Director of Research at PortSwigger aka Burp Suite
Director of Research at PortSwigger aka
Burp Suite
Posts
Director of Research at PortSwigger aka Burp Suite
In "Can AI Do Novel Security Research?" I'll share:
- A research-machine blueprint for AI enthusiasts
- Clearly defined AI fail-points for AI dodgers
- Extensive insight into what makes security research work
- Many many novel desync goodies
I'll also publish major updates to Turbo Intruder, Param Miner and HTTP Request Smuggler. Plus the full source of the HTTP Terminator itself. Choose your own adventure :)
Director of Research at PortSwigger aka Burp Suite
Director of Research at PortSwigger aka Burp Suite
I just did an interview with Application Security Weekly with teasers for my upcoming #BHUSA presentation "Can AI Do Novel Vulnerability Research: Meet the HTTP Terminator", plus reflections on the Top Ten Web Hacking Techniques of 2025 & 2026. Watch it here:
https://www.youtube.com/watch?v=fOWhhTrGtoI
Director of Research at PortSwigger aka Burp Suite
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract:
https://blackhat.com/us-26/briefings/schedule/?#can-ai-do-novel-security-research-meet-the-http-terminator-51894
Director of Research at PortSwigger aka Burp Suite
How is every doing? I wouldn't call it comfortable, but I'm starting to savor the experience of rediscovering where the new frontier is, every few weeks. It feels like replaying the early stages of my research career. Looking forward to making my own contribution at #BHUSA!🤞
Director of Research at PortSwigger aka Burp Suite
I've just submitted my latest research to Black Hat USA! This one has been cooking since last June, can't wait to share it with the world... in fact I'm quite excited just to see the community reaction to the title reveal.
Director of Research at PortSwigger aka Burp Suite
Access control bypass via header smuggling, with no desync required! Using header smuggling for more than HTTP desync like this is totally underrated - a lot of defences only filter the CL and TE headers. You can detect these with Parser Discrepancy Scan.
https://www.linkedin.com/posts/jakedmurphy1_excited-to-share-that-i-recently-identified-activity-7431735557115789313-xhnA/
Director of Research at PortSwigger aka Burp Suite
The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! https://portswigger.net/research/top-10-web-hacking-techniques-of-2025
Director of Research at PortSwigger aka Burp Suite
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring!
Director of Research at PortSwigger aka Burp Suite
Voting is now live for the top ten web hacking techniques of 2025! Grab a brew, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques:
https://portswigger.net/polls/top-10-web-hacking-techniques-2025
Director of Research at PortSwigger aka Burp Suite
Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions & make your own nominations here: https://portswigger.net/research/top-10-web-hacking-techniques-of-2025-nominations-open
Director of Research at PortSwigger aka Burp Suite
Turbo Intruder now has API docs! You can easily discover its many advanced features including
- pauseMarker for pause-basd desync.. or DoS
- decorators for easy response filtering
- 'randomPlz'
- wordlists.clipboard for lazy attack setup
...and many more!
https://github.com/PortSwigger/turbo-intruder/blob/dev/docs/index.md
Director of Research at PortSwigger aka Burp Suite
You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!
Director of Research at PortSwigger aka Burp Suite
Director of Research at PortSwigger aka Burp Suite
Have you ever been tempted to dive down the security research rabbit-hole? I'll be sharing insights on how to navigate the rewards and hazards with legendary researchers Natalie Silvanovich and @raistlin@sociale.network in a community panel session at Black Hat USA next week!