Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

Bug Bytes #93 – Discord RCE, Vulnerable HTML to PDF converters & DOMPurify bypass demystified

Bug Bytes

Bug Bytes

October 21, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 11 to 18

Continue reading: Bug Bytes #93 – Discord RCE, Vulnerable HTML to PDF converters & DOMPurify bypass demystified

Bug Bytes #92 – Pwning Apple for three months, XSS in VueJS, Hacking Salesforce Lightning & Unicode byͥtes

Bug Bytes

Bug Bytes

October 14, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 04 to 11

Continue reading: Bug Bytes #92 – Pwning Apple for three months, XSS in VueJS, Hacking Salesforce Lightning & Unicode byͥtes

Bug Bytes #91 – The shortest domain, Weird Facebook authentication bypass & GitHub Actions secrets

Bug Bytes

Bug Bytes

October 7, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 25 of Sep

Continue reading: Bug Bytes #91 – The shortest domain, Weird Facebook authentication bypass & GitHub Actions secrets

Top 20 bug bounty YouTube channels to follow in 2020!

Bug Bounty & VDP

News

October 5, 2020

At Intigriti, we have a tremendous amount of respect for content creators and educators devoting their time and energy into bringing the bug bounty community to the next level. In times where superficial algorithms delete or demonetise educational content for hackers, we believe it is our duty to he

Continue reading: Top 20 bug bounty YouTube channels to follow in 2020!

Bug Bytes #90 – The impossible XSS, Burp Pro tips & A millionaire on bug bounty and meditation

Bug Bytes

Bug Bytes

September 30, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 18 to 25

Continue reading: Bug Bytes #90 – The impossible XSS, Burp Pro tips & A millionaire on bug bounty and meditation

Intigriti wins ‘Cybersecurity Innovator of the Year’

Company News

Awards

September 23, 2020

Data News announced today Intigriti as winner of the Data News awards for Excellence for Cyber ​​Security Innovator of 2020. In particular, the innovative nature of the ethical hacking platform and the many positive references from customers were praised by the jury. For Intigriti, this award is a r

Continue reading: Intigriti wins ‘Cybersecurity Innovator of the Year’

Bug Bytes #89 – What $635,387.47 of bounties in 4 years looks like, A 14-year-old’s impressive Instagram XSS & The ultimate ffuf guide

Bug Bytes

Bug Bytes

September 23, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 11 to 18

Continue reading: Bug Bytes #89 – What $635,387.47 of bounties in 4 years looks like, A 14-year-old’s impressive Instagram XSS & The ultimate ffuf guide

Bug Bytes #88 – How @orange_8361 hacked Facebook (again), Privilege escalation in Microsoft’s Netlogon & HTTP request smuggling via HTTP/2

Bug Bytes

Bug Bytes

September 16, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 04 to 11

Continue reading: Bug Bytes #88 – How @orange_8361 hacked Facebook (again), Privilege escalation in Microsoft’s Netlogon & HTTP request smuggling via HTTP/2

Inti De Ceukelaire voted “IT Person of the Year”

Company News

Awards

September 15, 2020

Computable selected Inti from a longlist of 55 nominated IT Professionals Today it was announced that Inti de Ceukelaire (25), Head of Hackers at Intigriti, has been voted “IT Person of the Year” by Computable. He also has the honor of being the youngest winner ever. Inti has been selected from a lo

Continue reading: Inti De Ceukelaire voted “IT Person of the Year”

Bug Bytes #87 – Google Android Local Arbitrary Code Execution, ADB over WIFI & A bunch of New Relic bug reports

Bug Bytes

Bug Bytes

September 9, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 28 of Aug

Continue reading: Bug Bytes #87 – Google Android Local Arbitrary Code Execution, ADB over WIFI & A bunch of New Relic bug reports

Bug Bytes #86 – Stealing local files with Safari, Prototype pollution vs HTML sanitizers & A hacker’s mom learning bug bounty

Bug Bytes

Bug Bytes

September 2, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 21 to 28

Continue reading: Bug Bytes #86 – Stealing local files with Safari, Prototype pollution vs HTML sanitizers & A hacker’s mom learning bug bounty

Bug Business #10 – Get to know Intigriti content creator PentesterLand

Hacker Spotlight

Hacker Spotlight

August 27, 2020

Bug Business is a series of interviews in which experts from the bug bounty industry shine their light on bug types and trends. Mariem (PentesterLand) is the curator of our Bug Bytes newsletter. But she’s also a bug hunter. We sat down with her to talk about her background and her life as a hacker a

Continue reading: Bug Business #10 – Get to know Intigriti content creator PentesterLand

Bug Bytes #85 – Google Firebase keys worth $30K, How to find a mentor & Abusing Content-Type for WAF bypass & other shenanigans

Bug Bytes

Bug Bytes

August 26, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 14 to 21

Continue reading: Bug Bytes #85 – Google Firebase keys worth $30K, How to find a mentor & Abusing Content-Type for WAF bypass & other shenanigans

Bug Business #9 – Get to know pudsec, Intigriti’s Top Hacker in Q1 & Q2

Hacker Spotlight

Hacker Spotlight

August 20, 2020

Bug Business is a series of interviews in which experts from the bug bounty industry shine their light on bug types and trends. Shaun (pudsec) won third place in our leaderboard in both the first quarter of 2020 and the second quarter. An amazing achievement considering he is relatively new to bug b

Continue reading: Bug Business #9 – Get to know pudsec, Intigriti’s Top Hacker in Q1 & Q2

Bug Bytes #84 – From XSS to SSRF, Chaining bugs to RCE & Automation for mass recon and exploitation

Bug Bytes

Bug Bytes

August 19, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 07 to 14

Continue reading: Bug Bytes #84 – From XSS to SSRF, Chaining bugs to RCE & Automation for mass recon and exploitation

Bug Business #8 – Get to know Intigriti’s Top Hackers in Q2: kuromatae

Hacker Spotlight

Hacker Spotlight

August 13, 2020

Bug Business is a series of interviews in which experts from the bug bounty industry shine their light on bug types and trends. Today, we sat down with Anthony (kuromatae) who came in second in our leaderboard in the 2020 second quarter. He told us how he changed his life and is now living the Bug B

Continue reading: Bug Business #8 – Get to know Intigriti’s Top Hackers in Q2: kuromatae

Bug Bytes #83 – Web cache entanglement, SSRF via TLS, AST injection & New swag shop

Bug Bytes

Bug Bytes

August 12, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 31 of Jul

Continue reading: Bug Bytes #83 – Web cache entanglement, SSRF via TLS, AST injection & New swag shop

Swag for everyone: introducing our swag store!

Company News

News

August 10, 2020

Who doesn’t love hacker swag? At Intigriti, we’re not only rewarding our community members with monetary rewards up to €50.000, we are also distributing branded collectibles for our hackers to show their pride. Over the past few years, we have shipped more than a thousand swag packages all around th

Continue reading: Swag for everyone: introducing our swag store!

Bug Bytes #82 – Timeless timing attacks, Grafana SSRF, Pizza & Youtube delicacies

Bug Bytes

Bug Bytes

August 5, 2020

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 24 to 31

Continue reading: Bug Bytes #82 – Timeless timing attacks, Grafana SSRF, Pizza & Youtube delicacies

Bug Business #7 – Get to know _jca_, Intigriti’s Top Hacker in Q2

Hacker Spotlight

Hacker Spotlight

August 3, 2020

Bug Business is a series of interviews in which experts from the bug bounty industry shine their light on bug types and trends. Today, we sat down with Belgium-based Johan (_jca_) and discussed his recent successes in Bug Bounty, the methodologies and techniques he uses, and how his kids useless pil

Continue reading: Bug Business #7 – Get to know _jca_, Intigriti’s Top Hacker in Q2