bugcrowd Profile Banner
bugcrowd Profile
bugcrowd

@Bugcrowd

Followers
160,862
Following
6,488
Media
7,033
Statuses
22,736

The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™

San Francisco, CA
Joined September 2012
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@Bugcrowd
bugcrowd
4 years
Like for hacker cat. Retweet for hacker dog. You can only choose one...
Tweet media one
Tweet media two
46
358
2K
@Bugcrowd
bugcrowd
2 years
When you encounter a 403 Forbidden page 🚫 , try adding an "X-Client-IP" header with the value "127.0.0.1" #bugbountytips ✌🏽
Tweet media one
11
404
2K
@Bugcrowd
bugcrowd
9 months
Tweet media one
11
141
980
@Bugcrowd
bugcrowd
3 years
When you encounter a 403 Forbidden page, try adding a "X-Client-IP" header with the value "127.0.0.1". #bugcrowdtipjar
Tweet media one
12
287
935
@Bugcrowd
bugcrowd
3 years
┏━━┓┏━━┓┏━━┓┏━┓ ┗━┓┃┃┏┓┃┗━┓┃┗┓┃ ┏━┛┃┃┃┃┃┏━┛┃ ┃┃ HACK THE PLANET ┃┏━┛┃┃┃┃┃┏━┛ ┃┃ ┃┗━┓┃┗┛┃┃┗━┓ ┃┃ ┗━━┛┗━━┛┗━━┛ ┗┛
8
150
781
@Bugcrowd
bugcrowd
2 years
Bringing an important tip back! 👇 When you encounter a 403 Forbidden page 🚫 , try adding an "X-Client-IP" header with the value "127.0.0.1" #BugBountyTips
Tweet media one
18
191
788
@Bugcrowd
bugcrowd
2 years
🎉 100k Giveaway 🎉 Hackers walked so Bugcrowd could run. Thank you for being part of our community! 🏃 💯 To show our appreciation, we're giving away swag all day! 😎 To enter 🎟️ ⤵️ 🔁 RETWEET 🧡 LIKE ✅ Drop your fave Bugcrowd memory below👇 #ItTakesACrowd
342
404
718
@Bugcrowd
bugcrowd
3 years
As a hacker, how do you stay motivated? 💻 🤓
145
41
635
@Bugcrowd
bugcrowd
19 days
What vulns are in this and how would you exploit them?
Tweet media one
59
63
672
@Bugcrowd
bugcrowd
11 months
You can only save 1 of these tools. Which are you saving?
Tweet media one
184
48
501
@Bugcrowd
bugcrowd
1 year
⏰ Time for a #GIVEAWAY ! 💬 We want to hear from you. How to win swag? 📣 Retweet 📣 Like 📣 Complete the survey 📣 Drop an emoji once completed Click here to get started: ⤵
Tweet media one
441
407
634
@Bugcrowd
bugcrowd
2 years
The meme winner is... 🥁 🎉 @0xRh1d0Y 🎉 #BugBounty #HackingMemes
Tweet media one
20
68
610
@Bugcrowd
bugcrowd
2 years
#Ramadan Kareem! We wish you all an inspiring and rewarding month.
Tweet media one
45
60
587
@Bugcrowd
bugcrowd
3 years
Found a Wordpress site? The easiest place to find bugs is in the plugins. 1. Find the installed plugins with WPScan 2. Set up your own WP instance and install the same plugins 3. Hack your own instance 4. Report your bugs! The most common bug you'll find with this method is XSS
13
123
598
@Bugcrowd
bugcrowd
2 months
Wishing you a blessed #Ramadan filled with peace, joy, and reflection. Ramadan Mubarak. 🌙
Tweet media one
30
61
598
@Bugcrowd
bugcrowd
4 years
Happy Father's Day to hacking dads only! #HappyFathersDay #FathersDay
Tweet media one
11
73
581
@Bugcrowd
bugcrowd
3 years
🎁 Merry X(SS)MAS! Hackers!🎄 Beginning today we are doing 12 swag-ful days of giveaways and challenges. Today's challenge is simple: spread the cheer of #XSSMAS with a retweet of this tweet to be one of 12 researchers to get today's exclusive swag! ☃️
45
476
568
@Bugcrowd
bugcrowd
1 year
Week of #giveaways starts now! 🎁 Complete the tasks for your chance to win swag ⤵ ✅ Retweet ✅ Like ✅ Tag a friend in the comments #ItTakesACrowd #OuthackThemAll
400
390
568
@Bugcrowd
bugcrowd
4 years
Nobody: Not even hackers: Hackers in pop culture after pushing one button: "I'M IN!"
19
82
551
@Bugcrowd
bugcrowd
2 months
This is very cool. Get cheatsheets in your terminal with a curl command! ⌨️ Try this: curl Shout out to @igor_chubin ! 🎉
Tweet media one
8
166
570
@Bugcrowd
bugcrowd
1 year
#Ramadan Kareem! We wish you all an inspiring and rewarding month.
Tweet media one
34
63
543
@Bugcrowd
bugcrowd
5 months
🚨 Giveaway day 2: 👉 Follow us @bugcrowd 💟 Like this post 🔂 Retweet with your all-time favorite tool
141
158
532
@Bugcrowd
bugcrowd
2 years
Learn the mobile #hacking basics with our resources kit 👇👇👇 #bugbountytips
Tweet media one
5
141
511
@Bugcrowd
bugcrowd
4 years
As far as 2020 expectations, AI is right on track... 😂
Tweet media one
12
91
497
@Bugcrowd
bugcrowd
2 years
┏━━┓┏━━┓┏━━┓┏━━┓ ┗━┓┃┃┏┓┃┗━┓┃┗━┓┃ ┏━┛┃┃┃┃┃┏━┛┃┏━┛┃ HACK THE PLANET ┃┏━┛┃┃┃┃┃┏━┛┃┏━┛ ┃┗━┓┃┗┛┃┃┗━┓┃┗━┓ ┗━━┛┗━━┛┗━━┛┗━━┛
6
84
488
@Bugcrowd
bugcrowd
2 years
Our Web Hacking Resources Kit will help you to master the basics and get you on your way to your next P1! 😎 Check it out! 📲 #BugBountyTips #Hackers
Tweet media one
4
163
485
@Bugcrowd
bugcrowd
3 years
In your opinion, what hacking tool does every hacker needs in their arsenal? 🛠️
162
45
465
@Bugcrowd
bugcrowd
2 years
What's your favorite part of this hacker setup? 💻👇 We would share ours, but we can't choose just one. 👀 It's. Too. Cool. 😈 😎 Thanks for sharing!! @aditi_singghh
Tweet media one
49
29
455
@Bugcrowd
bugcrowd
3 years
If you're hunting for low-hanging bugs in source code, grep and regex can help you to identify hotspots. For example, you might find basic rXSS in PHP with something like this: grep -r "echo.*\$_\(GET\|REQUEST\|POST\)" .
3
137
443
@Bugcrowd
bugcrowd
1 year
The secrets of Google Tag Manager👀 #BugBountyTips @bsysop 👇 #OuthackThemAll #ItTakesACrowd
Tweet media one
Tweet media two
Tweet media three
13
115
451
@Bugcrowd
bugcrowd
2 years
Keep on #BugHunting 🐛💰
Tweet media one
1
58
422
@Bugcrowd
bugcrowd
25 days
You see this. What's the first thing you do?
Tweet media one
122
21
429
@Bugcrowd
bugcrowd
4 months
3 ways to use Nmap as a vulnerabiltiy scanner 🐛 nmap -sV --script vuln <target> 🪲 nmap -sV --script vulners.nse <target> 🐞 nmap -sV --script vulscan/vulscan.nse <target> Details on using vulscan in thread 🧵👇
2
108
418
@Bugcrowd
bugcrowd
6 months
Did someone say Week of Giveaways? Oh! That's right, we did. 😏 🎟️ To enter day 1: ⏺️ Follow us @Bugcrowd ❤️ Like this post 💬 Reply with a GIF that best represents your reaction when you find a critical bug
287
19
412
@Bugcrowd
bugcrowd
3 years
XXE's are still quite common, and they're usually a P1! Here are places that you can look for them, comment if you have any other ideas! Thread 👇.
6
128
395
@Bugcrowd
bugcrowd
3 years
When hunting for bugs, look for features that are complex. As a rule of thumb: More complex = less secure. #BugBountyTips
11
76
383
@Bugcrowd
bugcrowd
3 years
Here are a few ways to make the most of an XSS. Comment if you can think of some other ideas or resources! Thread 👇.
18
134
393
@Bugcrowd
bugcrowd
3 months
. @InsiderPHD 's top bug bounty hunting tools of 2023 🚀 🔨 Burp Suite 🔧 Kiterunner 🪛 Shodan 🪚 Amass 🗜️ FFUF ⛏️ SQLMap 🪓 Frida 🔩 TruffleHog 🛠️ XSS Hunter Express ⚒️ Nuclei 🧰 Interactsh What would you add or remove from this list in 2024?
5
60
389
@Bugcrowd
bugcrowd
4 years
Nobody: Hackers in stock photography:
Tweet media one
19
68
370
@Bugcrowd
bugcrowd
2 years
In case you missed it, this Web Hacking Resources kit is here for you. 😎 What tools would you like to see added? 👇 #BugBountyTips
Tweet media one
8
116
371
@Bugcrowd
bugcrowd
3 years
Did you know: The term 'bug' (as it refers to computers) was first coined in 1947 when a group of computer scientists found an actual moth causing malfunctions in a computer.
14
66
359
@Bugcrowd
bugcrowd
3 years
Have you been lookin for a crash course on XXE bugs? It's a class of bugs often missed by even the most seasoned hackers. 🤓 Here is everything you need to know to start finding XXE bugs. Godspeed! Happy hacking!
7
152
368
@Bugcrowd
bugcrowd
4 years
Describe a hacker in just 4 words...
192
49
359
@Bugcrowd
bugcrowd
3 years
What hacking tool does every hacker needs in their arsenal? Let us know 👇
105
69
357
@Bugcrowd
bugcrowd
4 months
10 recon tools for bug bounty hunting in 2024 🪲🔍 1️⃣ Nmap 2️⃣ SecurityTrails 3️⃣ Amass 4️⃣ Dirsearch 5️⃣ subfinder 6️⃣ Httpx 7️⃣ GitHub code search 8️⃣ Google Dorks 9️⃣ Shodan 🔟 Censys What tools would you add to this list?
11
74
363
@Bugcrowd
bugcrowd
4 years
Hackers gonna hack. 🤓 💻
14
50
353
@Bugcrowd
bugcrowd
3 years
Looking to quickly dump URLs from a webpage using curl and some regex magic!? Try: curl -s https://www.bugcrowd[.]com | pcregrep -o "(http:\/\/|https:\/\/).*?(?=\"|'| )" | sort -u
Tweet media one
3
115
344
@Bugcrowd
bugcrowd
3 years
Keep up the good work researchers! 💪 🧡 💥
Tweet media one
8
20
326
@Bugcrowd
bugcrowd
1 year
"For me, the ninth month of the Islamic calendar, Ramadan, is the month to think about the blessings Allah has casted on me and my family, reflect on the year and act towards becoming a better Muslim." - Murtaza Haizji (Senior Manager Demand Gen) Ramadan Mubarak 🙏
Tweet media one
24
32
331
@Bugcrowd
bugcrowd
2 years
Too relatable 😂 😭
Tweet media one
11
37
323
@Bugcrowd
bugcrowd
2 years
Best wishes to all who are celebrating Eid 🌙 #EidMubarak #APAHM
Tweet media one
17
37
322
@Bugcrowd
bugcrowd
3 months
How to enumerate subdomains using Ffuf and SecLists! Just like you would fuzz directories but you put "FUZZ" at the start of the URL instead of at the end. ⌨️ ffuf -u FUZZ.<target> -w <wordlist>
Tweet media one
3
80
328
@Bugcrowd
bugcrowd
3 years
What's something a non-hacker wouldn't understand? We'll go first: congratulating each other for finding bugs 🐛
65
18
312
@Bugcrowd
bugcrowd
5 months
Want to win swag? 👀 Giveaway day 3: 🤝 Follow us @bugcrowd 👍 Like this post 📸 Reply with a picture of your workspace
148
19
318
@Bugcrowd
bugcrowd
3 years
New to bounties? We've created this page containing links to everything you need to know including free educational resources, researcher docs, how to find bugs, beginner resources, how to get private invites, and more. Login to view! #BugcrowdTipJar
2
113
319
@Bugcrowd
bugcrowd
3 years
If you ever find a SSRF on a Windows box, try running on your own VPS, then send the SSRF to file://<yourvps>. With a bit of luck, the server will send you some tasty Windows NetNTLMv2 hashes to crack! What are other methods do you use? #BugcrowdTipJar
5
78
317
@Bugcrowd
bugcrowd
1 year
🐜 🤝 💰
Tweet media one
4
39
316
@Bugcrowd
bugcrowd
5 months
Share a little gratitude for our final giveaway 🧡 To enter: 🐜 Follow us @bugcrowd ⭐️ Like this post 🧵 Tag a hacker who's motivated you to keep hacking
213
24
313
@Bugcrowd
bugcrowd
3 years
XSS is the most common bug class! It pays to be good at finding them. In the latest how-to blog post, @hakluke covers what XSS is, different discovery methods, contexts, filter bypasses, weaponized payloads, and more.
3
133
313
@Bugcrowd
bugcrowd
4 years
Hacking is fun and all, but what are your hobbies outside of infosec?
163
16
304
@Bugcrowd
bugcrowd
4 years
While he hits some pretty big bounties, you might be surprised how @hunter0x7 got started in bug hunting. Join us for this researcher spotlight and down to earth chat with Ahsan Khan! #ItTakesACrowd
Tweet media one
25
34
304
@Bugcrowd
bugcrowd
4 years
Define "vulnerability" using only 4 words?
428
32
303
@Bugcrowd
bugcrowd
3 years
Roses are red. 🌹 P5's are blue. 5️⃣ Dups happen sometimes, 🐜 but they're valid bugs too! 🌟
8
40
286
@Bugcrowd
bugcrowd
2 years
A meme a day keeps the blues away. 🔁 Retweet for meme 1 💙 Like for meme 2 ⚠️ We will choose one random participant to win SWAG! #BugBountyMemes by 👉 @thecryptohack3r
Tweet media one
Tweet media two
16
88
290
@Bugcrowd
bugcrowd
3 years
When you find an XSS, at minimum, use alert(document.domain) over alert(1). This helps to demonstrate the context that the JavaScript is executing in. Even better, escalate the XSS to perform an account takeover! Don't forget to share your own XSS tips using #BugBountyTipJar
8
51
288
@Bugcrowd
bugcrowd
4 years
What are the best resources for beginners? What do you recommend to hackers who are just starting out? We're all 👂👂👂
35
73
291
@Bugcrowd
bugcrowd
3 years
We've all been there... 🙃
Tweet media one
16
32
285
@Bugcrowd
bugcrowd
1 month
WOAHHHHHHHHHHH! congratulations!! 🐛💸👏
@fwrnr
Felipe Warrener-Iglesias
1 month
I was awarded $65,400 for my submissions on @bugcrowd #ItTakesACrowd The #bugbounty #bugbountytip here is turn off your testing mindset and turn on your vulnerability research mindset.
Tweet media one
59
39
708
4
14
293
@Bugcrowd
bugcrowd
7 months
Step 1: Go to your computer. Step 2: Start hacking. Step 3: Submit your bugs.
21
35
279
@Bugcrowd
bugcrowd
6 years
. @binance has launched a public #bugbounty program with @Bugcrowd ! Get all the new program details here: #OuthackThemAll
Tweet media one
31
83
247
@Bugcrowd
bugcrowd
4 months
Do you have a New Year's resolution to start bug bounty hunting? Get a head start with @nahamsec 's HUGE list of resources for beginners: 🐞 Basics 🐛 Blogs & Talks 🐜 Books 🦟 Setup 🪲 Tools 🪳 Labs 🕷️ Talks 🐜 Coding 🦟 Mindset And more! 👇
4
88
281
@Bugcrowd
bugcrowd
2 years
🚨
Tweet media one
11
25
275
@Bugcrowd
bugcrowd
1 year
We're giving swag, you're giving tips! Day 4 of #giveaways 🎁 👇 What's the best resource you've added to your #bugbounty library? 👀
137
47
279
@Bugcrowd
bugcrowd
3 years
Who inspired you in infosec during 2020? 🧐💻 #ItTakesACrowd
133
19
268
@Bugcrowd
bugcrowd
3 years
I'm gonna tell my kids they started Bugcrowd.
Tweet media one
7
25
267
@Bugcrowd
bugcrowd
2 years
Researchers, ⊂_ヽ   \\ we    \( ͡° ͜ʖ ͡°)     > ⌒ヽ    /   へ\    /  / \\appreciate    レ ノ   ヽ_つ   / /   / /|  ( (ヽ  | |、\you!  | 丿 \⌒)  | |  ) / ノ )  Lノ (_/ Have a great weekend. 😎
7
21
261
@Bugcrowd
bugcrowd
2 years
👋 Researchers! What's a hacking tool all beginners should be using? 🛠️ Asking for a friend! 🤭 #ItTakesACrowd
76
40
265
@Bugcrowd
bugcrowd
3 years
What does SQL stand for? Wrong answers only...
225
10
264
@Bugcrowd
bugcrowd
1 year
Today seems like a good day to watch YouTube 🥱 Tell us your favorite #hacker content creator and be entered to win a Pentesterlab Subscription!👇 Week of #giveaways day 2 🎁
223
30
266
@Bugcrowd
bugcrowd
4 years
My mom when I told her to chews a secure password... #ItTakesACrowd
Tweet media one
7
36
257
@Bugcrowd
bugcrowd
1 year
New year, new swag, new game! Hacker's choice: THIS or THAT❓ Drop your choice below and be entered to win NEW swag! 👇 #MacintoshDay
Tweet media one
367
20
256
@Bugcrowd
bugcrowd
3 years
Knowing regex is a very powerful skill for hackers. It allows us to be more productive, and also gives us an insight into how we might exploit Regex-based security controls. Read this blog by @hakluke to learn more!
Tweet media one
4
87
262
@Bugcrowd
bugcrowd
4 years
When the kombucha takes over...
Tweet media one
10
16
259
@Bugcrowd
bugcrowd
5 months
eLFI's back and on the hunt searching for your coolest hacker swag! 🎁 From keyboards to hoodies, what's been your favorite piece of #Bugcrowd swag over the years? 📸 To enter: 👉 Retweet + Like 👉 Reply with a pic of your swag #giveaway #eLFI
Tweet media one
88
106
256
@Bugcrowd
bugcrowd
2 years
ɹǝʞɔɐɥ ʎɹɐuıpɹoɐɹʇxǝ uɐ ǝɹ'noʎ ,sıɥʇ pɐǝɹ uɐɔ noʎ ɟı 👀 👀 👀
38
14
250
@Bugcrowd
bugcrowd
4 years
What people think I do vs what I actually do:
Tweet media one
10
34
254
@Bugcrowd
bugcrowd
2 years
API Tip 💡💡 💡 Thank you, @InsiderPhD 🙌 #bugbountytips
Tweet media one
1
58
257
@Bugcrowd
bugcrowd
2 years
We're dropping some #BugBountyTips 👉 Chain AutoRepeater and Taborator to Automate SSRF Findings. Created by: @bsysop 👏 Check the thread below for more details ⤵️
Tweet media one
10
79
247
@Bugcrowd
bugcrowd
4 months
Looking at getting into bug bounty hunting? Bugcrowd University is a ✨FREE✨ project to help you level-up your skills! Modules include: ✅ Making a Good Submission ✅ Burp Suite ✅ XSS ✅ Recon and Discovery ✅ SSRF ✅ XXE And more! Jump in 👇
6
70
250
@Bugcrowd
bugcrowd
3 years
Our hacking starter pack. What's yours? 👇
Tweet media one
Tweet media two
Tweet media three
Tweet media four
22
19
243
@Bugcrowd
bugcrowd
1 year
THIS or THAT ❓ Answer below, you could win that 😏
Tweet media one
275
12
244
@Bugcrowd
bugcrowd
3 years
Researchers ⊂_ヽ   \\ we    \( ͡° ͜ʖ ͡°)     > ⌒ヽ    /   へ\    /  / \\appreciate    レ ノ   ヽ_つ   / /   / /|  ( (ヽ  | |、\you  | 丿 \ ⌒)  | |  ) / ノ )  Lノ (_/ Have a great weekend 🧡
2
16
245
@Bugcrowd
bugcrowd
2 years
Want to WIN SWAG?🏆 Play the game!🎮 🔒Guess the password (26 letters) 🔢Numbers correspond to letters ✍️Example: 1 = A, 2 = B, 3 = C 🔑We'll drop a hint for every 100 likes 👇Comment your guess below, no letters allowed Hint: #StarWars #MayTheForceBeWithYou #WorldPasswordDay
Tweet media one
90
25
243
@Bugcrowd
bugcrowd
3 years
A quick one-liner that will gather + crawl all subdomains, then convert to a custom wordlist unique to that organisation based on discovered URLs! subfinder -d bugcrowd[.]com -silent | httpx -silent | hakrawler -plain | tr "[:punct:]" "\n" | sort -u
0
81
246
@Bugcrowd
bugcrowd
2 years
👀 Want to win swag? 👇 As a hacker, tell us 1 way you take care of your mental health. 🧡 Reminder: #YouMatter #YourMindMatters #MentalHealthAwarenessMonth
301
17
246
@Bugcrowd
bugcrowd
1 month
The first stage of bug hunting is recon. The first stage of recon is... subdomains? Not always. @JR0ch17 prefers a small scope and focuses on single applications instead. Here's his unique 11 step approach to recon👇
1
66
245
@Bugcrowd
bugcrowd
2 years
🚨CHALLENGE TIME🚨 Can you popup an alert?😉 Rules⤵️ 📣DM us a screenshot once complete 📣100 likes & we'll release a hint 15 winners⤵️ 🥇5 winners: hoodies 🥈5 winners: t-shirts 🥉5 winners: stickers + glasses GO 👉 Challenge by @MRCodedBrain
Tweet media one
29
38
246
@Bugcrowd
bugcrowd
3 years
Today’s #BugcrowdScholar challenge is simple! Comment below with your best bug bounty tip that's helped you save time or make impact and we'll choose some random scholars! #BugBountyTips #BugcrowdTipJar 🤓
88
46
242
@Bugcrowd
bugcrowd
3 months
A list of payloads to detect XSS vulnerabilities: 🐞 XSS in HTML/Applications 🐛 XSS in wrappers javascript and data URI 🐜 XSS in files 🦟 XSS in PostMessage 🪲 Filter Bypass and exotic payloads And more! 👇
0
63
242