Making HTTP header injection critical via response queue...
portswigger.net
makinghttpheadervia
Top 10 web hacking techniques of 2021 | PortSwigger Research
portswigger.net
topwebhacking
Breaking the chains on HTTP Request Smuggler | PortSwigger...
portswigger.net
http requestchains
Top 10 web hacking techniques of 2019 | PortSwigger Research
portswigger.net
topwebhacking
ZAP – PortSwigger Labs: Username Enumeration with ZAP Scripts
www.zaproxy.org
zapportswiggerlabs
Hunting evasive vulnerabilities | PortSwigger Research
portswigger.net
huntingevasive
Top 10 web hacking techniques of 2018 | PortSwigger Research
portswigger.net
topwebhacking
Practical Web Cache Poisoning | PortSwigger Research
portswigger.net
practicalwebcache
HTTP Desync Attacks: what happened next | PortSwigger Research
portswigger.net
httpattackshappened
HTTP/3 connection contamination: an upcoming threat...
portswigger.net
httpconnection
The single-packet attack: making remote race-conditions 'local...
portswigger.net
singlepacketattack
HTTP/2: The Sequel is Always Worse | PortSwigger Research
portswigger.net
httpsequelalways
AngularJS CSP bypass in 56 characters | PortSwigger Research
portswigger.net
angularjscspbypass
Server-Side Prototype Pollution Scanner - PortSwigger
portswigger.net
server sidescanner
Refining your HTTP perspective, with bambdas | PortSwigger...
portswigger.net
refininghttp
JavaScript without parentheses using DOMMatrix | PortSwigger...
portswigger.net
javascriptwithout
Bypassing CSP using polyglot JPEGs | PortSwigger Research
portswigger.net
cspusingpolyglot
ZAP – PortSwigger Labs: Password Brute-force via Password...
www.zaproxy.org
brute forcezaplabs
Burp Scanner - Web Vulnerability Scanner from PortSwigger
portswigger.net
burpscannerweb
Finding DOM Polyglot XSS in PayPal the Easy Way | PortSwigger...
portswigger.net
findingdompolyglot
Server-Side Template Injection | PortSwigger Research
portswigger.net
server sidetemplate
Top 10 web hacking techniques of 2020 | PortSwigger Research
portswigger.net
topwebhacking
ZAP – PortSwigger Labs: 2FA Broken Logic
www.zaproxy.org
zapportswiggerlabs
Top 10 web hacking techniques of 2024 | PortSwigger Research
portswigger.net
topwebhacking
HTTP Desync Attacks: Request Smuggling Reborn | PortSwigger...
portswigger.net
httpattacksrequest
Evading defences using VueJS script gadgets | PortSwigger...
portswigger.net
defencesusingvuejs
Top 10 web hacking techniques of 2022 | PortSwigger Research
portswigger.net
topwebhacking
Turbo Intruder: Embracing the billion-request attack...
portswigger.net
turbointruderattack
The curl quirk that exposed Burp Suite & Google Chrome...
portswigger.net
burp suitecurlquirk
Web Security Blog - PortSwigger
portswigger.net
web securityblog
Backslash Powered Scanning: hunting unknown vulnerability...
portswigger.net
poweredscanning
PortSwigger
discord.com
portswigger
HTTP/1.1 must die: the desync endgame | PortSwigger Research
portswigger.net
httpmustdieendgame
Top 10 web hacking techniques of 2023 | PortSwigger Research
portswigger.net
topwebhacking
XSS without HTML: Client-Side Template Injection with AngularJS...
portswigger.net
client sidexsshtml
When security features collide | PortSwigger Research
portswigger.net
security features
A hacking hat-trick: previewing three PortSwigger Research...
portswigger.net
hat trickhacking
How I accidentally framed myself for a hacking frenzy...
portswigger.net
accidentallyframed
Introducing the URL validation bypass cheat sheet | PortSwigger...
portswigger.net
cheat sheeturl
So you want to be a web security researcher? | PortSwigger...
portswigger.net
web securitywant
Adapting Burp extensions for tailored pentesting | PortSwigger...
portswigger.net
adaptingburp
Bypassing Web Cache Poisoning Countermeasures | PortSwigger...
portswigger.net
webcachepoisoning
Cracking the lens: targeting HTTP's hidden attack-surface...
portswigger.net
attack surfacelens
Portable Data exFiltration: XSS for PDFs | PortSwigger Research
portswigger.net
portabledataxsspdfs
Inline Style Exfiltration: leaking data with chained CSS...
portswigger.net
inlinestyleleaking
How I choose a security research topic | PortSwigger Research
portswigger.net
security research
Cracking reCAPTCHA, Turbo Intruder style | PortSwigger Research
portswigger.net
crackingrecaptcha
Shadow Repeater:AI-enhanced manual testing | PortSwigger Research
portswigger.net
ai enhancedshadow
Responsible denial of service with web cache poisoning...
portswigger.net
responsibledenial
Exploiting CORS misconfigurations for Bitcoins and bounties...
portswigger.net
exploitingcors
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine...
portswigger.net
websocketturbo
Web Cache Entanglement: Novel Pathways to Poisoning...
portswigger.net
webcachenovel
SAML roulette: the hacker always wins | PortSwigger Research
portswigger.net
samlroulettehacker
XSS in hidden input fields | PortSwigger Research
portswigger.net
xsshiddeninput
Top 10 Web Hacking Techniques of 2017 | PortSwigger Research
portswigger.net
topwebhacking
Finding that one weird endpoint, with Bambdas | PortSwigger...
portswigger.net
findingoneweird
ZAP – PortSwigger Labs: Broken Brute-Force Protection, IP Block
www.zaproxy.org
brute forcezaplabs
Detecting and exploiting path-relative stylesheet import...
portswigger.net
exploitingpath