04.2024 seeu.edu.mk
 25.04.2024 xaxim.sc.gov.br
 25.04.2024 lacerdopolis.sc.gov.br
 24.04.2024 tap.mk.gov.lv
 23.04.2024 data.aad.gov.au
 23.04.2024 bitporno.to
 23.04.2024 sys01.lib.hkbu.edu.hk
 23.04.2024 srvm.gov.za
 22.04.2024 stc.edu.hk
 22.04.2024 friv5online.com

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    22 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!
    10 April, 2024
    Mars:
Hatim uncovered a XSS bug that we were able to quickly resolve. Thanks very much for your assistance and help.
    8 April, 2024
    Panthermedia:
Thanks to the support of Hatim Chabik, we were able to identify and solve an XSS bug.
    5 April, 2024
    pubpharm:
Pooja found a XSS vulnerability on our website and provided us with the needed Information for replication and fixing the issue. Which she verified afterwards.
We thank her for the reporting and assistance.
    2 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!