Remove Metadata From Screenshots Before Bug Bounty Submission
PoC screenshots can leak researcher device IDs and capture timestamps — wipe before platform submission.
Ready to clean a photo? MetadataWipe processes JPEG, PNG, and video files locally — no account and no server transfer.
Open MetadataWipe toolBug bounty researchers attach proof-of-concept screenshots to HackerOne reports — SSRF responses, IDOR JSON panels, admin dashboards with redacted-but-leaky UI, and mobile app fault states. Programs store reports for years; triage staff, vendors, and sometimes other researchers with access see attachments. Mobile PoC screenshots inherit phone EXIF; even desktop PNGs may embed software and timestamp metadata linking a pseudonymous handle to a real workstation timezone and tooling fingerprint.
MetadataWipe addresses researcher OPSEC on envelope data — complementary to HideShot visual redaction of tokens and distinct from generic screenshot pages that focus on social sharing rather than vulnerability disclosure archives.
How to use MetadataWipe
- 1. Capture PoC screenshot to a dedicated bug-bounty folder.
- 2. Load the image in MetadataWipe via the browser tool.
- 3. Review and remove DateTime, device, GPS, and software metadata fields.
- 4. Download wiped screenshot and pair with HideShot if visible secrets remain.
- 5. Attach only cleaned files to the platform report form.
Researcher OPSEC and Platform Archives
Mobile app PoCs geotag lab locations when screenshots include maps or location UI.
Timestamp metadata correlates report submission timing with researcher day jobs.
Software tags fingerprint tooling setups across multiple pseudonymous accounts.
Proof images that identify the researcher
A PNG of a vulnerable response should show the bug, not the phone model, the capture clock, or a GPS leftover from the last camera shot. Program platforms archive attachments. So does your sent mail. DateTimeOriginal-style timestamps can line up with your public social posts. Software tags name OEM skins. IPTC author appears if you annotated on a desktop and exported from Photoshop.
OPSEC for reports is mostly about tickets and tokens in the pixels. The header is the piece people forget because it is invisible in the report form preview.
Cleaning a PNG capture before the report form
Screenshots are usually PNG; the homepage tool accepts PNG and JPEG. Open MetadataWipe, read Software and timestamps, and strip locally with no server upload of the proof.
- Redact secrets in the pixels first if needed, export PNG/JPEG, then wipe metadata so the editor cannot put tags back.
- Skip screen recordings here; this tool does not strip MP4. Export a still frame and wipe that still.
- Confirm Make, Model, and clock fields are gone on the download.
- Attach only the cleaned files to HackerOne, Bugcrowd, or email.
If you must include a browser photo of a physical kiosk, that JPEG can hold real GPS of the site. Decide whether the report needs location; if not, wipe GPS.
Platform archives, duplicate reports, and helper laptops
Duplicate attachments sent to two programs double the archive. Wipe once, reuse the cleaned PNG, and do not “improve sharpness” by grabbing the original again.
A laptop you borrowed for Burp may write a different Software string into a PNG export. That still identifies a machine. Wipe. Sidecars from annotated PSDs should never ride along in the zip you send triagers.
PDF writeups are outside this tool's Author rewrite. Place cleaned PNGs into the PDF so the images are clean even if PDF properties are handled elsewhere.
Proxy intercept screenshots often include a desktop clock and a hostname in the pixels plus Software in the PNG header. Redact the hostname in the image, then wipe so DateTimeOriginal-style chunks do not recreate a timeline next to your public researcher handle. Collaborate by sending cleaned PNGs, not a shared camera-roll album that still holds GPS from the commute.
Report-attachment errors that keep device tags
- Markup in the OS screenshot tool and sending without a wipe. Circles sit on pixels; chunks often remain.
- Including the original and the redacted copy “for context.” The original is the leak.
- Photographing the monitor with a phone instead of a PNG capture. Now you have GPS. Wipe the JPEG or recapture as PNG and wipe that.
- Using a HEIC from the phone camera of a whiteboard. Export JPEG, wipe, attach JPEG.
Related guides
See also:
Frequently asked questions
Do bug bounty platforms strip screenshot metadata?
Treat HackerOne, Bugcrowd, and Intigriti as long-term archives — wipe before submission.
What metadata appears on security screenshots?
DateTime, device model on mobile captures, software tags, and sometimes GPS if screenshots include map PoCs.
Should I also redact visually?
Yes. Use HideShot for tokens, PII, and internal hostnames — MetadataWipe handles invisible envelope data.
Are desktop PNG screenshots safe?
Desktop grabs often include minimal EXIF but may carry software chunks — verify in the panel.
Remove EXIF data, GPS location, and common photo metadata in your browser.
Try MetadataWipe freeBug bounty platforms are credential and vulnerability archives — reports remain accessible to program owners long after bounties pay. Researcher OPSEC traditionally focuses on redacting API keys and user PII in screenshots, but metadata deanonymization is a second lane: EXIF proving a report was crafted on a specific phone model at 2 a.m. local time in a city inferred from timezone-adjacent metadata. Program rules rarely mention metadata; triage teams do not consistently strip it on ingest.
MetadataWipe gives security researchers a local pre-submission pass for PoC attachments — strip envelope data before HackerOne or Bugcrowd storage, alongside visual redaction habits for secrets in the frame.
What Bug Bounty Screenshot Metadata Exposes — and Why Strip It
Capture timestamps correlating pseudonymous activity with researcher employment hours.
Mobile device Make/Model linking multiple reports to one physical phone.
GPS on map-based vulnerability PoCs showing lab or home location.
Software metadata revealing screenshot tools and OS build fingerprints.
Realistic Scenarios
Scenario A — Mobile IDOR: A researcher wipes GPS and device serial from Android app PoC screenshots before HackerOne submission.
Scenario B — Corporate program: A consultant strips timestamp metadata from dashboard leaks before Bugcrowd triage under a vendor handle.
Scenario C — Duplicate accounts: A researcher removes software fingerprints to avoid correlating two platform identities through identical EXIF tooling signatures.
Step-by-Step: How to Use the Tool
- Save PoC screenshots outside personal camera roll when possible.
- Load each attachment in MetadataWipe before report submission.
- Remove all reported metadata fields.
- Apply HideShot to visible tokens, emails, and internal hostnames if needed.
- Submit wiped files through the platform report form — retain local originals in encrypted research notes.
Common Mistakes
Redacting URLs visually but sending raw EXIF. Envelope data persists in archived reports.
Assuming programs delete attachments after closure. Treat submissions as permanent retention.
Using personal phone screenshots without wipe for corporate program targets. Device fingerprint links corporate research to personal hardware.
Why Browser-Only Bug Bounty Metadata Removal Matters
Vulnerability screenshots are sensitive intelligence — sending them to cloud EXIF tools adds a third party to the disclosure chain. MetadataWipe strips tags locally before platform archives store your PoC forever.