Researchers’ blog
Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.
Bug Bytes #168 – Behind The Tool, NotGitBleed & Custom Transport Encoding in Burp
Bug Bytes
April 20, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Bidirectional API Integration at a Glance
Product Updates
April 20, 2022
As an organization you want to optimize your time as much as possible and a lot of our customers were doing this by automating their bug bounty program through Intigriti’s external API. Forwarding submissions to internal ticketing systems such as for example JIRA or automated posting with every new
Bug Bytes #167 – AWS RDS Local File Read & Are you making these learning mistakes or misusing Burp’s predefined lists?
Bug Bytes
April 13, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Empower your security team to build stronger defenses against cybercriminals [Interview]
Hacker Spotlight
April 6, 2022
This interview originally appeared in Cybernews in April 2022. Trusting your cybersecurity team to identify vulnerabilities in your company’s security systems is vital. However, you’ll likely sleep better at night by getting a second look from an outsider. Such is the work that bug bounty hunters (e
Bug Bytes #166 – Double-edged SSRF, ToolTime & Fun hackers stories
Bug Bytes
April 6, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Bug Bytes #165 – Spring4Shell, CDN WAF bypass & Practical cryptography for pentesters
Bug Bytes
March 31, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Collaboration makes you better!
Product Updates
March 28, 2022
Researcher collaboration is essential to ensure the success of a bug bounty program. Quality, creativity and impact are often achieved by working together and exchanging technical know-how. Live events and live communication tools, like our Discord community, showed us the increased popularity and i
Bug Bytes #164 – New Collaborator domain, BITB attack & XSS to RCE on an almost static site
Bug Bytes
March 23, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
7 ways bug bounty programs can help drive the security development lifecycle
News
March 18, 2022
Software Development Lifecycles (SDLCs) today have to take a huge number of security and privacy realities into consideration with every release — and with the widespread adoption of agile methodologies, release cycles have become more frequent. Such rapid, large-scale change in how software is prod
Bug Bytes #163 – Uber Eats payment bypass, Mystery lab challenge & 1337Up livestream
Bug Bytes
March 16, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Bug Bytes #162 – How to read RFCs, Param Miner doc & SSRF with browser exploitation
Bug Bytes
March 9, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
3 female hackers inspiring the next generation of infosec talent
Hacker Spotlight
March 8, 2022
It’s no secret that there is a shortage of female hackers. Being part of this world, we understand this better than anyone. Within the bug bounty community alone, 95% of hunters are male—but we’re here to change that. One way we can help diversify the industry is to influence the next generation of
Bug Bytes #161 – Java Tomcat challenge, LFI via Markdown & Nuclei + Burp = Love
Bug Bytes
March 2, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Turbo Intruder – Hacker Tools: Going faster than ever! 👩💻
Hacking Tools
March 1, 2022
How often do you find yourself running scans that take ages to complete? How often do you cancel a scan because it has been taking too long? But what if you left it to run for 3 more minutes? Would that have given you a breakthrough result? Today, we’re going to go fast, really fast! Let’s take a lo
Bug Bytes #160 – Invisible SQL Injection, Reading redacted text & Coinbase’s largest-ever bug bounty
Bug Bytes
February 23, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
How ethical hackers can help to increase your attack surface visibility
News
February 21, 2022
200 years after the first design for a Panopticon, some security experts still dream of safeguarding the security of an entire institution from a single, centralized viewpoint. They are looking in the wrong direction. Cybersecurity teams who want to achieve comprehensive attack surface visibility sh
Bug Bytes #159 – GitBleed, BigQuery SQL injection & Salesforce Recon and Exploitation Toolkit
Bug Bytes
February 16, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
3 ways ethical hackers can help reduce cybersecurity skills gaps
News
February 11, 2022
How often do you read in the news about the great job a cybersecurity team just did? The inevitable response is just one of many reasons for today’s acute cybersecurity skills gap. Information security hiring managers are struggling to attract enough talent, and most pundits consider understaffed se
Bug Bytes #158 – postMessage XSS tips, API testing toolbox & Finding 100+ bugs in WordPress plugins
Bug Bytes
February 9, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Vulnerability scanners vs bug bounty programs: What does your business need?
News
February 8, 2022
To compare vulnerability scanners vs bug bounty programs is, in many ways, to bring the long-standing debate about humans vs machines to the realm of cybersecurity. Automated tools, like security scanners, have been helping protect computers and networks for decades now. Recently, automation has pro
