Self-Hosted Bug Bounty Programs: A Free Index

The programs that aren't on any platform

Hello fellow hackers ๐Ÿ‘‹

For about a year, my hunting looked like everyone else's. Open a bug bounty platform, pick something from the list, dig in, move on. The scopes were crowded and I knew it. The moment a good program opens, so does everybody else's terminal.

So I went looking somewhere quieter, and I started with dorks, a lot of tabs, and a lot of dead ends.

It worked, eventually. I found an organisation running its own disclosure process with nobody on it, sent a report, and it went well. ๐ŸŽฏ That was the moment this clicked, not the report, but what it implied about how many more there were.

๐Ÿ” What is a self-hosted program?

A program an organisation runs itself, on its own domain, with no platform in the middle. You've almost certainly walked past one:

https://www.target.com/vulnerability-disclosure
https://www.target.com/responsible-disclosure
https://www.target.com/security/report-a-vulnerability

An ordinary page on an ordinary site. It says what they want reported, where to send it, and, if you're lucky, whether they pay and whether they'll promise not to come after you for looking.

No dashboard, no signup, no queue position. Just a company saying here is where to reach us.

On a platform: everyone, one target. Off platform: thousands of targets, almost nobody

Most of them are on no platform at all. Not because they're secret, the pages are public and indexed, but because a regional bank or a city council is never going to pay a platform's annual fee. Same for universities, hospitals, government departments, and a long tail of companies that will never sign that contract.

It isn't hidden. It's just unlisted.

๐Ÿค” Can't you just dork for these?

Yes. You absolutely can, and you'll find good programs doing it. I maintain a dorks tool for exactly that and I still use it.

Search results for a disclosure-page dork: four disclosure pages on four different domains

The difference is what happens after the search. A dork gives you one page of results, for one query, on one day. What I've been doing instead is collecting all of those targets in one place, watching for new ones as they turn up, and keeping the whole set in a single list you can filter.

I've also folded in the programs I'd already gathered by hand over months of hunting this way, the ones that never surface in any single query.

And it isn't one technique doing the finding. Several run continuously across the public internet, and anything new lands in the same list. A policy that went up last week is a target almost nobody has opened yet. Being early to those is close to the only real edge available here.

Less "search and hope". More "here's everything so far, and here's what arrived this week."

๐ŸŽฏ Introducing Public-Programs

Public, free, no account, nothing to install:

โ†’ ashikkunjumon.com/Public-Programs

Thousands of programs, each with a contact that resolved when it was last checked. Most name no platform, and the index opens filtered to those; the rest are there too, tagged with the platform they run on, so you can include or exclude them.

The index, filtered to programs that state safe harbour

โš™๏ธ What you can filter

  • Reward: the ones that pay money, kept apart from swag and hall-of-fame credit. Very different propositions, and the table shouldn't blur them.
  • Safe harbour: who has actually written down that they won't come after you for good-faith research. The smallest slice by a long way.
  • Country: matters more than people expect. Disclosure law is national, and you want to be somewhere you understand.
  • Status: hide anything whose own stated expiry has already passed.

๐Ÿงฉ What actually gets checked

A list of domains ages badly. Contacts stop working, disclosure pages come down, expiry dates pass quietly. So the checking runs continuously, not once when I built it.

Anything provably gone is withheld rather than listed: a domain that no longer resolves, a page that returns a real 404. That's why this is shorter than a raw sweep would hand you.

What checking can't do is prove the opposite. "Not provably gone" is a much weaker claim than "real", and the space between those two is where the false positives live. A site that answers 200 for every path it doesn't recognise looks exactly like one serving a policy, right down to the status code. A domain can publish a flawless security.txt pointing at pages nobody ever wrote. Somebody can park a domain, drop a contact address on it, and get listed having done nothing else.

I go looking for these and pull them when I find them, and I'd rather say they're in there than let you assume the list is clean. Treat an entry as a lead worth opening, not a destination someone has already vouched for.

The disclosure page behind each entry gets read too (the only way to know whether safe harbour language is in it), and anything new gets flagged.

โš ๏ธ A few issues worth knowing

Sent the report. Six weeks later: no reply, no read receipt, no bounce

I'd rather say all of this plainly than have you find out on your own.

  • Read the policy before you test anything. Scope, what's out of bounds, how they want the report. It's all in there, and it's the difference between a report that's welcome and one that isn't.
  • Check the policy yourself, from the link in the list. Confirm it still loads and still says what you expect. No tool is perfect, this one included. A page can change the day after it was last checked.
  • A contact that resolves isn't a contact that's read. A check from outside can prove an address is gone. It can't prove anyone is at the other end.
  • Some pages answer 200 and still aren't real. A soft 404 wears a real page's clothes, and from outside it looks like a working policy.
  • A policy can outlive the team that wrote it. Served, well-formed, nobody left who owns it.
  • No triage team, no SLA, no dashboard. Nothing tells you where your report sits. Some organisations reply in a day; some never reply at all.
  • Expect dead ends. Some entries go nowhere and I can't tell you in advance which. "Checked" means exactly what it says and nothing more.

If that unpredictability is going to frustrate you, the platforms exist and there's no shame in staying there.

The docs cover what each field means and what the index can't tell you.

๐Ÿ“ฌ One ask

Spot something that shouldn't be listed, or something that's missing? There's a contact page. I'd rather hear it than let the list quietly rot.

Happy hunting. ๐ŸŽฏ