❓ How can bug bounty programs …
1️⃣ Keep hackers engaged in the long term?
2️⃣ Effectively increase the amount of good quality reports that you receive?
3️⃣ Stand out from competition and be the program that hackers choose to hack on?

📽️ In this video, I covered 5 tips that can allow any bug bounty programs to stand out from the rest. If you implement them, you can expect an increased participation from skilled and good hackers (or security researchers) and a consistent stream of valuable vulnerability submissions! Most importantly, are you ready to handle the resulting high quality reports? 😊

🫵 Hackers, if these tips hit the mark, please share them with your favourite bug bounty programs! Your input could lead to improvements like loyalty programs and direct report submissions (skip platform analysts or triage teams). Let's level up the bug bounty landscape together! 😎

⬇️⬇️⬇️

https://youtu.be/msr-7ZtmLdE

#bugbounty #bugbountytips #togetherwehitharder #hackerone #ittakesacrowd #outhackthemall #bugcrowd #bugcrowdtipjar #hackwithintigriti #intigriti #yeswehack #yeswerhackers #ethicalhacking #whitehat

5 Tips for Boosting Long-Term Engagement in your Bug Bounty Program

YouTube

#20 Vulnerable Snippet {{ solution }} ☑️

See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/

Bug: SQL injection 💉
Lang: PHP 🐘, MySQL 🐬

Check out the explanation in the image below!👇
#YesWeRHackers #BugBounty #YWHSnippet

Hunter stories from cyberspace - YesWeRHackers - Global Bug Bounty Platform

YesWeHack is a sound statement: Yes We Hack, we love that. It is our motto and we don't diverge. #yesWeRHackers.

Global Bug Bounty Platform

Vulnerable Code Snippet 💀
Level: Easy 🪲

Does it only work once?!

For all #BugBounty hunters, it is available on Github for hands-on testing! 👉 https://github.com/yeswehack/vulnerable-code-snippets/tree/main/new

#YesWeRHackers
Found the issue? Explain how in the comments! 👇

vulnerable-code-snippets/new at main · yeswehack/vulnerable-code-snippets

Twitter vulnerable snippets. Contribute to yeswehack/vulnerable-code-snippets development by creating an account on GitHub.

GitHub

#19 Vulnerable snippets solution! ☑️

See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/

Github repo updated as usual!
➡️https://github.com/yeswehack/vulnerable-code-snippets

Vuln: Open Redirect ⛔️
Lang: JavaScript ⚡️

Check out the explanation in the image below!👇
#YesWeRHackers #BugBounty #YWHSnippet

Hunter stories from cyberspace - YesWeRHackers - Global Bug Bounty Platform

YesWeHack is a sound statement: Yes We Hack, we love that. It is our motto and we don't diverge. #yesWeRHackers.

Global Bug Bounty Platform

Vulnerable code snippets time!💀
Level: Easy 🪲

~ [#]vulnerable..?

Try it out at Github: https://github.com/yeswehack/vulnerable-code-snippets/blob/main/new/vcode/19-new.php

#BugBounty #YesWeRHackers
Found the bug? Explain how in the comments! 👇

vulnerable-code-snippets/19-new.php at main · yeswehack/vulnerable-code-snippets

Twitter vulnerable snippets. Contribute to yeswehack/vulnerable-code-snippets development by creating an account on GitHub.

GitHub

Pimp My Burp #7 is out! 🥷

We take a dive into the Burp extension HaE! 🤯

This extension can detect custom regex patterns and highlight them for you so you don't miss the juicy bugs!

Find out more 👉 https://blog.yeswehack.com/yeswerhackers/pimpmyburp/pimpmyburp-7-how-hae-burp-suite-extension-help-you-daily-hunting/

#YesWeRHackers #bugbountytips

PimpMyBurp #7: How HaE Burp Suite extension can help you in your daily hunting session

The Burp Suite extension Highlighter And Extractor (HaE) makes it possible to collect, categorise and highlight requests and/or responses according to their content.

Global Bug Bounty Platform

#18 Vulnerable snippets solution! ☑️

Congrats @[email protected]!
See you in DM for the swag 🎁

See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/

Type: Local File Inclusion
Lang: PHP🐘

Check out the explanation in the image below! 👇
#YesWeRHackers #YWHSnippet

Hunter stories from cyberspace - YesWeRHackers - Global Bug Bounty Platform

YesWeHack is a sound statement: Yes We Hack, we love that. It is our motto and we don't diverge. #yesWeRHackers.

Global Bug Bounty Platform

Vulnerable Code Snippets Time 🥷
Level: Medium 🐝

This web application does not like dot dot slash!

Try it out at Github: https://github.com/yeswehack/vulnerable-code-snippets/tree/main/new

#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments! 👇

🎁 The best solution gets an exclusive swag!

vulnerable-code-snippets/new at main · yeswehack/vulnerable-code-snippets

Twitter vulnerable snippets. Contribute to yeswehack/vulnerable-code-snippets development by creating an account on GitHub.

GitHub

⏰ DOJO Challenge #21 - EvilTwin-Admin

🎁 Top 3 reports win a swag pack!
🗓️ Submit your solution before 10/02/2023

Check it out here 👉 https://dojo-yeswehack.com/practice/4401d46f16b6

#BugBounty #YesWeRHackers #YWHDOJO

YesWeHack Dojo

#17 Vulnerable snippets solution! ✅

🎁Congrats @[email protected]! See you in DM for the swag

See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/

Type: Deserialization of Untrusted Data
Lang: Python 🐍

Check out the explanation in the image below!👇
#YesWeRHackers #YWHSnippet

Hunter stories from cyberspace - YesWeRHackers - Global Bug Bounty Platform

YesWeHack is a sound statement: Yes We Hack, we love that. It is our motto and we don't diverge. #yesWeRHackers.

Global Bug Bounty Platform