Bug Bytes #177 – Hackers descend on Ahmedabad, the hardest CTF and tales of easy P1s
By travisintigriti
October 12, 2022
Last updated on March 6, 2025
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by InsiderPhD. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources.
This issue covers the weeks from October 2nd until October 8th.
Intigriti News
From my notebook
Hackers this week descended on the city of Ahmedabad in India for BSides, now I’ve never been myself, but I will admit to some FOMO seeing all the hackers on twitter, thankfully IamVaaman has us covered with his video sharing some of the highlights while we wait for the official videos!
While the videos for BSides Ahmedabad 2022 are not out yet, we do have some slides from various creators. Here are the ones I could find on Twitter this week:
Wondering what it was like on the ground? Check out this vlog: This is what hackers do at a hacker con – IamVaaman
Inspired by BSides? pmnh reflects on 2 years of Bug Bounty hunting – This is a great article with some great advice for would-be bounty hunters
Other Amazing Things
NullCon Cybersecurity Interview: Rohit (Security Zines) – Hacking Simplified
The hardest CTF task I’ve ever done – Bug Bounty Reports Explained
Open Source Security – Let’s chat about Let’s Encrypt with Josh Aas
The Hacker Factory Podcast – From Developer To Cybersecurity
Melting the DNS Iceberg: Taking over your infrastructure Kaminsky style
IDOR in GraphQL Query Leaking Private Photos of a Million $ App
You may also like
June 26, 2026
Intigriti Bug Bytes #237 - June 2026 🚀
Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo SolarWinds at
May 30, 2026
Intigriti Bug Bytes #236 - May 2026 🚀
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a
April 24, 2026
Intigriti Bug Bytes #235 - April 2026 🚀
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising an NPM package with 40M weekly downloads Bypassing Cloudflare WAF for a full ATO 20-part series on exploiting JWT vulnerabilities First Intigriti Bug Bounty Meetup And so much more! Let's dive