Bug Bytes #177 – Hackers descend on Ahmedabad, the hardest CTF and tales of easy P1s
By travisintigriti
October 12, 2022
Last updated on August 8, 2026
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by InsiderPhD. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources.
This issue covers the weeks from October 2nd until October 8th.
Intigriti News
From my notebook
Hackers this week descended on the city of Ahmedabad in India for BSides, now I’ve never been myself, but I will admit to some FOMO seeing all the hackers on twitter, thankfully IamVaaman has us covered with his video sharing some of the highlights while we wait for the official videos!
While the videos for BSides Ahmedabad 2022 are not out yet, we do have some slides from various creators. Here are the ones I could find on Twitter this week:
Wondering what it was like on the ground? Check out this vlog: This is what hackers do at a hacker con – IamVaaman
Inspired by BSides? pmnh reflects on 2 years of Bug Bounty hunting – This is a great article with some great advice for would-be bounty hunters
Other Amazing Things
NullCon Cybersecurity Interview: Rohit (Security Zines) – Hacking Simplified
The hardest CTF task I’ve ever done – Bug Bounty Reports Explained
Open Source Security – Let’s chat about Let’s Encrypt with Josh Aas
The Hacker Factory Podcast – From Developer To Cybersecurity
Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style
IDOR in GraphQL Query Leaking Private Photos of a Million $ App
You may also like
July 31, 2026
Intigriti Bug Bytes #238 - July 2026 🚀
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much mo
June 26, 2026
Intigriti Bug Bytes #237 - June 2026 🚀
Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo SolarWinds at scal
May 30, 2026
Intigriti Bug Bytes #236 - May 2026 🚀
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a sani