Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

Bug Bytes #157 – Daily bug bounty recaps, Reading other bug hunter’s reports & Hacking Google Drive integrations

Bug Bytes

Bug Bytes

February 2, 2022

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #157 – Daily bug bounty recaps, Reading other bug hunter’s reports & Hacking Google Drive integrations

Meg – Hacker Tools: Endpoint scan the masses! 👩‍💻

Hacker Tools

Hacking Tools

February 1, 2022

You’ve just enumerated all the subdomains of your target and what? There’s 400 of them? Are you going to start individual scans to find endpoints on them? No you’re not! You’re going to use Meg, of course! Meg is not the girl nextdoor, no it’s an amazing tool you need to know about! As more and more

Continue reading: Meg – Hacker Tools: Endpoint scan the masses! 👩‍💻

Bug Bytes #156 – Python NaN Injection, Null-byte based file inclusion & $100K for hacking the Apple webcam

Bug Bytes

Bug Bytes

January 26, 2022

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #156 – Python NaN Injection, Null-byte based file inclusion & $100K for hacking the Apple webcam

How can a bug bounty program improve your IT security posture?

Bug Bounty & VDP

News

January 21, 2022

Rapidly evolving technology has created a world whereby cybersecurity must grow and mature at equal speed. Your IT security posture should anticipate fast change by providing real-world, real-time testing of your cyber defenses for known and unknown threats. This article looks at how to use a bug bo

Continue reading: How can a bug bounty program improve your IT security posture?

Bug Bytes #155 – When logout logs you in, 120 days bug hunting challenge & Testing reverse proxies with Nuclei

Bug Bytes

Bug Bytes

January 19, 2022

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #155 – When logout logs you in, 120 days bug hunting challenge & Testing reverse proxies with Nuclei

Bug Bytes #154 – URL parsing confusion, Forging cookies for almost $100k & Exploiting impossible Pickle deserialization

Bug Bytes

Bug Bytes

January 12, 2022

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #154 – URL parsing confusion, Forging cookies for almost $100k & Exploiting impossible Pickle deserialization

Attack surface management best practices: Intigriti’s top tips

Security Testing

News

January 12, 2022

While the cultural stereotype of a hacker sitting in front of a monochrome CRT tapping obscure terminal commands makes for interesting fiction, the damage real hackers do is far less entertaining. In this article, Intigriti discusses attack surface management best practices that help organizations s

Continue reading: Attack surface management best practices: Intigriti’s top tips

EyeWitness – Hacker Tools: Hacking through screenshots 👩‍💻

Hacker Tools

Hacking Tools

January 11, 2022

EyeWitness is an incredible tool that allows you to quickly get a feel for what assets to target first. We all know hundreds of content discovery tools that give us vast amounts of data, but do we ever focus on efficiently parsing all that data? How do you go through hundreds of endpoints? If you’re

Continue reading: EyeWitness – Hacker Tools: Hacking through screenshots 👩‍💻

Meet the hacker: GangsterSquad

Hacker Spotlight

Hacker Spotlight

January 7, 2022

Have you ever wondered what it would be like to be a cybercriminal? Well, if you’re an ethical hacker, you must go beyond imagining and put yourself into the shoes of one. Not all hackers are inherently bad. However, they get a bad reputation from mainstream media. Despite having the same skill sets

Continue reading: Meet the hacker: GangsterSquad

Bug Bytes #153 – New PHP LFI technique, Cache poisoning at scale & Null byte attacks are still alive!

Bug Bytes

Bug Bytes

January 5, 2022

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #153 – New PHP LFI technique, Cache poisoning at scale & Null byte attacks are still alive!

Top 20 bug bounty YouTube channels to follow in 2021!

Bug Bounty & VDP

News

December 31, 2021

After last year’s edition of our “Top 20 bug bounty Youtube channels” blog post, you should all know by now how important content creators are to Intigriti. We really appreciate all the time and hard work they are putting into enabling a new wave of hackers and security researchers! Over the last 12

Continue reading: Top 20 bug bounty YouTube channels to follow in 2021!

Bug Bytes #152 – SSRF via Gateway actuator, Flickr account takeover & Writeup of NSO’s iMessage RCE

Bug Bytes

Bug Bytes

December 22, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #152 – SSRF via Gateway actuator, Flickr account takeover & Writeup of NSO’s iMessage RCE

21 things that happened in 2021 at Intigriti: a year of milestones

Company News

News

December 21, 2021

The following blog shares a compilation of noteworthy events and achievements at Intigriti in 2021. Intigriti has grown substantially over the past year, and we’re excited to see how we transform in 2022. But as we prepare to ring in the new year, we’re taking a moment to reflect on the celebrations

Continue reading: 21 things that happened in 2021 at Intigriti: a year of milestones

Bug Bytes #151 – The one where the Internet is on fire

Bug Bytes

Bug Bytes

December 15, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #151 – The one where the Internet is on fire

How Intigriti responded to the Log4j vulnerability

Company News

News

December 14, 2021

In this article, we’ll demonstrate how crowd security platforms give organizations additional support and assurance when a public zero-day vulnerability disclosure, such as Log4Shell (the Log4j vulnerability), happens. Last week, a zero-day vulnerability (Log4shell) was publicly disclosed in the wid

Continue reading: How Intigriti responded to the Log4j vulnerability

Bug Bytes #150 – CMS wordlists, Lesser known Python bugs & Containers learning path

Bug Bytes

Bug Bytes

December 8, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #150 – CMS wordlists, Lesser known Python bugs & Containers learning path

Intel chooses Intigriti as its bug bounty vulnerability management platform

Customer Stories

News

December 2, 2021

Antwerp (Belgium), December 2nd, 2021 – Intigriti, the global bug bounty platform and fastest-growing ethical hacker community, is proud to announce it has been selected by Intel, the industry ICT leader in the design and manufacturing of semiconductors, as its bug bounty vulnerability management pl

Continue reading: Intel chooses Intigriti as its bug bounty vulnerability management platform

Bug Bytes #149 – WordPress plugin confusion, Bug bounty automation & CTF tricks

Bug Bytes

Bug Bytes

December 1, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #149 – WordPress plugin confusion, Bug bounty automation & CTF tricks

Bug Bytes #148 – Google SSRF filmed, A 1 N/A bug to $15k & Tuning raced conditions

Bug Bytes

Bug Bytes

November 24, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #148 – Google SSRF filmed, A 1 N/A bug to $15k & Tuning raced conditions

GoSpider – Hacker Tools: Enumerate the web! 👩‍💻

Hacker Tools

Hacking Tools

November 23, 2021

As a bug bounty hunter, you need to get a good view of all the pages and endpoints your targets host. Manually enumerating these can become labour intensive, boring and on top of that, is prone to errors. Today we’re going to look at GoSpider, a tool that can do all this for us! Photo by Pixabay on

Continue reading: GoSpider – Hacker Tools: Enumerate the web! 👩‍💻