How To Start Bug Bounties (2021)
ozguralp.medium.com
ozguralp.medium.com
It also feeds into things. I'll feel like I'm so close to a discovery, and ask ChatGPT if I found sensitive data, or a vulnerability, and it always says "yes", but 90% of the time, it's not. I end up Googling away to find out what I really have.
I would never use ChatGPT for a report, or trust it with this sort of thing. You could probably ask it if editing HTML with dev tools is a security vulnerability, and it will probably say "Yes, you should immediately report that. Would you like me to draft the report for you?"
It's good for writing some short scripts, though. Just don't let it know it's for a "bug bounty". Can't believe people are just blindly trusting it.
> data policies can prevent pentesters from using it in their engagements.
I recently watched a Jason Haddix talk[0] where he mentioned that companies like Cloudflare are watching what pentesters do, so that they can better train their AI against such attacks.
Step 2: Mark all bug reports as "Works as intended"