Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

Meet the hacker: 0xkasper, CTF player, student, and hunter.

Hacker Spotlight

Hacker Spotlight

May 13, 2021

Our in-house team of security analysts won’t judge reports by their author, but some researchers are known internally to put a smile on the face of our triage team. One of these researchers is 0xKasper, who as it turns out only lives a few blocks away from one of our Intigriti offices. More than eno

Continue reading: Meet the hacker: 0xkasper, CTF player, student, and hunter.

Bug Bytes #122 – ReDoS demystified, PayloadAllTheThings inside Burp & An $18k Instagram OAuth misconfiguration

Bug Bytes

Bug Bytes

May 12, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #122 – ReDoS demystified, PayloadAllTheThings inside Burp & An $18k Instagram OAuth misconfiguration

Hacker tools: Nuclei, a YAML based vulnerability scanner

Hacker Tools

Hacking Tools

May 10, 2021

Time is money, and certainly when it comes to bug bounty! Good tools can help you find bugs before others do – but only if you know how to properly use them. We will be reviewing some of our favourite open-source tools and providing you with some tips and tricks on how to use them. Today we will rev

Continue reading: Hacker tools: Nuclei, a YAML based vulnerability scanner

Meet the hacker: Get to know sumgr0, the king of subdomain takeovers.

Hacker Spotlight

Hacker Spotlight

May 7, 2021

Intigriti researcher sumgr0 caught our eyes when he secured himself a top position in our quarterly leaderboard by honing his skills on just one program. We caught up with him for an interview to talk about his recon techniques, automation and why he enjoys using the Intigriti platform. Hi Sumit! I’

Continue reading: Meet the hacker: Get to know sumgr0, the king of subdomain takeovers.

Bug Bytes #121 – Free burp collaborator alternative, hacking chrome extensions & $28k Facebook oauth account takeover

Bug Bytes

Bug Bytes

May 5, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #121 – Free burp collaborator alternative, hacking chrome extensions & $28k Facebook oauth account takeover

Hacker tools: FFuF (Fuzz Faster u Fool)

Hacker Tools

Hacking Tools

May 3, 2021

Time is money, and certainly when it comes to bug bounty! Good tools can help you find bugs before others do – but only if you know how to properly use them. We will be reviewing some of our favourite open-source tools and providing you with some tips and tricks on how to use them. The first tool we

Continue reading: Hacker tools: FFuF (Fuzz Faster u Fool)

Hacksplained joins Intigriti to further enable community of 35.000 ethical hackers

Hacker Spotlight

Hacker Spotlight

April 30, 2021

Intigriti is proud to announce that Pascal Schulz, better known under his pseudonym ‘Hacksplained’ is joining the community team as hacker enablement manager . The Austria-based security researcher and educational content creator will focus on further growing the community team, enabling the power o

Continue reading: Hacksplained joins Intigriti to further enable community of 35.000 ethical hackers

How To Debunk These 6 Common Bug Bounty Misconceptions

Bug Bounty & VDP

News

April 28, 2021

The value of bug bounty programs is recognised by well-known companies all over the world. However, there are still a few stubborn myths about the concept that persists. This article lists six of the most common misconceptions we hear when speaking to potential customers about bug bounty programs. T

Continue reading: How To Debunk These 6 Common Bug Bounty Misconceptions

Bug Bytes #120 – MacOS pwned, Homebrew RCE & The world’s shortest backdoor

Bug Bytes

Bug Bytes

April 28, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #120 – MacOS pwned, Homebrew RCE & The world’s shortest backdoor

Bug Bytes #119 – AutoGraphQL, WhatsApp MitD & Desktop apps mishandling bad URIs

Bug Bytes

Bug Bytes

April 21, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #119 – AutoGraphQL, WhatsApp MitD & Desktop apps mishandling bad URIs

Hacker tools: FuFF (Fuzz Faster u Fool)

Hacker Tools

Hacking Tools

April 20, 2021

Time is money, and certainly when it comes to bug bounty! Good tools can help you find bugs before others do – but only if you know how to properly use them. We will be reviewing some of our favourite open-source tools and providing you with some tips and tricks on how to use them. The first tool we

Continue reading: Hacker tools: FuFF (Fuzz Faster u Fool)

Bug Bytes #118 – Kiterunner, Server-side XSS & Abusing payment systems for free money

Bug Bytes

Bug Bytes

April 14, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. CLICK HERE TO SUBSCRIBE This issue covers

Continue reading: Bug Bytes #118 – Kiterunner, Server-side XSS & Abusing payment systems for free money

Get to know iQimpz, one of Intigriti’s top hackers

Hacker Spotlight

Hacker Spotlight

April 12, 2021

Bug Business is a series of interviews in which experts from the bug bounty industry shine their light on bug types and trends. iQimpz is a well-known researcher at Intigriti, he always sends in quality reports and is known for his IDOR’s. Hello! I’m Dylan Lawhon, a 20-year-old hacker, Christian, an

Continue reading: Get to know iQimpz, one of Intigriti’s top hackers

Bug Bytes #117 – Writeups à gogo, Google blind SSRF challenge & InfoSec drama

Bug Bytes

Bug Bytes

April 7, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from March 29

Continue reading: Bug Bytes #117 – Writeups à gogo, Google blind SSRF challenge & InfoSec drama

4 key benefits of launching a successful bug bounty program

Bug Bounty & VDP

News

April 6, 2021

In this article, we highlight four key bug bounty program benefits. We also explain how crowdsourced security models play an essential part in multi-layered security. From choosing a solid framework and writing secure code to running vulnerability scans, each additional security step you take lowers

Continue reading: 4 key benefits of launching a successful bug bounty program

Bug Bytes #116 – New OAuth attacks, Hacking Shopify with a single dot & Netmask SSRF

Bug Bytes

Bug Bytes

March 31, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from March 22

Continue reading: Bug Bytes #116 – New OAuth attacks, Hacking Shopify with a single dot & Netmask SSRF

Bug Bytes #115 – Hacking Facebook & Google’s networks, H2C smuggling revisited & Networking fundamentals

Bug Bytes

Bug Bytes

March 24, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from March 15

Continue reading: Bug Bytes #115 – Hacking Facebook & Google’s networks, H2C smuggling revisited & Networking fundamentals

Bug Bytes #114 – Binary fuzzing for Web vulnerabilities, Leaky page & NahamCon2021

Bug Bytes

Bug Bytes

March 17, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from March 8 t

Continue reading: Bug Bytes #114 – Binary fuzzing for Web vulnerabilities, Leaky page & NahamCon2021

Bug Bytes #113 – MS Exchange pre-auth RCE, Burp Crawler demystified & SSO security thesis

Bug Bytes

Bug Bytes

March 10, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from March 1 t

Continue reading: Bug Bytes #113 – MS Exchange pre-auth RCE, Burp Crawler demystified & SSO security thesis

Bug Bytes #112 – JSON parsers inconsistencies, Fuzzing for SSRF & Microsoft $50k account takeover

Bug Bytes

Bug Bytes

March 3, 2021

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from February

Continue reading: Bug Bytes #112 – JSON parsers inconsistencies, Fuzzing for SSRF & Microsoft $50k account takeover