Researchers’ blog
Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.
Meet the hacker: Katie Paxton-Fear
Hacker Spotlight
June 24, 2021
In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking to Katie Paxton-Fear (aka. InsiderPhD), who is well-known for
A history of bug bounty programs & incentivised vulnerability disclosure
News
June 23, 2021
Hacker-powered security and bug bounty programs are growing concepts within the cybersecurity sector today. What you may not know is that ethical hacking, often dubbed as white-hat hacking, predates black-hat hacking activities. Throughout the sixties, hacking simply meant optimising systems and mac
Bug Bytes #128 – GraphQL Autocorrect, Dangerous Dynamic code loading & How to audit Salesforce Lightning Components
Bug Bytes
June 23, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker tools: BBRF – organizing your recon
Hacking Tools
June 22, 2021
Nice weather, lots of new programs on Intigriti, and another tool to discover. This week we will look at a tool created by one of Intigriti’s top researchers. Like Honoki, you probably faced the overwhelming information coming in when doing recon. BBRF will help to organize your findings in a centra
Meet the hacker: Samuel Eng
Hacker Spotlight
June 17, 2021
In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we were talking with Samuel Eng, who is one of the most experienced hackers ou
Bug Bytes #127 – IPv6 for recon, OpenID 2FA bypass & New threats of Service Workers Caches
Bug Bytes
June 16, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker tools: Nmap – Next level port scanning
Hacking Tools
June 14, 2021
It’s a new week and we have a new tool. This week we will review Nmap, the port scanner of choice for every security researcher. In this article, we will discuss some of the less known features of Nmap. Read on to know more. Nmap is an open-source network mapper that uses various techniques to disco
Illustrating Hackers: Changing perceptions by changing how we see hackers
Hacker Spotlight
June 11, 2021
Anyone familiar with the Intigriti brand is likely to know that we illustrate our hackers. If you know our brand but not our quirky cartoons, a glance at our Ethical Hacker Insights Report or weekly hacker interviews will quickly bring you up to speed. In this blog post, we’re going to disclose why
Bug Bytes #126 – XSS in AWS, exotic Python RCE vectors, zseano’s methodology
Bug Bytes
June 9, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker tools: Amass – hunting for subdomains
Hacking Tools
June 8, 2021
Welcome to our hacker tools series. In the past weeks, we discussed some useful tools to help you with your bug bounty career. This week we will discuss Amass, the well-known subdomain discovery tool. Amass is a tool that uses passive and active information gathering techniques to compile a nice lis
The Intigriti Ethical Hacker Insights Report 2021 educates on how to counter cybersecurity weaknesses
News
June 2, 2021
Antwerp (Belgium), June 1st, 2021 – The advent of a no-touch, online society has seen countless organisations embracing the power of online business operations and a distributed workforce. But, with an increase in cybercriminal activity, it’s clear companies need a security strategy that doesn’t jus
Bug Bytes #125 – Nuclei for mobile, ImageTragick like it’s 2016 & Intro to HTTP/2 and HTTP/3
Bug Bytes
June 2, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Meet the hacker: p4fg, the Swedish master of Automation
Hacker Spotlight
June 1, 2021
In our ‘meet the hacker’ series, we’re taking the time to talk with Intigriti community members that have an impressive track record, an unusual methodology or have made valuable contributions to the community. This time, we’re meeting up with Peter from Sweden, who goes by the handle p4fg, accompan
What is an ethical hacker? And why do companies hire them?
News
May 27, 2021
Ask someone to define the word ‘hacker’ and it’s almost guaranteed to spark a debate. Yet, hacking isn’t a new concept. In fact, it’s been around for decades. Throughout the sixties, hacking simply meant optimising systems and machines to make them run more efficiently. Since then, the world’s fear
Bug Bytes #124 – The 2021 hacker report, a port scanning Armada & SSTI to RCE in Go apps
Bug Bytes
May 26, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Common Types Of Vulnerability Disclosure When Working With Ethical Hackers
News
May 24, 2021
Vulnerability disclosure refers to the method whereby an ethical hacker reports a security flaw or issue to a business. In this article, we explore the three most common types of vulnerability disclosure: Private disclosure, full disclosure and responsible disclosure. We also reveal how organisation
Hacker tools: SQLMap – Finding SQLi like a pro.
Hacking Tools
May 23, 2021
Welcome back to our hacker tools series. This week we will discuss SQLMap, a python based open-source tool to detect and exploit SQL injection flaws. It can automate your SQLi tests in a fast and easy way, but you still need to know what you are doing to make full use of the tool, so keep reading. S
Vulnerability Disclosure Programs Vs Bug Bounty: Which Is Best?
News
May 19, 2021
Ethical hackers dedicate significant amounts of time to discover and report security flaws to businesses. Creating a stress-free and sensical way for them to disclose security vulnerabilities to you is critical. Not only does it encourage responsible disclosure, but it maximises the success of their
Bug Bytes #123 – Exiftool RCE, Learn mobile hacking for free & #BurpHacksForBounties
Bug Bytes
May 19, 2021
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers
Hacker tools: Arjun – The parameter discovery tool
Hacking Tools
May 17, 2021
Time is money, and certainly when it comes to bug bounty! Good tools can help you find bugs before others do – but only if you know how to properly use them. Today, we are reviewing a parameter discovery tool called Arjun. Arjun is a command-line tool specifically designed to look for hidden HTTP pa
