Bug hunters will test anything, I don’t need to have any suspicion LOL? and like I said I tested multiple stuff and also found other vulnerabilities, calling it a “specific thing” when I clearly said it was that AND others
Anyway, I see you don’t want to reach any agreement here + ignoring what I said many many times, so my recommendation for you is to keep on shilling for the vibe coded app! Preferably ask the neptune app for some invitation codes after the promotion you’re doing for them
If you are looking to expand your portfolio and not do work for money, I’d say my previous advise on Responsible Disclosure + posting to a blog as your working resume is a great path forward.
If you are looking to help out products for privacy, my personal opinion is not to help closed source software. Put your efforts in FOSS which actually helps the privacy domain. The next TikTok killer eating our data isn’t anything I’d care about to begin with.
If you are looking for immediate money, don’t do other people homework. Go through Bug Bounty programs.
Create test account A
Upload video to test account A without being logged into A
You have now demonstrated the exploit on your own account
What you found was a vulnerability. This means their system is at risk because they didn’t lock the doors.
What you did was an exploit. You made use of the vulnerability against an account that was not your own.
I would consider your work grey hat at this point. I don’t think you are a villain, or a bad person, but leveraging a vulnerability on other accounts without explicit permission or being a part of the company is playing with fire. Its more-so for your sake moving forward to have better practices on the disclosure part.
I agree I should’ve probably asked for their permission? But seeing how they treated me I don’t think that was going to be any different either way. The bug was reported 10 minutes after I found it so it’s not like it caused any major damage, or any damage at all, which a person in this thread seems to be implying
In this case, I suspect you were probably frustrated with how dumb of vulnerability this is, and wanted to expedite it forward with a demonstration.
I get it, but remember its not your job or responsibility to force them to fix anything. You can lead a horse to the trough, but you can’t make them drink. That is not your fault, nor your responsibility. Given it was in Beta, I assume they are probably doing security as an afterthought after they have a working concept up and running. Regardless, I won’t be joining any TikTok killer, as I’ve already killed it by not installing it
My dude, you have no idea how any web application works by the fact you thought I can tell if something is a vulnerability or not without even requesting that endpoint, that’s simply not how the internet works.
This might help.
I was more arguing with the fact that you’re deliberately ignoring my points
@lyricism + @Freminet : at this point it is well established how to do it better next time. If you both want to duke it out, go to your the DMs to work it out, or start acting in better faith. Otherwise its time to request a lock to this thread.
Nice flowchart, but that’s not how the real world of security research works. If every researcher followed that to the letter, half the apps you use would have been drained of your personal data months ago.
Here is a reality check on how bug hunting actually works for independent researchers:
Observation vs. Pentesting: I didn’t set out to “pentest” them for 10 hours. I noticed a massive red flag in their API in the first 5 minutes of using the app. In the security world, if you see a door with a broken lock, you don’t just walk away and wait for a burglar to find it, you tell the owner(which is what I did).
Implicit Permission: I went to their Discord and a developer literally told me to “report it right here.” That is an invitation to provide a Proof of Concept (PoC). You can’t ask for a report and then cry “no permission” when the report shows you how broken your code is.
The “Gray Hat” Reality: Most startups are too small or too disorganized to have a formal Bug Bounty program (like HackerOne). Responsible disclosure means finding a flaw and giving the company a chance to fix it before a malicious actor finds it. I chose to report it privately instead of selling the exploit or dumping their user database.
The Goal is Security: I’m not the threat here, the code that allows anyone to upload a video to any account is the threat. Treating me like a criminal for showing you a hole in your fence is a “Newbie Startup” mistake.
I’ll also reiterate this is a privacy guides forum, not a pentesting security forum. This thread isn’t about privacy violations, its about a pentester who got booted from a beta program, which has already been thoroughly discussed. In reality, unless “Neptune App” was on the fence for being recommended, I don’t think there is much more meaningful discussion to have here. If there are questions about how to disclose properly, OWASP is likely a better starting ground than here.
I’m not the one acting like this is a pentesting forum here, @lyricism is(who expects me to magically know if an endpoint is vulnerable or not without requesting it), my main point was to warn people about an app that’s charging $8 per invitation code to get access to an app that has no security, I also wanted to show that they will actively silence anyone who finds a vulnerability after reporting it
I’d prefer leave this unlisted since it really deviated from the main point here