Researchers’ blog

Subscribe to our RRS feed to stay up-to-date with our latest blog articles for researchers.

Bug Bytes #35 – DerbyCon Roundup, From Zero To Admin & Same-Origin Summarised

Bug Bytes

Bug Bytes

September 10, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #35 – DerbyCon Roundup, From Zero To Admin & Same-Origin Summarised

Bug Bytes #34 – Challenge Winner, Bounty Economy and CSRF bible

Bug Bytes

Bug Bytes

September 3, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #34 – Challenge Winner, Bounty Economy and CSRF bible

Bug Bytes #33 – SSRF going wild, intigriti’s new challenge & JSON CSRF

Bug Bytes

Bug Bytes

August 27, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #33 – SSRF going wild, intigriti’s new challenge & JSON CSRF

Bug Bytes #32 – XSS in Google.org, Burp Teams & Paged out!

Bug Bytes

Bug Bytes

August 20, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #32 – XSS in Google.org, Burp Teams & Paged out!

Bug Bytes #31 – HTTP Desync Attacks by @albinowax, Exploiting Out Of Band XXE by @Zombiehelp54, GitHub Recon and Sensitive Data Exposure

Bug Bytes

Bug Bytes

August 13, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #31 – HTTP Desync Attacks by @albinowax, Exploiting Out Of Band XXE by @Zombiehelp54, GitHub Recon and Sensitive Data Exposure

Bug Bytes #30 – Chaining Cache Poisoning To Stored XSS, How To Bypass Cloudflare’s WAF & Ghostwriter by SpecterOps

Bug Bytes

Bug Bytes

August 6, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #30 – Chaining Cache Poisoning To Stored XSS, How To Bypass Cloudflare’s WAF & Ghostwriter by SpecterOps

Bug Bytes #29 – Why do Penetration Testing Teams Hate You, SSL/TLS vulnerabilities & A Deep Dive into XXE Injection

Bug Bytes

Bug Bytes

July 30, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #29 – Why do Penetration Testing Teams Hate You, SSL/TLS vulnerabilities & A Deep Dive into XXE Injection

Bugbytes #28 – Wireshark over SSH, Pwning New Relic & Filter Fun with @zseano

Bug Bytes

Bug Bytes

July 23, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bugbytes #28 – Wireshark over SSH, Pwning New Relic & Filter Fun with @zseano

Bug Bytes #27 – Secretz, Privilege Escalation on New Relic & How To Keep Your Bugs Organised

Bug Bytes

Bug Bytes

July 15, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: Bug Bytes #27 – Secretz, Privilege Escalation on New Relic & How To Keep Your Bugs Organised

Bug Bytes #26 – File upload to SQLi, Google’s CTF & Data Breach 101

Bug Bytes

Bug Bytes

July 9, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #26 – File upload to SQLi, Google’s CTF & Data Breach 101

BugBytes #25 – To scan or not to scan, GOTCHA and live mentoring by @zseano

Bug Bytes

Bug Bytes

July 2, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. This issue co

Continue reading: BugBytes #25 – To scan or not to scan, GOTCHA and live mentoring by @zseano

The Bug Bounty Bucket List

Bug Bytes

Bug Bytes

July 1, 2019

Summer vacation has started and this is the ideal moment to sharpen some of your bug bounty skills. We’ve made a bucket list with 20 actionable goals for the summer break – how many can you scratch off? Find a blind XSS in something else than a contact form. There are lots of potential vectors to in

Continue reading: The Bug Bounty Bucket List

Bug Bytes #24 – VIM made easy by @TomNomnom, @jon_bottarini’s hunt for hidden features & Rock-ON

Bug Bytes

Bug Bytes

June 25, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #24 – VIM made easy by @TomNomnom, @jon_bottarini’s hunt for hidden features & Rock-ON

Bug Bytes #23 – 20K IDOR Trick, Bug Bounty Vloggers everywhere & Persistent Burp Collaborator

Bug Bytes

Bug Bytes

June 18, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #23 – 20K IDOR Trick, Bug Bounty Vloggers everywhere & Persistent Burp Collaborator

Bug Bytes #22 – Disabling distracting Firefox traffic from Burp, A 2019 Workflow for Subdomain Enumeration by @0xpatrik & DirectoryImporter

Bug Bytes

Bug Bytes

June 11, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #22 – Disabling distracting Firefox traffic from Burp, A 2019 Workflow for Subdomain Enumeration by @0xpatrik & DirectoryImporter

Bug Bytes #21 – Automation of the recon process by @armaancrockroax, stored XSS via MIME sniffing & building virtual machine labs

Bug Bytes

Bug Bytes

June 4, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #21 – Automation of the recon process by @armaancrockroax, stored XSS via MIME sniffing & building virtual machine labs

Bug Bytes #20 – Another LFI on Google, Turning your time into bugs by @Zseano & Live Hacking like a MVH by @fransrosen

Bug Bytes

Bug Bytes

May 28, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #20 – Another LFI on Google, Turning your time into bugs by @Zseano & Live Hacking like a MVH by @fransrosen

How our community hacked our own XSS challenge

Company News

News

May 27, 2019

Following the succes of our first XSS challenge, we decided to treat our Twitter followers for another game of “spot the cross-site scripting vulnerability”: NEW CHALLENGE: We're giving away a Burp Pro license, swag & invites to celebrate 5k followers! 🤩💙 Claim your prize: 👉 https://t.co/KYQHSOpG

Continue reading: How our community hacked our own XSS challenge

Bug Bytes #19 – The Real Impact of Open Redirect, Advanced CORS Exploitation Techniques & Common API Pitfalls

Bug Bytes

Bug Bytes

May 21, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: Bug Bytes #19 – The Real Impact of Open Redirect, Advanced CORS Exploitation Techniques & Common API Pitfalls

BugBytes #18 – Information disclosure on Shopify, Awesome Asset Discovery & How To Work Smarter Not Harder with Bug Bounty

Bug Bytes

Bug Bytes

May 14, 2019

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The first series are curated by Mariem, better known as PentesterLand. Every week, she keeps us updated with a comprehensive list of all write-ups, tools, tutorials and resources we should not have missed. Hey hackers!

Continue reading: BugBytes #18 – Information disclosure on Shopify, Awesome Asset Discovery & How To Work Smarter Not Harder with Bug Bounty