Elektrine lite

← Feed

James Kettle

albinowax@infosec.exchange

<p>Director of Research at PortSwigger aka <br />Burp Suite</p>

Posts

  • Post #4394645

    The whitepaper is live! Read &quot;Can AI Do Novel Security Research? Meet the HTTP Terminator&quot; here: https://portswigger.net/research/http-terminator

  • Post #4254254

    In &quot;Can AI Do Novel Security Research?&quot; I&#39;ll share: - A research-machine blueprint for AI enthusiasts - Clearly defined AI fail-points for AI dodgers - Extensive insight into what makes security research work - Many many novel desync goodies I&#39;ll also publish major updates to Turbo Intruder, Param Miner and HTTP Request Smuggler. Plus the full source of the HTTP Terminator itself. Choose your own adventure :)

  • Post #4162289

    Next week I&#39;ll present &quot;Can AI Do Novel Security Research? Meet the HTTP Terminator&quot; at DEF CON &amp; Black Hat USA! I&#39;m really excited to share this one - got some spectacular outcomes from a wild research journey. See you there! #DEFCON

  • Post #1881307

    I just did an interview with Application Security Weekly with teasers for my upcoming #BHUSA presentation &amp;quot;Can AI Do Novel Vulnerability Research: Meet the HTTP Terminator&amp;quot;, plus reflections on the Top Ten Web Hacking Techniques of 2025 &amp;amp; 2026. Watch it here: https://www.youtube.com/watch?v=fOWhhTrGtoI

  • Post #1714842

    You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!

  • Post #1714841

    Turbo Intruder now has API docs! You can easily discover its many advanced features including - pauseMarker for pause-basd desync.. or DoS - decorators for easy response filtering - &amp;#39;randomPlz&amp;#39; - wordlists.clipboard for lazy attack setup ...and many more! https://github.com/PortSwigger/turbo-intruder/blob/dev/docs/index.md

  • Post #1714840

    Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions &amp;amp; make your own nominations here: https://portswigger.net/research/top-10-web-hacking-techniques-of-2025-nominations-open

  • Post #1714838

    Voting is now live for the top ten web hacking techniques of 2025! Grab a brew, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques: https://portswigger.net/polls/top-10-web-hacking-techniques-2025

  • Post #1714837

    Love web &amp;amp; AI security research? Want to do it full time on-site with myself, Gareth Heyes &amp;amp; Zak Fedotkin? Join the PortSwigger Research team - we&amp;#39;re hiring! https://apply.workable.com/portswigger/j/FC27ED6166/

  • Post #1714833

    Access control bypass via header smuggling, with no desync required! Using header smuggling for more than HTTP desync like this is totally underrated - a lot of defences only filter the CL and TE headers. You can detect these with Parser Discrepancy Scan. https://www.linkedin.com/posts/jakedmurphy1_excited-to-share-that-i-recently-identified-activity-7431735557115789313-xhnA/

  • Post #1714832

    I&amp;#39;ve just submitted my latest research to Black Hat USA! This one has been cooking since last June, can&amp;#39;t wait to share it with the world... in fact I&amp;#39;m quite excited just to see the community reaction to the title reveal.

  • Post #1714831

    How is every doing? I wouldn&amp;#39;t call it comfortable, but I&amp;#39;m starting to savor the experience of rediscovering where the new frontier is, every few weeks. It feels like replaying the early stages of my research career. Looking forward to making my own contribution at #BHUSA!🤞

  • Post #1182924

    Have you ever been tempted to dive down the security research rabbit-hole? I&amp;#39;ll be sharing insights on how to navigate the rewards and hazards with legendary researchers Natalie Silvanovich and @raistlin in a community panel session at Black Hat USA next week!

  • Post #1165582

    I&amp;#39;m thrilled to announce &amp;quot;Can AI Do Novel Security Research? Meet the HTTP Terminator&amp;quot; will premiere at Black Hat USA! Check out the abstract: https://blackhat.com/us-26/briefings/schedule/?#can-ai-do-novel-security-research-meet-the-http-terminator-51894

  • Post #452140

    The voting has concluded, and we&amp;#39;re thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! https://portswigger.net/research/top-10-web-hacking-techniques-of-2025