Home / Companies / Bugcrowd / Blog / April 2021

April 2021 Summaries

6 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
Draft Submissions and Autosave enhancements have been added to the submission process on Bugcrowd, allowing researchers to save their submissions as drafts and autosave them every 30 seconds. Researchers can now find their drafts using a tokenized search feature in the Submission index. Drafts can be deleted by clicking the "Delete" button next to the "Save draft" option in the footer. Collaborators cannot see draft submissions until they are invited and accepted, and there is no advantage to opening multiple drafts to try and game the system. The new features aim to provide researchers better control over their submission workflow and prevent losing submitted details due to connection or computer failures.
Apr 27, 2021 778 words in the original blog post.
A crowdsourced cybersecurity program's output typically decreases over time due to the "program aging" effect, where the initial chaotic period of finding numerous vulnerabilities calms down as low-hanging fruit is picked and many researchers move on. To address this, it's essential to understand that researchers optimize for return on investment (ROI) and will participate in programs with higher relative value and lower time investment. Increasing the sample size of testers can help validate against the average crowd Pp threshold, but going public is the most effective way to engage the entire security community. High-value testers have higher Pp thresholds, and focusing exclusively on critical findings can diminish ROI and reduce overall engagement. Reviewing the sample size, relative value, and potential rV are crucial first steps in addressing diminishing output, with adjustments needed every 30 days or 60 days after three consecutive raises, depending on priority levels.
Apr 27, 2021 2,723 words in the original blog post.
The LevelUp virtual conference is now open for submission of talk ideas. It features high-quality technical presentations by members of the hacker and infosec community, covering a range of topics such as API & Mobile, Recon techniques, Hardware Hacking, Testing methodologies, and Soft career developing skills. The event series offers an opportunity to network with researchers, participate in CTF challenges, and enjoy good jokes. Presentations are welcome on various subjects, including professional and personal development, and should last between 20-50 minutes. The conference aims to provide a platform for bug hunters and researchers to develop new skills and knowledge.
Apr 19, 2021 359 words in the original blog post.
The Bugcrowd Incentive Programs offer various ways for researchers to earn swag, including the MVP Program, P1 Warrior Incentive Program, Bugcrowd Scholar Program, Surprise & Delight Program, and Bugcrowd Challenges & Events. The MVP Program rewards researchers with progressive tiers of awards based on their accuracy rate and priority percentile scores, while the P1 Warrior program rewards those who submit valid P1 vulnerabilities. The Bugcrowd Scholar Program provides educational resources and scholarships to help build careers in security. The Surprise & Delight Program offers unique swag opportunities based on researcher activity and achievements. Bugcrowd Challenges & Events provide limited-run swag through special events and social giveaways. Researchers can stay up-to-date with the latest programs by bookmarking this page or following Bugcrowd's Twitter account.
Apr 16, 2021 1,033 words in the original blog post.
As a pentester with web development experience and OSCP certification, the author initially struggled to find bugs in bug bounty programs, which he had expected to be an easy side hustle. However, after attending a security meetup and meeting Shubs (@infosec_au), who spoke about using automation to discover ephemeral bugs and interesting targets, the author's approach changed significantly. He realized that as a pentester, he was paid for his time, whereas in bug bounty hunting, he was paid for impact, which meant altering his hacking style to focus on finding unique and impactful bugs rather than following established methodologies. The key takeaways include focusing on gaps in coverage, using automation to scale out efforts, performing continuous monitoring and testing, and leveraging creativity and experimentation to find novel bugs.
Apr 10, 2021 1,429 words in the original blog post.
Hacking requires a significant amount of prerequisite knowledge that goes beyond just knowing how to use the Internet normally. The author reflects on their own learning journey, realizing that understanding the basics of web applications, web servers, HTTP, SSL, TCP/IP, and DNS is crucial for hacking. However, it's not necessary to have in-depth knowledge of every concept; rather, having a broad shallow knowledge of everything can be beneficial. This approach allows for Just-In-Time Learning, where new skills or concepts are learned as needed. The author emphasizes the importance of foundational knowledge, which serves as the foundation for more advanced knowledge and creativity. With strong foundational knowledge, hackers can recognize dangerous edge cases, chain vulnerabilities together, and uncover more bugs with higher severities. Ultimately, gaining foundational knowledge is essential for hacking success.
Apr 03, 2021 1,330 words in the original blog post.