Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

Meet the hacker: Katie Paxton-Fear

Hacker Spotlight

Hacker Spotlight

June 24, 2021

In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking to Katie Paxton-Fear (aka. InsiderPhD), who is well-known for

Continue reading: Meet the hacker: Katie Paxton-Fear

A history of bug bounty programs & incentivised vulnerability disclosure

Bug Bounty & VDP

News

June 23, 2021

Hacker-powered security and bug bounty programs are growing concepts within the cybersecurity sector today. What you may not know is that ethical hacking, often dubbed as white-hat hacking, predates black-hat hacking activities. Throughout the sixties, hacking simply meant optimising systems and mac

Continue reading: A history of bug bounty programs & incentivised vulnerability disclosure

Bug Bytes #128 – GraphQL Autocorrect, Dangerous Dynamic code loading & How to audit Salesforce Lightning Components

Bug Bytes

Bug Bytes

June 23, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #128 – GraphQL Autocorrect, Dangerous Dynamic code loading & How to audit Salesforce Lightning Components

Hacker tools: BBRF – organizing your recon

Hacker Tools

Hacking Tools

June 22, 2021

Nice weather, lots of new programs on Intigriti, and another tool to discover. This week we will look at a tool created by one of Intigriti’s top researchers. Like Honoki, you probably faced the overwhelming information coming in when doing recon. BBRF will help to organize your findings in a centra

Continue reading: Hacker tools: BBRF – organizing your recon

Meet the hacker: Samuel Eng

Hacker Spotlight

Hacker Spotlight

June 17, 2021

In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking with Samuel Eng, who is one of the most experienced hackers ou

Continue reading: Meet the hacker: Samuel Eng

Bug Bytes #127 – IPv6 for recon, OpenID 2FA bypass & New threats of Service Workers Caches

Bug Bytes

Bug Bytes

June 16, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #127 – IPv6 for recon, OpenID 2FA bypass & New threats of Service Workers Caches

Hacker tools: Nmap – Next level port scanning

Hacker Tools

Hacking Tools

June 14, 2021

It’s a new week and we have a new tool. This week we will review Nmap, the port scanner of choice for every security researcher. In this article, we will discuss some of the less known features of Nmap. Read on to know more. Nmap is an open-source network mapper that uses various techniques to disco

Continue reading: Hacker tools: Nmap – Next level port scanning

Illustrating Hackers: Changing perceptions by changing how we see hackers

Hacker Spotlight

Hacker Spotlight

June 11, 2021

Anyone familiar with the Intigriti brand is likely to know that we illustrate our hackers. If you know our brand but not our quirky cartoons, a glance at our Ethical Hacker Insights Report or weekly hacker interviews will quickly bring you up to speed. In this blog post, we’re going to disclose why

Continue reading: Illustrating Hackers: Changing perceptions by changing how we see hackers

Bug Bytes #126 – XSS in AWS, exotic Python RCE vectors, zseano’s methodology

Bug Bytes

Bug Bytes

June 9, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #126 – XSS in AWS, exotic Python RCE vectors, zseano’s methodology

Hacker tools: Amass – hunting for subdomains

Hacker Tools

Hacking Tools

June 8, 2021

Welcome to our hacker tools series. In the past weeks, we discussed some useful tools to help you with your bug bounty career. This week we will discuss Amass, the well-known subdomain discovery tool. Amass is a tool that uses passive and active information gathering techniques to compile a nice lis

Continue reading: Hacker tools: Amass – hunting for subdomains

The Intigriti Ethical Hacker Insights Report 2021 educates on how to counter cybersecurity weaknesses

Security Testing

News

June 2, 2021

Antwerp (Belgium), June 1st, 2021 – The advent of a no-touch, online society has seen countless organisations embracing the power of online business operations and a distributed workforce. But, with an increase in cybercriminal activity, it’s clear companies need a security strategy that doesn’t jus

Continue reading: The Intigriti Ethical Hacker Insights Report 2021 educates on how to counter cybersecurity weaknesses

Bug Bytes #125 – Nuclei for mobile, ImageTragick like it’s 2016 & Intro to HTTP/2 and HTTP/3

Bug Bytes

Bug Bytes

June 2, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #125 – Nuclei for mobile, ImageTragick like it’s 2016 & Intro to HTTP/2 and HTTP/3

Meet the hacker: p4fg, the Swedish master of Automation

Hacker Spotlight

Hacker Spotlight

June 1, 2021

In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we’re meeting up with Peter from Sweden, who goes by the handle p4fg, accompan

Continue reading: Meet the hacker: p4fg, the Swedish master of Automation

What is an ethical hacker? And why do companies hire them?

Bug Bounty & VDP

News

May 27, 2021

Ask someone to define the word ‘hacker’ and it’s almost guaranteed to spark a debate. Yet, hacking isn’t a new concept. In fact, it’s been around for decades. Throughout the sixties, hacking simply meant optimising systems and machines to make them run more efficiently. Since then, the world’s fear

Continue reading: What is an ethical hacker? And why do companies hire them?

Bug Bytes #124 – The 2021 hacker report, a port scanning Armada & SSTI to RCE in Go apps

Bug Bytes

Bug Bytes

May 26, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #124 – The 2021 hacker report, a port scanning Armada & SSTI to RCE in Go apps

Common Types Of Vulnerability Disclosure When Working With Ethical Hackers

Bug Bounty & VDP

News

May 24, 2021

Vulnerability disclosure refers to the method whereby an ethical hacker reports a security flaw or issue to a business. In this article, we explore the three most common types of vulnerability disclosure: Private disclosure, full disclosure and responsible disclosure. We also reveal how organisation

Continue reading: Common Types Of Vulnerability Disclosure When Working With Ethical Hackers

Hacker tools: SQLMap – Finding SQLi like a pro.

Hacker Tools

Hacking Tools

May 23, 2021

Welcome back to our hacker tools series. This week we will discuss SQLMap, a python based open-source tool to detect and exploit SQL injection flaws. It can automate your SQLi tests in a fast and easy way, but you still need to know what you are doing to make full use of the tool, so keep reading. S

Continue reading: Hacker tools: SQLMap – Finding SQLi like a pro.

Vulnerability Disclosure Programs Vs Bug Bounty: Which Is Best?

Bug Bounty & VDP

News

May 19, 2021

Ethical hackers dedicate significant amounts of time to discover and report security flaws to businesses. Creating a stress-free and sensical way for them to disclose security vulnerabilities to you is critical. Not only does it encourage responsible disclosure, but it maximises the success of their

Continue reading: Vulnerability Disclosure Programs Vs Bug Bounty: Which Is Best?

Bug Bytes #123 – Exiftool RCE, Learn mobile hacking for free & #BurpHacksForBounties

Bug Bytes

Bug Bytes

May 19, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #123 – Exiftool RCE, Learn mobile hacking for free & #BurpHacksForBounties

Hacker tools: Arjun – The parameter discovery tool

Hacker Tools

Hacking Tools

May 17, 2021

Time is money, and certainly when it comes to bug bounty! Good tools can help you find bugs before others do – but only if you know how to properly use them. Today, we are reviewing a parameter discovery tool called Arjun. Arjun is a command-line tool specifically designed to look for hidden HTTP pa

Continue reading: Hacker tools: Arjun – The parameter discovery tool