BLUE
JK
James Kettle
@jameskettle.com
Director of Research at PortSwigger aka Burp Suite Sometimes known as albinowax Portfolio: jameskettle.com/
362 followers10 following33 posts
JKjameskettle.com

That triage journey is not pretty

1
Reposted by James Kettle
GHhandle.invalid

I'm delighted to announce that I'll be presenting: "Splitting the email atom: exploiting parsers to bypass access controls" at Blackhat USA Check out the abstract for more details: www.blackhat.com/us-24/briefi...

Black Hat USA 2024
Black Hat USA 2024

Black Hat USA 2024

0
JKjameskettle.com

I'm thrilled to announce "Listen to the whispers: web timing attacks that actually work" will premiere at Black Hat USA!   After nine months of running bulk timing attacks on thousands of live sites, I've got a lot to share! Check out the abstract here: www.blackhat.com/us-24/briefi...

Black Hat USA 2024
Black Hat USA 2024

Black Hat USA 2024

0
JKjameskettle.com

We've just published "Making desync attacks easy with TRACE" by new PortSwigger Research member Martin Doyenhard! portswigger.net/research/tra...

1
JKjameskettle.com

Yeah, I didn't explore the DoS angle much but it's definitely there, especially with the ability to overrun rate-limits and weak locking systems

0
JKjameskettle.com

Just submitted my talk proposal to Black Hat USA! This year I went all-in on a risky topic, and landed a beautiful range of findings from 'practical' to 'aspirational' :)

0
JKjameskettle.com

Voting is now live for the Top ten web hacking techniques of 2023! Make a brew, browse the nominations, and cast your vote here: portswigger.net/polls/top-10...

0
JKjameskettle.com

We've just launched a new topic on Web LLM Attacks! If you've never exploited indirect prompt injection, you're missing out on some serious fun. Have a shot at the labs here: portswigger.net/web-security...

Web LLM attacks | Web Security Academy
Web LLM attacks | Web Security Academy

Organizations are rushing to integrate Large Language Models (LLMs) in order to improve their online customer experience. This exposes them to web LLM ...

0
JK
James Kettle
@jameskettle.com
Director of Research at PortSwigger aka Burp Suite Sometimes known as albinowax Portfolio: jameskettle.com/
362 followers10 following33 posts