Intigriti

@intigriti.com

Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍 linktr.ee/hackwithintigriti

Latest Bug Bytes is live! 🚀 This month's issue is as usual packed with bug bounty tips: ✅ Intigriti turns 10! ✅ RCE in GitHub and GitHub Enterprise Server ✅ Burp Suite going agentic with Burp AT ✅ Hacking Gemini Enterprise for $15,000 ✅ 3,708 live credentials found by scanning GitHub Archive

Bild

That's a wrap on #BugQuest! 🏁 Over the past 31 days, you've learned the fundamentals of finding and exploiting broken access control vulnerabilities. We've covered everything from authentication vs authorization basics to spotting subtle bypasses in code reviews.

Bild

Day 31 of #BugQuest! 😎 Yesterday, we covered Firefox Multi-Account Containers for manual testing across multiple user sessions. Today, we're wrapping up with Autorize, an open-source Burp Suite extension.

BildBildBild

Today marks day 29 of #BugQuest! 🤠 For those who’ve been following us along since the first day, we’re almost there! Just 2 more days left before you can go there and hack the planet (with BAC vulnerabilities)!

BildBildBild

Day 28 of #BugQuest! 🤠 Yesterday, we featured another code snippet, this time vulnerable to an algorithm confusion attack that allowed a malicious user to bypass signature validation entirely in insecure JWT implementations.

BildBildBild

Latest Bug Bytes is live! 🚀 This month's issue is as usual packed with bug bounty tips: ✅ Earning $180K via SSRFs ✅ Free Burp Suite Pro licenses for top hackers ✅ Bypassing tricky file upload restrictions ✅ Injecting malicious code into AI coding assistants + company news & much more! 😎

Bild

Day 26 of #BugQuest! 🤠 Yesterday's challenge featured a method-specific authorization check where GET requests were protected, but POST/PUT or any other requests bypassed the authorization entirely, allowing attackers to modify any user's profile data.

BildBildBild

Day 25 of #BugQuest! 🤠 Yesterday's challenge featured a static keyword swapping technique where the endpoint accepted both "my" and direct workspace IDs, allowing attackers to access other users' workspaces by bypassing a subtle oversight made by the developer.

BildBildBild

As Intigriti 0326 wraps up, we're releasing the official write-up for March’s CTF challenge! 🤠 KulinduKodi presented us with a secure search portal that required chaining a tricky DOM clobbering with a CSP bypass to achieve client-side code execution on the challenge page on behalf of the admin! 😎

Bild

Day 24 of #BugQuest! 🤠 Yesterday’s challenge involved spotting a common missing authorization check in an endpoint that allowed any bad user to view other people’s order data. Today's challenge is trickier! This vulnerability pattern was covered on Day 19, where we learned about REDACTED. 😎

BildBildBild

Day 25 of #BugQuest! 🤠 Yesterday's challenge featured a static keyword swapping technique where the endpoint accepted both "my" and direct workspace IDs, allowing attackers to access other users' workspaces by bypassing a subtle oversight made by the developer.

BildBildBild

Day 23 of #BugQuest! 🤠 Today also marks the start of the practice section of this series! Over the next week, we'll be featuring several vulnerable code snippets to help you spot more broken access controls. Let’s start easy! Can you spot the vulnerability in the following code snippet? 🐛

BildBildBild

Broken access controls can be quite complex to find... 😓 but sometimes surprisingly easy to exploit! 🤠 However, you must have the right methodology. 🧐 In our latest article, we break down what authorization flaws are, a 3-step methodology, and 7 proven broken access exploitation techniques! 🤠

Bild

Today marks day 21 of #BugQuest! 🤠 And we're covering one of the trickiest BAC vulnerability types that’s harder to spot. We all know that broken access controls do not always stem from a single endpoint that lacks authorization controls.

BildBildBild

Day 20 of #BugQuest! 🤠 Today, we're exploring one of the most critical authorization (and authentication) bypass techniques: JWT token manipulation. JWTs (JSON Web Tokens) are commonly implemented to manage authentication within web applications.

BildBildBild

Can you hack an AI bot? 🤠 If you want to find out if you've got what it takes to hack AI, come see our team at RSAC Booth S-1161! 🧐 🔥 Three difficulty levels 🏆 Three top-tier prizes 🧠 One question... Can you think like a hacker? 😎

Bild

Today marks day 18 of #BugQuest! 🤠 And we're exploring two interesting techniques that can help us exploit BAC flaws in applications that fail to handle user input delivered in an unexpected manner.

BildBildBild

Day 17 of #BugQuest! 🔄 Yesterday, we covered the core BAC testing methodology. Today, we're diving into a specific exploitation technique. Developers often implement authorization checks for each HTTP method and app route, but often overlook others.

BildBildBild

Today marks day 16 of #BugQuest and the start of the exploitation section! 🎯 We've spent two weeks building the foundation and discovering endpoints. Now comes the fun part, actually breaking authorization checks and exploiting BAC vulnerabilities.

BildBildBild