Researchers’ blog
Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.
👩💻 Hacker Tools: ReNgine – Automatic recon
Hacking Tools
August 24, 2021
Every bug bounty journey starts in the same way: Reconnaissance. We need to scope out our target. Find out what they are hosting, what services are running, what ports are open and so on. This can be extremely time-consuming when done manually, not to think of the nightmare to organise all these ins
👩💻 Hacker Tools: How to set up XSSHunter
Hacking Tools
August 18, 2021
Cross-site scripting or XSS vulnerabilities are incredibly common and not to be underestimated. Oftentimes, they can even occur in the dark, in places where you can’t see the result. In this week’s instance of Hacker Tools, we’re going to look at XSSHunter, a tool to help you find blind XSS vulnerab
Hacker Tools: Ciphey – Automatic decryption, decoding & cracking
Hacking Tools
August 11, 2021
Have you ever come across an encoded string, hash, or encrypted message and wondered: “What type of encoding is this?”? Then Ciphey is the tool for you! “What type of encryption is this?”, “What hashing algorithm produced this hash?”, “What cipher is being used?”. The answer to those questions, that
Intigriti launches fast lane program to incentivise cybersecurity research
News
August 10, 2021
Today, we are launching the first ‘fast lane’ program that enables security researchers to monetize novel cybersecurity research prior to public disclosure. The initiative aims to effectively connect finders of emerging threats with affected organisations, allowing them to prepare and respond in a t
Bug Bytes #134 – SAML authentication bypass, RCE in PyPI & Lesser known XXE attack vectors
Bug Bytes
August 6, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
The Intigriti Leaderboard: What is it and how does it impact your program?
News
August 6, 2021
If you’re watching the Olympic Games, you’ll know that the leaderboard shows the top-performing countries based on the successes of their athletes. In the case of Intigriti’s Leaderboard, the athletes are an elite team of ethical hackers, and their arena is an ever-expanding attack surface that evol
Hacker Tools: NoSQLMap – No SQL, Yes exploitation
Hacking Tools
August 4, 2021
Ever since big data and real-time applications have become the norm, we’ve increasingly needed different database solutions. MongoDB, CouchDB, Redis, Cassandra, and so many more NoSQL databases have sprouted, but what about their security? How do we go about finding misconfigurations and vulnerabili
5 ways to maximize hacker participation in your bug bounty program
News
August 2, 2021
Our customer success team at Intigriti is often faced with the same question: How can we maximize ethical hacker participation in our bug bounty program? To answer this query, we asked our security researcher community what their top reasons were for picking a bug bounty target as part of our Ethica
Bug Bytes #133 – It’s still DNS, A $50K stray token & Path traversal in microservices
Bug Bytes
July 28, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker Tools: JWT_Tool – The JSON Web Token Toolkit
Hacking Tools
July 27, 2021
When you log in to a website and start surfing, why don’t you need to type in your password for every subsequent request? JWT is a very likely reason for that. It allows information transmission and authorization in a simple format. However, sometimes it is implemented incorrectly and that can lead
Bug Bytes #132 – RCE on 12.7% of the Internet & Why you should turn off your password manager’s autofill
Bug Bytes
July 21, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker Tools: Aquatone – Visualize your attack surface
Hacking Tools
July 20, 2021
On any website we visit, we’re stuck in a net of security measures keeping us from doing whatever we want. Bug bounty programs give us a unique opportunity to attempt to slip through the tiny holes in that net. However, whilst being focused on fine-grained hunting, we can often lose sight of the big
Meet the hacker: Rana Khalil
Hacker Spotlight
July 15, 2021
In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking to Rana Khalil, who is well-known for her Youtube channel and
Bug Bytes #131 – Credential stuffing in bug bounty, Hijacking shortlinks & Hacker shows
Bug Bytes
July 14, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker tools: CyberChef – The cyber swiss army knife
Hacking Tools
July 13, 2021
As a bug bounty hunter, your laptop is your kitchen, your tools are your utensils and you are the chef cooking up some beautiful bugs, but every great cook needs a sous-chef and CyberChef was made to do just that. This week we will be taking a deep dive into CyberChef and everything it has to offer.
Bug Bytes #130 – DOM Invader, The extended BApp store & Will Google kill XSS?
Bug Bytes
July 7, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker tools: Gobuster – the all-in-one tool for you
Hacking Tools
July 5, 2021
Summer is at our doorstep, the weather is getting better and the Intigriti team is ready to help you once again. This week, we will go over Gobuster, a well-known tool amongst researchers for mainly brute-forcing directories. But that’s not all the tool can do. It has multiple options what makes it
Meet the hacker: Tom Hudson
Hacker Spotlight
July 1, 2021
In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking to Tom Hudson (aka. TomNomNom), who is well-known for his plet
Bug Bytes #129 – LEXSS, SSRF via ColdFusion/CFML tags & ForgeRock OpenAM RCE
Bug Bytes
June 30, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker tools: XSStrike – Hunting for low-hanging fruits.
Hacking Tools
June 29, 2021
Welcome to our wonderful “Hacker tools” series. If you have mastered all our previous articles, you must have submitted a valid report by now. If not, check out this week’s tool. XSStrike is a Cross-Site Scripting detection framework written by s0md3v. Yes, you are correct, the same developer of Arj
