tal
195 posts


Very fast man @RelentlessT7
Triaged p1 within 1 minute after submit
@Bugcrowd
#bounty #bugbountytips #BugBounty #CyberSecurity #EthicalHacking #InfoSec #BugHunter #SecurityResearcher #WebSecurity #HackThePlanet #Pentest #bugbountytips #fulltimebughunter #shahwarshah #money

English

Not a big poster here, but wanted to give a huge shoutout to @RelentlessT7 and Jan, two of the best triagers @Bugcrowd team! Thanks for the super quick responses and support on my reports. Appreciate you both and the whole Bugcrowd team 🖤


English

@XHackerx007 @Bugcrowd @Masonhck3571 This is such a unique and excellent news, congratulations and to way more. Happy to be part of this incredible journey 🙏🏻 🔥
English

I did it—$1 million on @Bugcrowd
For a lot of people this might be a small achievement, but for me, I’ve been waiting for this!
Do you know the most important tip in bug bounty? Choose one favorite program and spend years working on it. That’s my way. I’ve been working on the same program for about 3–4 years—every day on the same program. When I get bored or can’t find anything, I switch to another program until I find a bug, then I go back to my favorite program again.
After 3–4 years of hunting the same program, this helped me understand the team’s weak points. For example, they often ship ASMX/SVC endpoints without securing them, and they sometimes leave backup files in the web app, etc. With this approach, I made more than $750K from that one program alone!
Another tip—my personal rule—is: when I hunt a new program, I never leave or give up until I find a P1 or P2. If you make that deal with yourself, you’ll be unstoppable!
Believe me, these two tips are the keys to success in bug bounty that few people talk about.
Finally, huge thanks to the @Bugcrowd team for their support—I really love that team. Thanks to @RelentlessT7,
Timmy_Bugcrowd, @Masonhck3571, and all the triagers! Also thanks to FIS Global and their lovely security team!
Your turn now to make $1M—you can do it!
#ItTakesACrowd #CyberSecurity #infosec #redteam #BlueTeam #BugBounty #bugbountytips #bugbountytip #HackerCommunity #Bugcrowd

English

My sticker collection just got a major boost. 🤩 This swag is top-tier. Thank you @bugcrowd
@caseyjohnellis @codingo_ @vortexau @RelentlessT7 @raven_rou @trimkadriu @amalmurali47 @davegerryjr @mikepatx @drunkrhin0 #Ittakesacrowd #OuthackThemAll #BugBounty

English
tal retweetledi

TOOL RELEASE🔥🚀
Clear reports and good communication with the teams can make the difference in the outcome of your report, including the final bounty/bonus.
To assist you in the reporting and communication, here is CrowdAssist ✨.
@Bugcrowd compatible.
🧵👇
#BugBounty #AI



English

Thank you @Bugcrowd team, for the support on my recent submission! Appreciate all the work from @RelentlessT7 and the support team.
Awarded a $3500 bounty for a P1 submission. 🙌
English
tal retweetledi

Many don’t realize they already have a powerful, fully autonomous, free hackbot on their computer.
If you’re using Cursor, you’ve got it.
Here's Cursor solving a @PortSwigger webacademy SQL injection lab! #bugbounty
English

@RelentlessT7 @Bugcrowd Ha, it is you! Cheers mate 🧡
English

Just got some really nice feedback from @Bugcrowd on one of my #BugBounty submissions 🧡
Bonus point: Looks like I'm safe from AI 😂

English
tal retweetledi
tal retweetledi

Ever had triage issues after losing the final CRLF when copying an HTTP request? I discussed this with @albinowax a while ago, and the latest Burp release now flags missing blank lines automatically! #bugbounty

English

Guess who this was? I was talking about my great friend chivato aka @SecGus 😁
bugcrowd@Bugcrowd
Hacking or Socializing? The LHE dilemma (with @insiderPhD and @_godiego__)
English

Super happy to see our research ranking #3 in @PortSwigger Top Web Hacking Techniques of 2024! 🚀
This one was a wild ride!
Huge thanks to @_medusa_1_ & @sw33tLie for the amazing teamwork and to @Bugcrowd, who supported us! ❤️
What next? Keep tuned 👀🥷🏻
#BugBounty #Hacking
PortSwigger Research@PortSwiggerRes
The results are in! We're proud to announce the Top ten web hacking techniques of 2024! portswigger.net/research/top-1…
English
tal retweetledi

@bishopfox @owasp @hahwul 🎉 Celebrate
@0x10n gifts $462K @GoogleVRP bounty to @picoctf
@Vivek23647571 received $10K bounty from @GoogleVRP
@RelentlessT7 promoted to Staff ASE at @Bugcrowd
@Samm0uda and team received $250K bounties from @Meta (@phwd_, @JosipFranjkovic, and @vulnano)
English

More than deserved🎉
tal@RelentlessT7
Some exciting personal news: I’ve leveled up to Staff ASE at @Bugcrowd from my previous role as Senior ASE. Huge thanks to my amazing colleagues and the researcher community! It’s an absolute pleasure doing what I do, and I’m already pumped to tackle the next set of goals!
English

Some exciting personal news: I’ve leveled up to Staff ASE at @Bugcrowd from my previous role as Senior ASE. Huge thanks to my amazing colleagues and the researcher community!
It’s an absolute pleasure doing what I do, and I’m already pumped to tackle the next set of goals!
English
tal retweetledi

Bronxi's bringing you all the best tips on Web Cache Deception 101 📚
With real-life examples and everyday parallels, the method to understanding caching has never been easier. Watch now! 🤓 ⤵️
youtu.be/rPUt72QB_hg?si…
#WebCache #WebCacheDeception #Bugcrowd #BugBounty #Cybersecurity #Hacking

YouTube
English

