Home / Companies / Bugcrowd / Blog / September 2020

September 2020 Summaries

13 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
Skyscanner's bug bounty program is an attractive opportunity for researchers with skills in e-commerce flows, creative exploitation of vulnerabilities, and high-impact business logic vulnerabilities. The program covers various areas, including its mobile apps, website, and subdomains, offering higher rewards for findings in focus areas. Researchers are encouraged to do reconnaissance of the entire platform, making it a great chance to enhance their skills and make extra money. The first submitted report of a vulnerability will receive monetary rewards, and additional resources are available for learning more about e-commerce flows and improving skills.
Sep 30, 2020 306 words in the original blog post.
Tomnomnom is a well-known bug bounty hunter who sets himself apart from others by his ability to quickly develop tools for bug bunting, which he attributes to his quick turnaround time and willingness to learn and adapt. He emphasizes the importance of writing tools early on in one's journey, getting familiar with Burp Suite, and not relying solely on code to succeed. Tomnomnom also stresses the value of community resources, particularly Twitter, in sharing knowledge and tools among bug bounty hunters. He believes that having a strong foundation in command-line skills is essential for success in bug bunting.
Sep 27, 2020 1,305 words in the original blog post.
Bugcrowd is excited to announce a Cybersecurity Awareness Month Program Challenge in October. Researchers can participate by completing one or all four weekly challenges, which offer increasingly valuable rewards for submitting qualifying reports. The first 100 researchers with an unresolved or resolved P3 bug will receive a limited edition Bugcrowd shirt, while the next 50 will get a Bugcrowd hoodie. Later weeks' challenges will award even more exclusive items such as JBL headphones and a Bugcrowd keyboard. The final challenge will award the top 10 report writers with impactful bug fixes. Researchers can sign up for a Researcher account to participate and submit their findings, with rewards shipped after the blog announcement in November.
Sep 25, 2020 369 words in the original blog post.
The use of crowdsourced security testing has increased in recent years, with many organizations turning to this approach as a way to improve the efficiency and effectiveness of their security testing. However, there are still misconceptions surrounding crowdsourced security testing that can hinder its adoption. Bugcrowd aims to address these concerns by offering a viable alternative to traditional pen testing, leveraging a combination of automation and human intuition to out-hack attackers. The company's platform has been designed with trust in mind, utilizing vetting processes such as background checks and ID verification to ensure the credibility of researchers. Additionally, Bugcrowd offers crowdsourced network pen tests that provide dedicated resources for structured, methodology-driven testing, addressing concerns around auditor acceptance and the scope of testing targets. By partnering with certified QSCA firms, Bugcrowd ensures alignment with compliance standards, providing a comprehensive solution for organizations seeking to improve their security posture.
Sep 23, 2020 1,084 words in the original blog post.
Noticing anything new lately? We have been making major improvements to the Researcher experience on the Bugcrowd platform. Some of these changes enhance the profile design and workflow for users. Others offer new ways to show us who you are outside of the platform. Our two newest additions are enhancements to the Researcher profile: Resumes and Profile Layout Updates, which aim to provide better-tuned opportunity suggestions by utilizing data on a Researcher's skills, interests, experiences with Bugcrowd or security in general, alongside their past activity on the platform. The new Resume section allows Researchers to tell us about their skills and accomplishments in Information Security and beyond, while the Profile Layout Changes include a new profile banner that enables Researchers to express themselves through images. These changes are part of a larger goal to create a place where Researchers can consolidate and showcase all of their security talents, skills, interests, and wins.
Sep 19, 2020 369 words in the original blog post.
Ahsan Khan, a full-time bug hunter, has been in this field for almost 5 years, honing his skills and finding incredible vulnerabilities. He attributes his interest in cybersecurity to a friend who hacked his computer, leading him to learn about hacking through online tutorials and articles. Ahsan started with easy-to-hunt programs and gradually moved on to bounty programs, impacting his life by providing financial stability and motivating him to work hard. He spends around 12-18 hours per day hunting bugs and has found that a strong mindset and persistence are key to success. Ahsan recommends starting with simple bugs, learning the basics, and using resources like PortSwigger Labs and PentesterLab for advanced techniques.
Sep 18, 2020 717 words in the original blog post.
Bugcrowd has introduced a new feature called Discovery, which aims to improve the visibility of program offerings by providing a new way to sort through and find program recommendations. The Just For You recommendation engine uses platform data and linked profiles to provide personalized suggestions based on individual interests and skill sets. There are also three groups: Experts Needed, Try Something New, and From your Github activity, each offering unique challenges and opportunities for researchers. Additionally, a Featured section allows users to discover programs with specific target types or coordinated disclosure, and Bugcrowd plans to expand the feature of connecting GitHub accounts to researcher profiles in the coming months. The Discovery page is now available for users to explore and find new program recommendations.
Sep 16, 2020 450 words in the original blog post.
When searching for a web application pen test provider, it's essential to evaluate potential vendors beyond price, considering factors such as the quality of their testing talent, speed of launch, time to results, reporting capabilities, and ability to integrate with existing workflows. A large talent pool is beneficial, but only if there is a mechanism in place to quickly match requirements to skill and availability. Additionally, customers should ask about the provider's experience with remote work and ensure they can manage a fully remote team, vetting and assessing their activities and performance. By asking these questions, organizations can find a vendor that meets their specific needs and ensures rapid, reliable penetration testing.
Sep 15, 2020 934 words in the original blog post.
Researchers can now generate backup codes for Two-Factor Authentication (2FA) on their Bugcrowd Accounts, allowing them to reset their accounts without needing to contact the support team. This update adds an extra layer of security to Bugcrowd Researcher accounts, requiring two means of identification before granting access. Researchers can enable or disable 2FA by going into their Account Settings and clicking on the “Security” tab in their Researcher profile. When 2FA is enabled, backup codes are generated to help reset the account without assistance from the support team. If researchers lose their device or forget their authentication credentials, they can use these backup codes to regain access to their accounts.
Sep 11, 2020 301 words in the original blog post.
Hx01, a Bugcrowd researcher, shares his journey into cybersecurity, starting with learning phishing at age 12 and being motivated by Orange Tsai's writeup on Remote Code Execution. He started hunting bugs in late 2016 but left for two years before returning in July 2019. Hx01 now hunts part-time, spending around 10-15 hours a week, and aims to earn over $500,000 on Bugcrowd by age 21. He credits Bugcrowd's Triage team and support for his continued participation, and shares tips such as reading documentation and practicing vulnerability classes to improve skills. Hx01 emphasizes the importance of persistence, even in the face of duplicates or N/A's, and encourages new hackers to join the community.
Sep 10, 2020 703 words in the original blog post.
We recently hosted a virtual event called LevelUp0x07, which took place on August 22nd and 23rd. The event aimed to benefit the community-at-large and relied heavily on the support of attendees. It featured various activities such as Twitter puzzles, swag challenges, talks, and a CTF Challenge to defeat The Matriarch. The event also included a Secure Code Warrior Tournament and was made possible by the contributions of incredibly talented speakers who shared their knowledge and experiences with the audience. While two speakers were unable to attend due to personal circumstances, they will be featured in upcoming breakout sessions. The event has concluded, but its legacy lives on through the community's continued conversation, which can be joined by signing up for the Discord channel.
Sep 03, 2020 388 words in the original blog post.
The P1 Warrior Program has announced its Q2 winners, recognizing researchers who submitted impressive reports of valid P1 submissions since January 1, 2019. The program rewards researchers for their contributions to improving the security posture across various industries. This quarter saw a great number of submissions, with Level 5 Warriors earning over 50 P1s and Level 3 Warriors earning between 10+ and 5+ P1s. The winners are listed in a tiered system, with Level 2 Warriors receiving 5+ P1s and some researchers earning as few as one valid submission. The program aims to encourage researchers to continue their work in identifying and reporting security vulnerabilities.
Sep 02, 2020 361 words in the original blog post.
Our researchers achieved a significant milestone, earning more MVPs than any other quarter in the history of their platform. This was made possible by both longstanding crowd members and new researchers who showcased their talent, with many achieving MVP status for the first time. The MVP Incentive Program recognizes hackers who consistently deliver high-quality submissions, requiring them to maintain a high average accuracy rate, achieve priority percentile ranges above 80%, submit at least four qualifying submissions, and have no significant enforcement infractions. To celebrate their achievements, winners receive exclusive swag rewards. The program aims to encourage the Crowd's continued excellence in Q3.
Sep 01, 2020 471 words in the original blog post.