James Kettle

@albinowax

Director of Research at PortSwigger Web Security aka

Manchester, England
Vrijeme pridruživanja: siječanj 2010.

Medijski sadržaj

  1. 6. pro 2019.
    Odgovor korisniku/ci

    This is with the same settings as you, targeting /robots.txt:

  2. 18. stu 2019.

    The definitive recording of HTTP Desync Attacks is now live, courtesy of !

  3. 10. lis 2019.

    I previously posted that the links to Medium from go via a redirect to hxxps://rsci.app.link/ which intermittently demands people's phone numbers. It was a mistake to tag - turns out the root cause of this horrifying behaviour is Medium's official iOS app!

  4. 13. ruj 2019.

    HTTP Desync Attacks is now out on YouTube, courtesy of and

    Prikaži ovu nit
  5. 14. kol 2019.

    Backslash Powered Scanner can now detect proxy subfolder escapes using 's path normalization research from last year - just enable 'experimental folder attacks'.

  6. 27. lip 2019.
    Odgovor korisnicima

    It already does. If you're not seeing interactions, it's probably because the client is trying to connect over HTTPS and the certificate won't be valid. You should still get a DNS interaction though.

  7. 3. tra 2019.

    While reading this top notch report in 2012, I really didn't expect it'd still be trivial to exploit Firefox in 2019...

  8. 2. tra 2019.

    After a wild few months of research, I've just submitted to ! I can't do this research justice with words, so here's a screenshot:

  9. 22. ožu 2019.
  10. 8. velj 2019.

    With Turbo Intruder 1.0.4 you can now selectively import findings into the sitemap, and save attacks as scan-issues. Fully automated Burp integration is possible from within scripts: Also, it's very slightly faster :)

  11. 31. sij 2019.

    Here's how to perform a multi-host vhost guessing attack with Turbo Intruder's speed & diffing logic: cc

  12. 23. sij 2019.
    Odgovor korisniku/ci

    Nice find! Looks like inline comments work too. RIP WAFs

  13. 19. sij 2019.

    Just about prepped for my Turbo Intruder stream. Watch it live here - kickoff in two hours:

  14. 16. sij 2019.

    Here's a teaser screenshot from my upcoming LevelUp presentation on Turbo Intruder. Watch it streamed live this Saturday at 1300 PT

  15. 6. pro 2018.

    Good news for people on small screens - Param Miner's config window now conforms to society's monitor-orientation ideals.

  16. 22. stu 2018.

    Hi , are you really sending a direct copy+paste of the blind XSS payload developed for ?

    Prikaži ovu nit
  17. 29. lis 2018.

    Unsure if a response is being cached? If it has a Set-Cookie header, request it twice and see if the header disappears in the second response.

  18. 8. lis 2018.

    The key new feature in today's Param Miner update is 'fuzz detect' which appends <a`'"${{\ to input values to try and detect better-hidden params. It's disabled by default because such headers upset various systems including a certain well known social network.

  19. 12. ruj 2018.

    Hahaha of course this server supports a HTTP header called 'GDPR'.

  20. 3. ruj 2018.

    Neat, the official recording of Practical Web Cache Poisoning is now online

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·