bugcrowd Profile Banner
bugcrowd Profile
bugcrowd

@Bugcrowd

Followers
167,560
Following
6,458
Media
7,399
Statuses
23,635

The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™

San Francisco, CA
Joined September 2012
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@Bugcrowd
bugcrowd
4 years
Like for hacker cat. Retweet for hacker dog. You can only choose one...
Tweet media one
Tweet media two
46
354
2K
@Bugcrowd
bugcrowd
3 years
When you encounter a 403 Forbidden page 🚫 , try adding an "X-Client-IP" header with the value "127.0.0.1" #bugbountytips ✌🏽
Tweet media one
11
402
2K
@Bugcrowd
bugcrowd
1 year
Tweet media one
11
138
959
@Bugcrowd
bugcrowd
3 years
When you encounter a 403 Forbidden page, try adding a "X-Client-IP" header with the value "127.0.0.1". #bugcrowdtipjar
Tweet media one
13
288
934
@Bugcrowd
bugcrowd
4 years
┏━━┓┏━━┓┏━━┓┏━┓ ┗━┓┃┃┏┓┃┗━┓┃┗┓┃ ┏━┛┃┃┃┃┃┏━┛┃ ┃┃ HACK THE PLANET ┃┏━┛┃┃┃┃┃┏━┛ ┃┃ ┃┗━┓┃┗┛┃┃┗━┓ ┃┃ ┗━━┛┗━━┛┗━━┛ ┗┛
8
147
775
@Bugcrowd
bugcrowd
2 years
Bringing an important tip back! 👇 When you encounter a 403 Forbidden page 🚫 , try adding an "X-Client-IP" header with the value "127.0.0.1" #BugBountyTips
Tweet media one
18
188
780
@Bugcrowd
bugcrowd
3 years
🎉 100k Giveaway 🎉 Hackers walked so Bugcrowd could run. Thank you for being part of our community! 🏃 💯 To show our appreciation, we're giving away swag all day! 😎 To enter 🎟️ ⤵️ 🔁 RETWEET 🧡 LIKE ✅ Drop your fave Bugcrowd memory below👇 #ItTakesACrowd
340
402
710
@Bugcrowd
bugcrowd
4 years
As a hacker, how do you stay motivated? 💻 🤓
145
41
629
@Bugcrowd
bugcrowd
1 year
You can only save 1 of these tools. Which are you saving?
Tweet media one
181
47
497
@Bugcrowd
bugcrowd
5 months
What vulns are in this and how would you exploit them?
Tweet media one
57
61
657
@Bugcrowd
bugcrowd
2 years
⏰ Time for a #GIVEAWAY ! 💬 We want to hear from you. How to win swag? 📣 Retweet 📣 Like 📣 Complete the survey 📣 Drop an emoji once completed Click here to get started: ⤵
Tweet media one
441
407
629
@Bugcrowd
bugcrowd
2 years
The meme winner is... 🥁 🎉 @0xRh1d0Y 🎉 #BugBounty #HackingMemes
Tweet media one
20
68
604
@Bugcrowd
bugcrowd
2 years
#Ramadan Kareem! We wish you all an inspiring and rewarding month.
Tweet media one
45
59
578
@Bugcrowd
bugcrowd
4 years
Found a Wordpress site? The easiest place to find bugs is in the plugins. 1. Find the installed plugins with WPScan 2. Set up your own WP instance and install the same plugins 3. Hack your own instance 4. Report your bugs! The most common bug you'll find with this method is XSS
13
122
592
@Bugcrowd
bugcrowd
6 months
Wishing you a blessed #Ramadan filled with peace, joy, and reflection. Ramadan Mubarak. 🌙
Tweet media one
28
58
587
@Bugcrowd
bugcrowd
4 years
Happy Father's Day to hacking dads only! #HappyFathersDay #FathersDay
Tweet media one
11
73
573
@Bugcrowd
bugcrowd
4 years
🎁 Merry X(SS)MAS! Hackers!🎄 Beginning today we are doing 12 swag-ful days of giveaways and challenges. Today's challenge is simple: spread the cheer of #XSSMAS with a retweet of this tweet to be one of 12 researchers to get today's exclusive swag! ☃️
45
474
562
@Bugcrowd
bugcrowd
2 years
Week of #giveaways starts now! 🎁 Complete the tasks for your chance to win swag ⤵ ✅ Retweet ✅ Like ✅ Tag a friend in the comments #ItTakesACrowd #OuthackThemAll
398
385
566
@Bugcrowd
bugcrowd
4 years
Nobody: Not even hackers: Hackers in pop culture after pushing one button: "I'M IN!"
19
82
547
@Bugcrowd
bugcrowd
6 months
This is very cool. Get cheatsheets in your terminal with a curl command! ⌨️ Try this: curl Shout out to @igor_chubin ! 🎉
Tweet media one
8
167
561
@Bugcrowd
bugcrowd
1 year
#Ramadan Kareem! We wish you all an inspiring and rewarding month.
Tweet media one
33
62
537
@Bugcrowd
bugcrowd
10 months
🚨 Giveaway day 2: 👉 Follow us @bugcrowd 💟 Like this post 🔂 Retweet with your all-time favorite tool
138
158
525
@Bugcrowd
bugcrowd
3 years
Learn the mobile #hacking basics with our resources kit 👇👇👇 #bugbountytips
Tweet media one
5
141
509
@Bugcrowd
bugcrowd
4 years
As far as 2020 expectations, AI is right on track... 😂
Tweet media one
11
91
495
@Bugcrowd
bugcrowd
3 years
Our Web Hacking Resources Kit will help you to master the basics and get you on your way to your next P1! 😎 Check it out! 📲 #BugBountyTips #Hackers
Tweet media one
4
163
483
@Bugcrowd
bugcrowd
3 years
┏━━┓┏━━┓┏━━┓┏━━┓ ┗━┓┃┃┏┓┃┗━┓┃┗━┓┃ ┏━┛┃┃┃┃┃┏━┛┃┏━┛┃ HACK THE PLANET ┃┏━┛┃┃┃┃┃┏━┛┃┏━┛ ┃┗━┓┃┗┛┃┃┗━┓┃┗━┓ ┗━━┛┗━━┛┗━━┛┗━━┛
6
82
483
@Bugcrowd
bugcrowd
4 years
In your opinion, what hacking tool does every hacker needs in their arsenal? 🛠️
162
44
462
@Bugcrowd
bugcrowd
3 years
What's your favorite part of this hacker setup? 💻👇 We would share ours, but we can't choose just one. 👀 It's. Too. Cool. 😈 😎 Thanks for sharing!! @aditi_singghh
Tweet media one
48
29
455
@Bugcrowd
bugcrowd
2 years
The secrets of Google Tag Manager👀 #BugBountyTips @bsysop 👇 #OuthackThemAll #ItTakesACrowd
Tweet media one
Tweet media two
Tweet media three
13
112
451
@Bugcrowd
bugcrowd
4 years
If you're hunting for low-hanging bugs in source code, grep and regex can help you to identify hotspots. For example, you might find basic rXSS in PHP with something like this: grep -r "echo.*\$_\(GET\|REQUEST\|POST\)" .
3
135
440
@Bugcrowd
bugcrowd
2 years
Keep on #BugHunting 🐛💰
Tweet media one
1
58
418
@Bugcrowd
bugcrowd
5 months
You see this. What's the first thing you do?
Tweet media one
117
17
417
@Bugcrowd
bugcrowd
8 months
3 ways to use Nmap as a vulnerabiltiy scanner 🐛 nmap -sV --script vuln <target> 🪲 nmap -sV --script vulners.nse <target> 🐞 nmap -sV --script vulscan/vulscan.nse <target> Details on using vulscan in thread 🧵👇
2
106
411
@Bugcrowd
bugcrowd
10 months
Did someone say Week of Giveaways? Oh! That's right, we did. 😏 🎟️ To enter day 1: ⏺️ Follow us @Bugcrowd ❤️ Like this post 💬 Reply with a GIF that best represents your reaction when you find a critical bug
280
18
408
@Bugcrowd
bugcrowd
4 months
GIVEAWAY 🎁🎁 It's simple, here are the rules: 🧑‍💻 Be a hacker 🔁 Retweet ❤️ Like 📝 Fill out the survey 👇 Drop an emoji when done You could win an entire swag bundle just by filling out the survey 😱
Tweet media one
228
224
400
@Bugcrowd
bugcrowd
4 years
XXE's are still quite common, and they're usually a P1! Here are places that you can look for them, comment if you have any other ideas! Thread 👇.
6
127
394
@Bugcrowd
bugcrowd
4 years
When hunting for bugs, look for features that are complex. As a rule of thumb: More complex = less secure. #BugBountyTips
11
76
383
@Bugcrowd
bugcrowd
4 years
Here are a few ways to make the most of an XSS. Comment if you can think of some other ideas or resources! Thread 👇.
18
132
391
@Bugcrowd
bugcrowd
7 months
. @InsiderPHD 's top bug bounty hunting tools of 2023 🚀 🔨 Burp Suite 🔧 Kiterunner 🪛 Shodan 🪚 Amass 🗜️ FFUF ⛏️ SQLMap 🪓 Frida 🔩 TruffleHog 🛠️ XSS Hunter Express ⚒️ Nuclei 🧰 Interactsh What would you add or remove from this list in 2024?
5
60
383
@Bugcrowd
bugcrowd
4 years
Nobody: Hackers in stock photography:
Tweet media one
19
67
367
@Bugcrowd
bugcrowd
3 years
In case you missed it, this Web Hacking Resources kit is here for you. 😎 What tools would you like to see added? 👇 #BugBountyTips
Tweet media one
8
117
365
@Bugcrowd
bugcrowd
4 years
Have you been lookin for a crash course on XXE bugs? It's a class of bugs often missed by even the most seasoned hackers. 🤓 Here is everything you need to know to start finding XXE bugs. Godspeed! Happy hacking!
7
152
367
@Bugcrowd
bugcrowd
4 years
Did you know: The term 'bug' (as it refers to computers) was first coined in 1947 when a group of computer scientists found an actual moth causing malfunctions in a computer.
14
66
352
@Bugcrowd
bugcrowd
3 years
What hacking tool does every hacker needs in their arsenal? Let us know 👇
105
69
355
@Bugcrowd
bugcrowd
4 years
Describe a hacker in just 4 words...
190
47
350
@Bugcrowd
bugcrowd
4 years
Hackers gonna hack. 🤓 💻
14
49
352
@Bugcrowd
bugcrowd
8 months
10 recon tools for bug bounty hunting in 2024 🪲🔍 1️⃣ Nmap 2️⃣ SecurityTrails 3️⃣ Amass 4️⃣ Dirsearch 5️⃣ subfinder 6️⃣ Httpx 7️⃣ GitHub code search 8️⃣ Google Dorks 9️⃣ Shodan 🔟 Censys What tools would you add to this list?
10
73
359
@Bugcrowd
bugcrowd
4 years
Looking to quickly dump URLs from a webpage using curl and some regex magic!? Try: curl -s https://www.bugcrowd[.]com | pcregrep -o "(http:\/\/|https:\/\/).*?(?=\"|'| )" | sort -u
Tweet media one
3
112
341
@Bugcrowd
bugcrowd
3 years
Keep up the good work researchers! 💪 🧡 💥
Tweet media one
8
19
325
@Bugcrowd
bugcrowd
1 year
"For me, the ninth month of the Islamic calendar, Ramadan, is the month to think about the blessings Allah has casted on me and my family, reflect on the year and act towards becoming a better Muslim." - Murtaza Haizji (Senior Manager Demand Gen) Ramadan Mubarak 🙏
Tweet media one
24
31
325
@Bugcrowd
bugcrowd
7 months
How to enumerate subdomains using Ffuf and SecLists! Just like you would fuzz directories but you put "FUZZ" at the start of the URL instead of at the end. ⌨️ ffuf -u FUZZ.<target> -w <wordlist>
Tweet media one
4
80
326
@Bugcrowd
bugcrowd
2 years
Too relatable 😂 😭
Tweet media one
11
37
318
@Bugcrowd
bugcrowd
3 years
What's something a non-hacker wouldn't understand? We'll go first: congratulating each other for finding bugs 🐛
65
18
311
@Bugcrowd
bugcrowd
3 years
New to bounties? We've created this page containing links to everything you need to know including free educational resources, researcher docs, how to find bugs, beginner resources, how to get private invites, and more. Login to view! #BugcrowdTipJar
2
114
318
@Bugcrowd
bugcrowd
2 years
Best wishes to all who are celebrating Eid 🌙 #EidMubarak #APAHM
Tweet media one
17
37
316
@Bugcrowd
bugcrowd
10 months
Want to win swag? 👀 Giveaway day 3: 🤝 Follow us @bugcrowd 👍 Like this post 📸 Reply with a picture of your workspace
143
19
313
@Bugcrowd
bugcrowd
4 years
If you ever find a SSRF on a Windows box, try running on your own VPS, then send the SSRF to file://<yourvps>. With a bit of luck, the server will send you some tasty Windows NetNTLMv2 hashes to crack! What are other methods do you use? #BugcrowdTipJar
5
78
318
@Bugcrowd
bugcrowd
2 years
🐜 🤝 💰
Tweet media one
4
38
309
@Bugcrowd
bugcrowd
24 days
Here's one for all you Google Dorks out there! 🤓 Try something like "© [COMPANY]. All rights reserved." to find new root domains!
Tweet media one
2
65
320
@Bugcrowd
bugcrowd
3 years
XSS is the most common bug class! It pays to be good at finding them. In the latest how-to blog post, @hakluke covers what XSS is, different discovery methods, contexts, filter bypasses, weaponized payloads, and more.
3
134
313
@Bugcrowd
bugcrowd
10 months
Share a little gratitude for our final giveaway 🧡 To enter: 🐜 Follow us @bugcrowd ⭐️ Like this post 🧵 Tag a hacker who's motivated you to keep hacking
211
25
307
@Bugcrowd
bugcrowd
4 years
Hacking is fun and all, but what are your hobbies outside of infosec?
163
16
300
@Bugcrowd
bugcrowd
4 years
While he hits some pretty big bounties, you might be surprised how @hunter0x7 got started in bug hunting. Join us for this researcher spotlight and down to earth chat with Ahsan Khan! #ItTakesACrowd
Tweet media one
25
34
298
@Bugcrowd
bugcrowd
4 years
Define "vulnerability" using only 4 words?
427
31
300
@Bugcrowd
bugcrowd
4 years
Roses are red. 🌹 P5's are blue. 5️⃣ Dups happen sometimes, 🐜 but they're valid bugs too! 🌟
8
40
286
@Bugcrowd
bugcrowd
5 years
What are the best resources for beginners? What do you recommend to hackers who are just starting out? We're all 👂👂👂
35
73
292
@Bugcrowd
bugcrowd
3 years
We've all been there... 🙃
Tweet media one
16
32
284
@Bugcrowd
bugcrowd
2 years
A meme a day keeps the blues away. 🔁 Retweet for meme 1 💙 Like for meme 2 ⚠️ We will choose one random participant to win SWAG! #BugBountyMemes by 👉 @thecryptohack3r
Tweet media one
Tweet media two
16
86
287
@Bugcrowd
bugcrowd
6 months
WOAHHHHHHHHHHH! congratulations!! 🐛💸👏
@fwrnr
Felipe Warrener-Iglesias
6 months
I was awarded $65,400 for my submissions on @bugcrowd #ItTakesACrowd The #bugbounty #bugbountytip here is turn off your testing mindset and turn on your vulnerability research mindset.
Tweet media one
58
39
712
4
14
287
@Bugcrowd
bugcrowd
4 years
When you find an XSS, at minimum, use alert(document.domain) over alert(1). This helps to demonstrate the context that the JavaScript is executing in. Even better, escalate the XSS to perform an account takeover! Don't forget to share your own XSS tips using #BugBountyTipJar
8
50
286
@Bugcrowd
bugcrowd
2 months
true story
Tweet media one
11
27
284
@Bugcrowd
bugcrowd
6 years
. @binance has launched a public #bugbounty program with @Bugcrowd ! Get all the new program details here: #OuthackThemAll
Tweet media one
31
82
241
@Bugcrowd
bugcrowd
11 months
Step 1: Go to your computer. Step 2: Start hacking. Step 3: Submit your bugs.
21
35
277
@Bugcrowd
bugcrowd
8 months
Do you have a New Year's resolution to start bug bounty hunting? Get a head start with @nahamsec 's HUGE list of resources for beginners: 🐞 Basics 🐛 Blogs & Talks 🐜 Books 🦟 Setup 🪲 Tools 🪳 Labs 🕷️ Talks 🐜 Coding 🦟 Mindset And more! 👇
4
87
275
@Bugcrowd
bugcrowd
2 years
We're giving swag, you're giving tips! Day 4 of #giveaways 🎁 👇 What's the best resource you've added to your #bugbounty library? 👀
133
47
275
@Bugcrowd
bugcrowd
4 years
Who inspired you in infosec during 2020? 🧐💻 #ItTakesACrowd
133
19
265
@Bugcrowd
bugcrowd
2 years
🚨
Tweet media one
11
25
269
@Bugcrowd
bugcrowd
4 months
. @insiderPhD 's 4 must have Burp Suite extensions:
Tweet media one
2
61
273
@Bugcrowd
bugcrowd
4 years
I'm gonna tell my kids they started Bugcrowd.
Tweet media one
7
24
266
@Bugcrowd
bugcrowd
2 years
Researchers, ⊂_ヽ   \\ we    \( ͡° ͜ʖ ͡°)     > ⌒ヽ    /   へ\    /  / \\appreciate    レ ノ   ヽ_つ   / /   / /|  ( (ヽ  | |、\you!  | 丿 \⌒)  | |  ) / ノ )  Lノ (_/ Have a great weekend. 😎
7
21
259
@Bugcrowd
bugcrowd
4 years
What does SQL stand for? Wrong answers only...
223
10
261
@Bugcrowd
bugcrowd
2 years
👋 Researchers! What's a hacking tool all beginners should be using? 🛠️ Asking for a friend! 🤭 #ItTakesACrowd
75
40
263
@Bugcrowd
bugcrowd
2 years
Today seems like a good day to watch YouTube 🥱 Tell us your favorite #hacker content creator and be entered to win a Pentesterlab Subscription!👇 Week of #giveaways day 2 🎁
220
29
261
@Bugcrowd
bugcrowd
2 years
New year, new swag, new game! Hacker's choice: THIS or THAT❓ Drop your choice below and be entered to win NEW swag! 👇 #MacintoshDay
Tweet media one
361
20
255
@Bugcrowd
bugcrowd
4 years
My mom when I told her to chews a secure password... #ItTakesACrowd
Tweet media one
7
35
255
@Bugcrowd
bugcrowd
3 months
What's your favorite bug type to find?
Tweet media one
37
22
261
@Bugcrowd
bugcrowd
4 years
Knowing regex is a very powerful skill for hackers. It allows us to be more productive, and also gives us an insight into how we might exploit Regex-based security controls. Read this blog by @hakluke to learn more!
Tweet media one
4
87
263
@Bugcrowd
bugcrowd
4 years
When the kombucha takes over...
Tweet media one
10
16
259
@Bugcrowd
bugcrowd
9 months
eLFI's back and on the hunt searching for your coolest hacker swag! 🎁 From keyboards to hoodies, what's been your favorite piece of #Bugcrowd swag over the years? 📸 To enter: 👉 Retweet + Like 👉 Reply with a pic of your swag #giveaway #eLFI
Tweet media one
89
104
254
@Bugcrowd
bugcrowd
3 years
API Tip 💡💡 💡 Thank you, @InsiderPhD 🙌 #bugbountytips
Tweet media one
1
58
257
@Bugcrowd
bugcrowd
2 years
ɹǝʞɔɐɥ ʎɹɐuıpɹoɐɹʇxǝ uɐ ǝɹ'noʎ ,sıɥʇ pɐǝɹ uɐɔ noʎ ɟı 👀 👀 👀
38
14
248
@Bugcrowd
bugcrowd
4 years
What people think I do vs what I actually do:
Tweet media one
10
34
250
@Bugcrowd
bugcrowd
2 years
We're dropping some #BugBountyTips 👉 Chain AutoRepeater and Taborator to Automate SSRF Findings. Created by: @bsysop 👏 Check the thread below for more details ⤵️
Tweet media one
10
78
248
@Bugcrowd
bugcrowd
8 months
Looking at getting into bug bounty hunting? Bugcrowd University is a ✨FREE✨ project to help you level-up your skills! Modules include: ✅ Making a Good Submission ✅ Burp Suite ✅ XSS ✅ Recon and Discovery ✅ SSRF ✅ XXE And more! Jump in 👇
7
71
251
@Bugcrowd
bugcrowd
3 years
Our hacking starter pack. What's yours? 👇
Tweet media one
Tweet media two
Tweet media three
Tweet media four
22
19
242
@Bugcrowd
bugcrowd
2 years
Want to WIN SWAG?🏆 Play the game!🎮 🔒Guess the password (26 letters) 🔢Numbers correspond to letters ✍️Example: 1 = A, 2 = B, 3 = C 🔑We'll drop a hint for every 100 likes 👇Comment your guess below, no letters allowed Hint: #StarWars #MayTheForceBeWithYou #WorldPasswordDay
Tweet media one
90
25
242
@Bugcrowd
bugcrowd
2 years
THIS or THAT ❓ Answer below, you could win that 😏
Tweet media one
272
12
241
@Bugcrowd
bugcrowd
4 years
A quick one-liner that will gather + crawl all subdomains, then convert to a custom wordlist unique to that organisation based on discovered URLs! subfinder -d bugcrowd[.]com -silent | httpx -silent | hakrawler -plain | tr "[:punct:]" "\n" | sort -u
0
81
247
@Bugcrowd
bugcrowd
2 years
🚨CHALLENGE TIME🚨 Can you popup an alert?😉 Rules⤵️ 📣DM us a screenshot once complete 📣100 likes & we'll release a hint 15 winners⤵️ 🥇5 winners: hoodies 🥈5 winners: t-shirts 🥉5 winners: stickers + glasses GO 👉 Challenge by @MRCodedBrain
Tweet media one
29
38
245