Opens profile photo
Follow
bugcrowd
@Bugcrowd
The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
Technology-Security CompanySan Francisco, CAlinktr.ee/bugcrowdJoined September 2012

bugcrowd’s posts

┏━━┓┏━━┓┏━━┓┏━┓ ┗━┓┃┃┏┓┃┗━┓┃┗┓┃ ┏━┛┃┃┃┃┃┏━┛┃ ┃┃ HACK THE PLANET ┃┏━┛┃┃┃┃┃┏━┛ ┃┃ ┃┗━┓┃┗┛┃┃┗━┓ ┃┃ ┗━━┛┗━━┛┗━━┛ ┗┛
8
801
🎉 100k Giveaway 🎉 Hackers walked so Bugcrowd could run. Thank you for being part of our community! 🏃 💯 To show our appreciation, we're giving away swag all day! 😎 To enter 🎟️ ⤵️ 🔁 RETWEET 🧡 LIKE Drop your fave Bugcrowd memory below👇 #ItTakesACrowd
350
725
Found a Wordpress site? The easiest place to find bugs is in the plugins. 1. Find the installed plugins with WPScan 2. Set up your own WP instance and install the same plugins 3. Hack your own instance 4. Report your bugs! The most common bug you'll find with this method is XSS
14
609
🎁 Merry X(SS)MAS! Hackers!🎄 Beginning today we are doing 12 swag-ful days of giveaways and challenges. Today's challenge is simple: spread the cheer of #XSSMAS with a retweet of this tweet to be one of 12 researchers to get today's exclusive swag! ☃️
46
575
┏━━┓┏━━┓┏━━┓┏━━┓ ┗━┓┃┃┏┓┃┗━┓┃┗━┓┃ ┏━┛┃┃┃┃┃┏━┛┃┏━┛┃ HACK THE PLANET ┃┏━┛┃┃┃┃┃┏━┛┃┏━┛ ┃┗━┓┃┗┛┃┃┗━┓┃┗━┓ ┗━━┛┗━━┛┗━━┛┗━━┛
6
496
If you're hunting for low-hanging bugs in source code, grep and regex can help you to identify hotspots. For example, you might find basic rXSS in PHP with something like this: grep -r "echo.*\$_\(GET\|REQUEST\|POST\)" .
3
456
What's your favorite part of this hacker setup? 💻👇 We would share ours, but we can't choose just one. 👀 It's. Too. Cool. 😈 😎 Thanks for sharing!!
Image
51
455
XXE's are still quite common, and they're usually a P1! Here are places that you can look for them, comment if you have any other ideas! Thread 👇.
6
402
Here are a few ways to make the most of an XSS. Comment if you can think of some other ideas or resources! Thread 👇.
18
396
Did you know: The term 'bug' (as it refers to computers) was first coined in 1947 when a group of computer scientists found an actual moth causing malfunctions in a computer.
14
365
Looking to quickly dump URLs from a webpage using curl and some regex magic!? Try: curl -s https://www.bugcrowd[.]com | pcregrep -o "(http:\/\/|https:\/\/).*?(?=\"|'| )" | sort -u
Image
3
347
New to bounties? We've created this page containing links to everything you need to know including free educational resources, researcher docs, how to find bugs, beginner resources, how to get private invites, and more. Login to view! bugcrowd.com/welcome #BugcrowdTipJar
2
326
"For me, the ninth month of the Islamic calendar, Ramadan, is the month to think about the blessings Allah has casted on me and my family, reflect on the year and act towards becoming a better Muslim." - Murtaza Haizji (Senior Manager Demand Gen) Ramadan Mubarak 🙏
Image
24
341
What's something a non-hacker wouldn't understand? We'll go first: congratulating each other for finding bugs 🐛
65
319
XSS is the most common bug class! It pays to be good at finding them. In the latest how-to blog post, covers what XSS is, different discovery methods, contexts, filter bypasses, weaponized payloads, and more.
3
319
What are the best resources for beginners? What do you recommend to hackers who are just starting out? We're all 👂👂👂
35
296
When you find an XSS, at minimum, use alert(document.domain) over alert(1). This helps to demonstrate the context that the JavaScript is executing in. Even better, escalate the XSS to perform an account takeover! Don't forget to share your own XSS tips using #BugBountyTipJar
8
293
Researchers, ⊂_ヽ   \\ we    \( ͡° ͜ʖ ͡°)     > ⌒ヽ    /   へ\    /  / \\appreciate    レ ノ   ヽ_つ   / /   / /|  ( (ヽ  | |、\you!  | 丿 \⌒)  | |  ) / ノ )  Lノ (_/ Have a great weekend. 😎
7
269
Researchers ⊂_ヽ   \\ we    \( ͡° ͜ʖ ͡°)     > ⌒ヽ    /   へ\    /  / \\appreciate    レ ノ   ヽ_つ   / /   / /|  ( (ヽ  | |、\you  | 丿 \ ⌒)  | |  ) / ノ )  Lノ (_/ Have a great weekend 🧡
2
253
A quick one-liner that will gather + crawl all subdomains, then convert to a custom wordlist unique to that organisation based on discovered URLs! subfinder -d bugcrowd[.]com -silent | httpx -silent | hakrawler -plain | tr "[:punct:]" "\n" | sort -u
252
🚨CHALLENGE TIME🚨 Can you popup an alert?😉 Rules⤵️ 📣DM us a screenshot once complete 📣100 likes & we'll release a hint 15 winners⤵️ 🥇5 winners: hoodies 🥈5 winners: t-shirts 🥉5 winners: stickers + glasses GO 👉 bgcd.co/3PKAefZ Challenge by
Image
29
251
If you had to put together a "Hacking for Beginners" starter kit, what is one item your kit absolutely can't exist without? 😎
72
238
Changes are coming to Bugcrowd Vulnerability Disclosure Programs. Starting Monday, Points will no longer be awarded on VDP submissions. Find out why we are making this change in our latest blog post here 👇
30
219