Increase number of bugs by sending duplicate of your own valid report

Disclosed: 2016-04-25 04:43:10 By ashish_r_padelkar To security
Unknown
Vulnerability Details
HI, This report is a basically a design issue and something similar to report where someone can gain reputations by sending dup. Not very high severity bug and i know you all can always roll back the changes. also it lies more on team rather than a system. but it happened before with me (although bugs were different , team marked it dup for some reason) .so thought of reporting it The difference here is, you don't increase your reputation but you can increase your number of bugs! Steps 1. The obvious pre requisite here is, you have to send valid report to any team 2. Wait for it to get triaged. once it is triaged, it is almost certain that it will be resolved! 3.Send the same report again with little modification, may be by changing the title and description 4. Now most teams will mark this as duplicate of your own report! 5. But when the original report gets resolved, your reputation remains the same but number of bugs increases by 2(one for original and one for dup). if you keep on submitting such bugs multiple times, you can boost your number of bugs which may create false impression (which will look good to others as profiles are public) The obvious resolution would be , not to count dup report if its dup of your own report! Regards Ashish
Actions
View on HackerOne
Report Stats
  • Report ID: 116951
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report