Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

Bug Bytes #53 – Exploiting a SSRF in WeasyPrint, The Bug That Exposed Your PayPal Password and 12 tricks for Burp Repeater

Bug Bytes

Bug Bytes

January 14, 2020

Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week. Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensiv

Continue reading: Bug Bytes #53 – Exploiting a SSRF in WeasyPrint, The Bug That Exposed Your PayPal Password and 12 tricks for Burp Repeater

Bug Bytes #52 – Account takeover via HTTP Request Smuggling, Lesser-known Tools for Android Application PenTesting and Hunting Credentials and Secrets in iOS Apps

Bug Bytes

Bug Bytes

January 7, 2020

Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week. Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensiv

Continue reading: Bug Bytes #52 – Account takeover via HTTP Request Smuggling, Lesser-known Tools for Android Application PenTesting and Hunting Credentials and Secrets in iOS Apps

Bug Bytes #51 – ArneSwinnen’s secrets, Hunting in the Dark & OSINT movie picks

Bug Bytes

Bug Bytes

December 31, 2019

Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week. Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensiv

Continue reading: Bug Bytes #51 – ArneSwinnen’s secrets, Hunting in the Dark & OSINT movie picks

The Best Write-ups that 2019 Brought Us

Web & API Hacking

Hacking Tools

December 30, 2019

Link: https://eng.getwisdom.io/hacking-github-with-unicode-dotless-i/ Author: @wisdom_devs Your application can support as many languages you like: in the end, your webserver will only process 1’s and 0’s. Normalization is everywhere and can attribute to situational and unique security issues, which

Continue reading: The Best Write-ups that 2019 Brought Us

Bug Bytes #50 – Null Bytes Worth $40K, Getting Your First Bug & Tab Tricks

Bug Bytes

Bug Bytes

December 24, 2019

Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week. Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensiv

Continue reading: Bug Bytes #50 – Null Bytes Worth $40K, Getting Your First Bug & Tab Tricks

Bug Bytes #49 – WHY YOUR HACKING QUESTIONS ARE FRUSTRATING!!! (and more)

Bug Bytes

Bug Bytes

December 17, 2019

Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week. Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensiv

Continue reading: Bug Bytes #49 – WHY YOUR HACKING QUESTIONS ARE FRUSTRATING!!! (and more)

Bug Bytes #48 – 20 char XSS, HackerOne accidental account takeover & one-time ☎️

Bug Bytes

Bug Bytes

December 10, 2019

Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week. Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensiv

Continue reading: Bug Bytes #48 – 20 char XSS, HackerOne accidental account takeover & one-time ☎️

Bug Bytes #47 – SecTalks, My First RCE, Smuggler.py and interview with @0xacb

Bug Bytes

Bug Bytes

December 5, 2019

Hey hackers! These are our favorite resources shared by pentesters and bug hunters last week. Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensiv

Continue reading: Bug Bytes #47 – SecTalks, My First RCE, Smuggler.py and interview with @0xacb

Bug Bytes #46 – Steal customer data via CORS Misconfiguration, Dnsexpire.py and #BadBugBountyPickupLines

Bug Bytes

Bug Bytes

November 28, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. Hey hackers! These are our favorite resou

Continue reading: Bug Bytes #46 – Steal customer data via CORS Misconfiguration, Dnsexpire.py and #BadBugBountyPickupLines

Bug Bytes #45 – DEFCON 27 Recap, JWT Playbook, Leaky repo & new XSS challenge

Bug Bytes

Bug Bytes

November 19, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. Hey hackers! These are our favorite resou

Continue reading: Bug Bytes #45 – DEFCON 27 Recap, JWT Playbook, Leaky repo & new XSS challenge

Bug Bytes #44 – New platform, new programs and a $25K HEAD CSRF

Bug Bytes

Bug Bytes

November 12, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. Hey hackers! These are our favorite resou

Continue reading: Bug Bytes #44 – New platform, new programs and a $25K HEAD CSRF

Bug Bytes #43 – Abusing HTTP hop-by-hop request headers, The Bug Bounty Podcast by @Regala_ & Live Bug Bounty Recon Session on Verizon Media’s Yahoo.com W/ @Securinti

Bug Bytes

Bug Bytes

November 5, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series is curated by Mariem, better known as PentesterLand. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources. This issue covers the week from 25th of O

Continue reading: Bug Bytes #43 – Abusing HTTP hop-by-hop request headers, The Bug Bounty Podcast by @Regala_ & Live Bug Bounty Recon Session on Verizon Media’s Yahoo.com W/ @Securinti

Bug Bytes #42 – XML to RCE, GitHub for Recon & Cloud Hacking Heaven

Bug Bytes

Bug Bytes

October 29, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #42 – XML to RCE, GitHub for Recon & Cloud Hacking Heaven

Introducing our new platform: what to expect

Company News

Product Updates

October 23, 2019

We are nearing the launch date of our brand new platform and are glad to give you a first view on what is to come, while we are polishing the release version of the new application. We aim to release in the weeks to come, so make sure to keep an eye on our progress and plans on our blog. Please be a

Continue reading: Introducing our new platform: what to expect

Bug Bytes #41 – Reading JS, Pwning Spread Sheet Conversions & EdOverflow’s CSP tool

Bug Bytes

Bug Bytes

October 22, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #41 – Reading JS, Pwning Spread Sheet Conversions & EdOverflow’s CSP tool

Bug Bytes #40 – Third Level Domains, LevelUp 0x05 & Authorization Token Manipulation

Bug Bytes

Bug Bytes

October 15, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #40 – Third Level Domains, LevelUp 0x05 & Authorization Token Manipulation

Bug Bytes #39 – HTTP Desync Attacks 2.0, Google Sponsors Vulnerability Disclosure & 7 New Tools

Bug Bytes

Bug Bytes

October 8, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #39 – HTTP Desync Attacks 2.0, Google Sponsors Vulnerability Disclosure & 7 New Tools

Bug Bytes #38 – New XSS Challenge, {{7*7}} to {{P1}} & the ultimate XSS payload generator

Bug Bytes

Bug Bytes

October 1, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #38 – New XSS Challenge, {{7*7}} to {{P1}} & the ultimate XSS payload generator

Bug Bytes #37 – How to find more IDORs, Race Condition to RCE & Tracy

Bug Bytes

Bug Bytes

September 24, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #37 – How to find more IDORs, Race Condition to RCE & Tracy

Bug Bytes #36 – Hacking a University, XSS to RCE & Bypassing LinkedIn Rate Limits

Bug Bytes

Bug Bytes

September 17, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #36 – Hacking a University, XSS to RCE & Bypassing LinkedIn Rate Limits