Reporting to the NASA Vulnerability Disclosure Program on Bugcrowd is an incredibly rewarding experience. The security team is highly professional, and they genuinely value the efforts of the community in keeping their massive infrastructure secure. Receiving Hall of Fame recognition and a Letter of Appreciation from NASA is a fantastic milestone for any security researcher. When tackling a scope as vast as NASA's, you don't need to rely on noisy automated scanners. My biggest piece of advice for this program is to master Google Dorking. Advanced dorking is arguably the most powerful technique you can use here. It allows you to sift through the noise, map out forgotten assets, and identify edge cases or misconfigurations that standard tooling completely misses. If you take the time to refine your search parameters and manually investigate the architecture, you can uncover high-impact issues. I would highly recommend this program to anyone looking to make a meaningful impact and test their manual recon skills!
Researcher profile
Not enough independently verifiable evidence yet. This is not a low score, it is no score.
What you’ve added here: reviews written, and how useful others found them.
How this BugScore is built
BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. You’re Unrated because nothing costly-to-fake is linked yet. Not a low score, just nothing to grade. Private and pseudonymous work counts: link a platform, claim a credit, or submit evidence.
How this Contribution is built
Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.
Programs reviewed
2Reviews
Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status took some proactive follow-up. While their initial response times can feel sluggish compared to standard bug bounty platforms, the Apple Security Team was professional once communication opened up regarding the remediation and potential bounty rewards. The highlight was working through the remediation phase and actively verifying the fix once they patched the flaw. For other researchers targeting Apple: rely heavily on manual testing and business logic over automated scanners, document your reproduction steps flawlessly, and don't be afraid to politely ping them for updates while you wait.