Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

👩‍💻 Hacker Tools: ReNgine – Automatic recon

Hacker Tools

Hacking Tools

August 24, 2021

Every bug bounty journey starts in the same way: Reconnaissance. We need to scope out our target. Find out what they are hosting, what services are running, what ports are open and so on. This can be extremely time-consuming when done manually, not to think of the nightmare to organise all these ins

Continue reading: 👩‍💻 Hacker Tools: ReNgine – Automatic recon

👩‍💻 Hacker Tools: How to set up XSSHunter

Hacker Tools

Hacking Tools

August 18, 2021

Cross-site scripting or XSS vulnerabilities are incredibly common and not to be underestimated. Oftentimes, they can even occur in the dark, in places where you can’t see the result. In this week’s instance of Hacker Tools, we’re going to look at XSSHunter, a tool to help you find blind XSS vulnerab

Continue reading: 👩‍💻 Hacker Tools: How to set up XSSHunter

Hacker Tools: Ciphey – Automatic decryption, decoding & cracking

Hacker Tools

Hacking Tools

August 11, 2021

Have you ever come across an encoded string, hash, or encrypted message and wondered: “What type of encoding is this?”? Then Ciphey is the tool for you! “What type of encryption is this?”, “What hashing algorithm produced this hash?”, “What cipher is being used?”. The answer to those questions, that

Continue reading: Hacker Tools: Ciphey – Automatic decryption, decoding & cracking

Intigriti launches fast lane program to incentivise cybersecurity research

Company News

News

August 10, 2021

Today, we are launching the first ‘fast lane’ program that enables security researchers to monetize novel cybersecurity research prior to public disclosure. The initiative aims to effectively connect finders of emerging threats with affected organisations, allowing them to prepare and respond in a t

Continue reading: Intigriti launches fast lane program to incentivise cybersecurity research

Bug Bytes #134 – SAML authentication bypass, RCE in PyPI & Lesser known XXE attack vectors

Bug Bytes

Bug Bytes

August 6, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #134 – SAML authentication bypass, RCE in PyPI & Lesser known XXE attack vectors

The Intigriti Leaderboard: What is it and how does it impact your program?

Bug Bounty & VDP

News

August 6, 2021

If you’re watching the Olympic Games, you’ll know that the leaderboard shows the top-performing countries based on the successes of their athletes. In the case of Intigriti’s Leaderboard, the athletes are an elite team of ethical hackers, and their arena is an ever-expanding attack surface that evol

Continue reading: The Intigriti Leaderboard: What is it and how does it impact your program?

Hacker Tools: NoSQLMap – No SQL, Yes exploitation

Hacker Tools

Hacking Tools

August 4, 2021

Ever since big data and real-time applications have become the norm, we’ve increasingly needed different database solutions. MongoDB, CouchDB, Redis, Cassandra, and so many more NoSQL databases have sprouted, but what about their security? How do we go about finding misconfigurations and vulnerabili

Continue reading: Hacker Tools: NoSQLMap – No SQL, Yes exploitation

5 ways to maximize hacker participation in your bug bounty program

Bug Bounty & VDP

News

August 2, 2021

Our customer success team at Intigriti is often faced with the same question: How can we maximize ethical hacker participation in our bug bounty program? To answer this query, we asked our security researcher community what their top reasons were for picking a bug bounty target as part of our Ethica

Continue reading: 5 ways to maximize hacker participation in your bug bounty program

Bug Bytes #133 – It’s still DNS, A $50K stray token & Path traversal in microservices

Bug Bytes

Bug Bytes

July 28, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #133 – It’s still DNS, A $50K stray token & Path traversal in microservices

Hacker Tools: JWT_Tool – The JSON Web Token Toolkit

Hacker Tools

Hacking Tools

July 27, 2021

When you log in to a website and start surfing, why don’t you need to type in your password for every subsequent request? JWT is a very likely reason for that. It allows information transmission and authorization in a simple format. However, sometimes it is implemented incorrectly and that can lead

Continue reading: Hacker Tools: JWT_Tool – The JSON Web Token Toolkit

Bug Bytes #132 – RCE on 12.7% of the Internet & Why you should turn off your password manager’s autofill

Bug Bytes

Bug Bytes

July 21, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #132 – RCE on 12.7% of the Internet & Why you should turn off your password manager’s autofill

Hacker Tools: Aquatone – Visualize your attack surface

Hacker Tools

Hacking Tools

July 20, 2021

On any website we visit, we’re stuck in a net of security measures keeping us from doing whatever we want. Bug bounty programs give us a unique opportunity to attempt to slip through the tiny holes in that net. However, whilst being focused on fine-grained hunting, we can often lose sight of the big

Continue reading: Hacker Tools: Aquatone – Visualize your attack surface

Meet the hacker: Rana Khalil

Hacker Spotlight

Hacker Spotlight

July 15, 2021

In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking to Rana Khalil, who is well-known for her Youtube channel and

Continue reading: Meet the hacker: Rana Khalil

Bug Bytes #131 – Credential stuffing in bug bounty, Hijacking shortlinks & Hacker shows

Bug Bytes

Bug Bytes

July 14, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #131 – Credential stuffing in bug bounty, Hijacking shortlinks & Hacker shows

Hacker tools: CyberChef – The cyber swiss army knife

Hacker Tools

Hacking Tools

July 13, 2021

As a bug bounty hunter, your laptop is your kitchen, your tools are your utensils and you are the chef cooking up some beautiful bugs, but every great cook needs a sous-chef and CyberChef was made to do just that. This week we will be taking a deep dive into CyberChef and everything it has to offer.

Continue reading: Hacker tools: CyberChef – The cyber swiss army knife

Bug Bytes #130 – DOM Invader, The extended BApp store & Will Google kill XSS?

Bug Bytes

Bug Bytes

July 7, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #130 – DOM Invader, The extended BApp store & Will Google kill XSS?

Hacker tools: Gobuster – the all-in-one tool for you

Hacker Tools

Hacking Tools

July 5, 2021

Summer is at our doorstep, the weather is getting better and the Intigriti team is ready to help you once again. This week, we will go over Gobuster, a well-known tool amongst researchers for mainly brute-forcing directories. But that’s not all the tool can do. It has multiple options what makes it

Continue reading: Hacker tools: Gobuster – the all-in-one tool for you

Meet the hacker: Tom Hudson

Hacker Spotlight

Hacker Spotlight

July 1, 2021

In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking to Tom Hudson (aka. TomNomNom), who is well-known for his plet

Continue reading: Meet the hacker: Tom Hudson

Bug Bytes #129 – LEXSS, SSRF via ColdFusion/CFML tags & ForgeRock OpenAM RCE

Bug Bytes

Bug Bytes

June 30, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #129 – LEXSS, SSRF via ColdFusion/CFML tags & ForgeRock OpenAM RCE

Hacker tools: XSStrike – Hunting for low-hanging fruits.

Hacker Tools

Hacking Tools

June 29, 2021

Welcome to our wonderful “Hacker tools” series. If you have mastered all our previous articles, you must have submitted a valid report by now. If not, check out this week’s tool. XSStrike is a Cross-Site Scripting detection framework written by s0md3v. Yes, you are correct, the same developer of Arj

Continue reading: Hacker tools: XSStrike – Hunting for low-hanging fruits.