bugcrowd

26.5K posts

bugcrowd banner
bugcrowd

bugcrowd

@Bugcrowd

The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™

San Francisco, CA 加入时间 Eylül 2012
6.1K 关注196.1K 粉丝
bugcrowd
bugcrowd@Bugcrowd·
Let’s check your database knowledge. query = "SELECT * FROM users WHERE id = " + userId Replace string concatenation with ________ to prevent SQLi A) query = f"SELECT * FROM users WHERE id = {userId}" B) query = "SELECT * FROM users WHERE id = " + escape(userId) C) cursor.execute("SELECT * FROM users WHERE id = %s", (userId,)) D) query = "SELECT * FROM users WHERE id = " + str(int(userId)) Bonus: Why are the others still injectable?
English
2
0
10
1.7K
bugcrowd
bugcrowd@Bugcrowd·
📢 April 16 at 11am ET: bugcrowd.com/webinar/?commi…{{lead.Id}}&utm_source=x&utm_medium=organic_social Join Bugcrowd, CISA VDP, and public sector security leaders for a Q&A on the impact of FedRAMP Moderate authorization. Hear from Kent Wilson, Trey Ford, and Shondalyn Smith on what this means for vulnerability disclosure, operational rigor, and proactive security across government and beyond. 🎙️🔥
English
1
0
1
970
bugcrowd
bugcrowd@Bugcrowd·
The average cost of a breach for financial institutions is $6 million 💸 Crowdsourced security helps financial services organizations bring in specialized expertise on demand, extend internal teams, and support compliance efforts through solutions like bug bounty, penetration testing, and vulnerability disclosure programs. ☝️ In fact, 96% of ethical hackers agree these programs help fill cybersecurity skills gaps. We’re letting you in on a few secrets in this blog: bugcrowd.com/blog/5-tips-to…
English
0
0
2
779
bugcrowd
bugcrowd@Bugcrowd·
The security world spent a decade obsessed with finding bugs faster. We succeeded, but now we have a massive bottleneck at the finish line. 🏁 AI finds vulnerabilities in seconds, but a human still has to ship the patch. When a maintainer is buried under 40 reports on a Friday, speed of discovery feels like noise. As Bugcrowd's Trey Ford notes, we optimized the wrong end of the pipe. It is time to value the fix as much as the find. 💯 Read the full analysis: darkreading.com/application-se…
bugcrowd tweet media
English
3
11
59
4.4K
bugcrowd
bugcrowd@Bugcrowd·
Save this for later🔖 What's your take?👇
English
0
0
4
662
bugcrowd
bugcrowd@Bugcrowd·
👉Test for mass assignment: - Add unexpected fields in requests - Modify existing parameters - Observe changes in behavior For example, you could add the following field when updating your user profile: {   "isAdmin": true }
English
1
0
3
734
bugcrowd
bugcrowd@Bugcrowd·
Broken Object Property Level Authorization (BOPLA) occurs when APIs fail to properly restrict access to specific properties within an object. Think of it as IDOR, but targeted at individual properties rather than the entire object. 👇🧵
bugcrowd tweet media
English
2
8
42
2.9K
bugcrowd
bugcrowd@Bugcrowd·
When VulnCon winds down, come hang with us! 🤙 We’re bringing the Bugcrowd community to The Canal Club for patio vibes, drinks, bites, and conversations that just might be the highlight of your trip. We’ll see you tomorrow, April 14, at 6:30pm! 🔗 Register here: luma.com/u3ceyli8
English
0
0
3
855
bugcrowd
bugcrowd@Bugcrowd·
AI agents are increasingly being used by some users to create a huge volume of low-quality, unverified submissions. We call this “sloptimism,” overly optimistic submissions driving large volumes of speculative or AI-generated reports.
bugcrowd tweet media
English
8
11
151
7K
bugcrowd
bugcrowd@Bugcrowd·
Sure, you 𝙘𝙤𝙪𝙡𝙙 read the whole 50-page Inside the Mind of a Hacker report. But if hearing the top insights live from Bugcrowd CEO Dave Gerry, while also getting networking and drinks, sounds better... this is your sign 😎 Join us at the GeoCyclone event in London on April 23: luma.com/qmh8uc6e
bugcrowd tweet media
English
0
2
7
1.5K
bugcrowd
bugcrowd@Bugcrowd·
Offensive testing is the theme Hackers search for bugs upstream A preemptive approach The attacker’s reproach Extends the reach of your security team. 🎤 🫳 🥵 And on that note, happy Friday! If you're into poems, we have plenty: bugcrowd.com/blog/10-cybers…
English
0
1
15
1.6K
bugcrowd
bugcrowd@Bugcrowd·
Conclusion: Authorisation must always be enforced server-side per object. Obscurity like UUIDs or frontend controls aren't enough.
English
0
1
5
766
bugcrowd
bugcrowd@Bugcrowd·
Even if IDs are non-sequentials (UUIDs), BOLA can still exist. Attackers often extract ID from: - API responses - Logs - Public Endpoints and reuse them across endpoints
English
1
1
5
783
bugcrowd
bugcrowd@Bugcrowd·
Broken Object Level Authorization (BOLA) is one of the most critical API vulnerabilities, and it consistently ranks at the top of OWASP API risks. Occurs when API fails to verify whether a user has permission to access a specific object.
bugcrowd tweet media
English
3
8
68
3.8K