Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

Bug Bytes #147 – From won’t fix to $100k+ bounties, HTTP Header Smuggling & ChaosDB

Bug Bytes

Bug Bytes

November 17, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #147 – From won’t fix to $100k+ bounties, HTTP Header Smuggling & ChaosDB

Bug Bytes #146 – Driftwood, Trojan Source & XSS via smart contract

Bug Bytes

Bug Bytes

November 10, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #146 – Driftwood, Trojan Source & XSS via smart contract

Bug Bytes #145 – How to Make a Million in 4 Years, CookieMonster & Threats to CI/CD Pipelines

Bug Bytes

Bug Bytes

November 3, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #145 – How to Make a Million in 4 Years, CookieMonster & Threats to CI/CD Pipelines

Bug Bytes #144 – Bug hunting on the modern Web, Token spraying & Discourse RCE

Bug Bytes

Bug Bytes

October 27, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #144 – Bug hunting on the modern Web, Token spraying & Discourse RCE

Bug Bytes #143 – Building an Apache SSRF exploit, Thesis on HTTP Request Smuggling & Turbo Intruder go brrr

Bug Bytes

Bug Bytes

October 20, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #143 – Building an Apache SSRF exploit, Thesis on HTTP Request Smuggling & Turbo Intruder go brrr

Bug Bytes #142 – Weird Google bugs, SAML padding Oracle & Apache path traversal continued

Bug Bytes

Bug Bytes

October 13, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #142 – Weird Google bugs, SAML padding Oracle & Apache path traversal continued

Bug Bytes #141 – Sesh Gremlin attack, RCE via password field & Pwning XMLSec for info disclosure and bounties

Bug Bytes

Bug Bytes

October 6, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #141 – Sesh Gremlin attack, RCE via password field & Pwning XMLSec for info disclosure and bounties

CRLFuzz – Hacker Tools: Injecting CRLF for bounties 👩‍💻

Hacker Tools

Hacking Tools

October 5, 2021

A CRLF injection is the injection of newlines in places where the server doesn’t expect newlines. This can cause a plethora of vulnerabilities including XSS, session fixation, cookie injection, open redirect, and much more! What are we waiting for? Let’s check out CRLFuzz, the tool that can help you

Continue reading: CRLFuzz – Hacker Tools: Injecting CRLF for bounties 👩‍💻

Bug Bytes #140 – The Great leak, Sandwich Attacks & Better InfoSec resumes

Bug Bytes

Bug Bytes

September 29, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #140 – The Great leak, Sandwich Attacks & Better InfoSec resumes

Waybackurls – Hacker Tools: Time-traveling for bounties 👩‍💻

Hacker Tools

Hacking Tools

September 24, 2021

The past can tell stories, show things that should’ve never been uncovered and today we will be looking at that past. We can go hunt for subdomains, secret endpoints, tokens, and secrets, all with the help of Waybackurls. Wayback Machine Logo Waybackurls by @TomNomNom is a small utility written in G

Continue reading: Waybackurls – Hacker Tools: Time-traveling for bounties 👩‍💻

Bug Bytes #139 – OMIGOD, Code review guides & A bug hunter’s five year journey

Bug Bytes

Bug Bytes

September 22, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #139 – OMIGOD, Code review guides & A bug hunter’s five year journey

Bug Bytes #138 – Web app security roadmap, OWASP Top 10 & Request smuggling via integer overflow

Bug Bytes

Bug Bytes

September 15, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #138 – Web app security roadmap, OWASP Top 10 & Request smuggling via integer overflow

Dalfox – Hacker Tools: XSS Scanning Made Easy 👩‍💻

Hacker Tools

Hacking Tools

September 14, 2021

Finding XSS can sometimes be a repetitive and laborious task. Many attempts at automating the process have been made, yet very little actually come close to getting it right. Today, we’re covering Dalfox, a tool that did get it right. Let’s find some cross-site scripting vulnerabilities! DalFox is a

Continue reading: Dalfox – Hacker Tools: XSS Scanning Made Easy 👩‍💻

The new OWASP Top 10 for 2021

Security Testing

News

September 10, 2021

OWASP top 10; Over the last 4 years, the cybersecurity field has continued to see incredible leaps forward at an unimaginable pace. As attacks that used to be prevalent 15 years ago are slowly dying out, new attack vectors are being discovered day in and day out. Security researchers and bug bounty

Continue reading: The new OWASP Top 10 for 2021

Atos and Intigriti launch new integrated Bug Bounty service

Customer Stories

News

September 10, 2021

Paris and Lille, France – September 9, 2021 – Atos and Intigriti, the European leading platform for bug bounty and ethical hacking, announce their collaboration to release an end-to-end bug bounty offering for organisations. Bug bounty consists of using expert researchers and ethical hackers, select

Continue reading: Atos and Intigriti launch new integrated Bug Bounty service

Bug Bytes #137 – Weird proxies 2, JDBC attacks & A handful of RCEs

Bug Bytes

Bug Bytes

September 8, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #137 – Weird proxies 2, JDBC attacks & A handful of RCEs

KiteRunner – Hacker Tools: Next-level API hacking 👩‍💻

Hacker Tools

Hacking Tools

September 7, 2021

When facing API endpoints, older tools for directory busting tend to be very ineffective. The days where a webserver is just a directory tree are behind us. The more modern ‘routes’ have taken over and wildly bruteforcing filenames isn’t effective anymore. We need to be smarter and scan based on pop

Continue reading: KiteRunner – Hacker Tools: Next-level API hacking 👩‍💻

Bug Bytes #136 – GraphQL fingerprinting, Building new SSTI payloads & A HTTP/2 request smuggling lab

Bug Bytes

Bug Bytes

September 1, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #136 – GraphQL fingerprinting, Building new SSTI payloads & A HTTP/2 request smuggling lab

👩‍💻 Hacker Tools: WPScan – Your WordPress isn’t safe!

Hacker Tools

Hacking Tools

August 31, 2021

WordPress is huge! Some even estimate 30% of public websites run it in some way or another. In fact, you’re reading this on a WordPress page. Are all of these sites secure? No! Not at all. While the latest up to date version of WordPress is very likely to be secure (until someone finds a zero-day in

Continue reading: 👩‍💻 Hacker Tools: WPScan – Your WordPress isn’t safe!

Bug Bytes #135 – Code review for bug hunters, Zoom $200K RCE & Breaking HTTP/2 and Exchange

Bug Bytes

Bug Bytes

August 25, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #135 – Code review for bug hunters, Zoom $200K RCE & Breaking HTTP/2 and Exchange