Got a report closed as Duplicate on Intigriti and I'm not sure whether to keep pushing or let it go.
What I found: Tier 2 wildcard subdomain (service-XX.example-corp.com) pointed to a third-party VPS running a admin panel. Known auth bypass on an older version — got admin access, created an account, logged in normally. Screenshots and PoC sent. Deleted the test account when triage asked.
Why it was closed: Company told triage they were already aware, host isn't theirs, fixing DNS for service-*.example-corp.com. Marked Duplicate. No duplicate report ID given.
Timeline: Admin UI port (e.g. :18xxx) was open when I submitted — I have screenshots. Shortly after my report, that port got locked down. Second service port (e.g. :24xxx) on the same subdomain still responds. Can't hit the bypass live anymore, but there's still clear evidence on the box that the panel was there before.
What I've done: Appealed once with timeline and screenshots. Triage hasn't replied.
Where I'm stuck: Domain was in scope even if the server wasn't theirs. Hard to accept Duplicate with no reference to the original report. Timing makes it look like they shut the port after disclosure, not that it was already handled.
Questions:
Duplicate without report ID — normal on Intigriti?
Appealed, no reply — escalate or wait?
Anyone got paid on wildcard subdomain + "not our host"?
Move on?
Source: r/bugbounty · by /u/reconHunter-bugBouny