For almost two years, I hunted bugs without a single acknowledgment.
Late nights, no triaged reports, no bounties — just learning, failing, and trying again.
I questioned myself many times, but I never quit.
I stopped chasing only paid bug bounty programs.
I switched to VDP/RDP programs to build my portfolio and gain confidence first.
That mindset shift was the real turning point.
During recon, I came across GEA Group’s VDP.
The scope wasn’t clearly defined, so I explored its subdomains myself.
My strategy: don’t aim for complex bugs — just find something valid and impactful.
Press enter or click to view image in full size
On one of their login pages, I noticed missing X-Frame-Options/CSP headers.
I tested it in an iframe → it loaded → pure clickjacking.
I documented PoC, screenshots, impact, and sent the report immediately.
Join Medium for free to get updates from this writer.
Less than a month later, I received the email.
The bug was fixed.
I was officially recognized in their Hall of Fame.
No money — but massive validation.
Press enter or click to view image in full size
You don’t fail in bug bounty unless you quit.