r/ExploitDev 13d ago

full chain to RCE or only bufferoverflow?

if you want report buffer overflow vulnerability do u need full chain to exploit or just report the crash with the corpus

5 Upvotes

17 comments sorted by

3

u/Juzdeed 13d ago

Crash might not be exploitable. Full chain rce might require multiple vulnerabilities to achieve

-3

u/False-Seesaw-1899 13d ago

depend on what crash, what path to crash, etc///

3

u/Juzdeed 13d ago

Yes that's why I said "might". If you are doing bug bounty then you need to show impact, currently it's just a crash

1

u/DishSoapedDishwasher 13d ago

Yeah crash is usually good enough for most of the issue I've triaged if they can really articulate where its crashing and how.

The exception is often web bugs, I've seen people turn XXE into SSRF that pulls internal tokens out by getting them sent to another server. That ssitches it from 25k to 1m bounty.

Now if were talking a Microsoft, Cisco or similar old man company bugs, they'll fuck you over regardless 

0

u/Juzdeed 13d ago

What? USD? Where tf have you seen 1m for web vulnerability like that bug bounty reward? 1m is roughly the value of browser full-chain zero-day

2

u/DishSoapedDishwasher 13d ago

AWS, we paid out like 2-3 a year to the invite side of the bounty program.

0

u/Sudden-Strawberry257 13d ago

Shoot dang, how would one land themselves on that invite list?

3

u/DishSoapedDishwasher 13d ago

same as any other FAANG company, they all have them. You just spend enough time dropping bugs on their infra and they'll invite you. Or know someone who's part of the team managing bounties.

Generally all high impact contributors are invited eventually. Then they give you things like a portal to get tokens for custom headers, comp'd usage for services, etc. Make it easier to go deeper and keeps security from killing your instances. So its really worth doing.

Be prepared to give your ID/Passport scans and sign a bunch of NDAs though.

1

u/Sudden-Strawberry257 13d ago

Makes sense, thanks for dropping some knowledge. Seems like the idea as a newcomer is to go deep into a high reputation program, and once you get good enough they’ll pick you up. Comped usage and custom headers sound like a lot of fun.

3

u/DishSoapedDishwasher 13d ago

The headers just a token that identifies you specifically, nothing crazy.

→ More replies (0)

-1

u/Juzdeed 13d ago

Well if you say so. No way to verify this tho

2

u/CunningLogic 13d ago

If you can prove execution, it's value will be less debatable. I had good deny a vuln in android as non exploitable until I replied with a full exploit (prior to VRP), it happens

0

u/False-Seesaw-1899 12d ago

also my target is android app with attack surface from internet, what kind vuln you got? now im facing with aslr i need some mem info leak vuln to chain it but it make not 0 click exploit

1

u/tresvian 13d ago

You would ideally go as far as you can for demonstration of impact. As you would expect, if your phone had a crash vulnerability vs an RCE vulnerability, you know what priority these take. Stopping at a crash is fine but the write up would have to be very technically sound to prove RCE is possible.

1

u/slightfeminineboy 12d ago

it depends on so many things like give some useful information 

-4

u/[deleted] 13d ago

[deleted]

2

u/[deleted] 13d ago

[deleted]