| | What's in a tag name? JavaScript, apparently (portswigger.net) |
| 3 points by torutofu 32 days ago | past |
|
| | CRLF-Powered Desync Attacks: Beheading HTTP Streams (portswigger.net) |
| 3 points by chillax 37 days ago | past |
|
| | Can AI do novel security research? Meet the HTTP Terminator (portswigger.net) |
| 1 point by mahemm 45 days ago | past | 1 comment |
|
| | CSS: The bomb inside your inbox (portswigger.net) |
| 101 points by ashurandi 49 days ago | past | 44 comments |
|
| | CSS: The bomb inside your inbox (portswigger.net) |
| 2 points by OuterVale 50 days ago | past | 1 comment |
|
| | Cookie Chaos: How to bypass __Host and __Secure cookie prefixes (portswigger.net) |
| 3 points by one33seven 57 days ago | past |
|
| | The Fragile Lock: Novel Bypasses for SAML Authentication (portswigger.net) |
| 3 points by todsacerdoti 9 months ago | past |
|
| | HTTP desync attacks: request smuggling reborn (portswigger.net) |
| 3 points by fanf2 11 months ago | past |
|
| | Cookie Chaos: How to bypass __Host and __Secure cookie prefixes (portswigger.net) |
| 2 points by todsacerdoti on Sept 3, 2025 | past | 1 comment |
|
| | Inline Style Exfiltration: leaking data with chained CSS conditionals (portswigger.net) |
| 1 point by pentestercrab on Aug 27, 2025 | past |
|
| | HTTP/1.1 must die: the desync endgame (portswigger.net) |
| 42 points by sprawl_ on Aug 15, 2025 | past | 25 comments |
|
| | HTTP/2: The Sequel is Always Worse (portswigger.net) |
| 7 points by quicksilver03 on Aug 9, 2025 | past |
|
| | HTTP/1.1 must die: the desync endgame (portswigger.net) |
| 3 points by jsnell on Aug 8, 2025 | past |
|
| | HTTP/1.1 must die: the desync endgame (portswigger.net) |
| 7 points by 882542F3884314B on Aug 7, 2025 | past | 2 comments |
|
| | HTTP/1.1 must die: the desync endgame (portswigger.net) |
| 17 points by octagons on Aug 7, 2025 | past | 2 comments |
|
| | Drag and Pwnd: Exploiting VS Code with ASCII (portswigger.net) |
| 1 point by albinowax_ on May 7, 2025 | past |
|
| | Welcome to the next generation of Burp Suite: elevate your testing with Burp AI (portswigger.net) |
| 2 points by thomas34298 on April 3, 2025 | past |
|
| | PESDv2 – diagram Burp traffic instantly with customizable Markdown/themes (portswigger.net) |
| 1 point by tony-ds on Feb 6, 2025 | past |
|
| | Top web hacking techniques of 2024 (portswigger.net) |
| 3 points by chillax on Feb 5, 2025 | past |
|
| | Splitting the email atom: exploiting parsers to bypass access controls (2024) (portswigger.net) |
| 1 point by frizlab on Jan 30, 2025 | past |
|
| | Stealing HttpOnly cookies with the cookie sandwich technique (portswigger.net) |
| 6 points by chillax on Jan 23, 2025 | past |
|
| | Listen to the whispers: web timing attacks that work (portswigger.net) |
| 188 points by saikatsg on Nov 21, 2024 | past | 33 comments |
|
| | New Doyensec Prototype Pollution BurpSuite Extension (portswigger.net) |
| 2 points by tony-ds on Oct 24, 2024 | past |
|
| | Listen to the whispers: web timing attacks that work (portswigger.net) |
| 2 points by rrampage on Sept 25, 2024 | past |
|
| | Splitting the email atom: exploiting parsers to bypass access controls (portswigger.net) |
| 2 points by hackvertor on Sept 5, 2024 | past | 1 comment |
|
| | Listen to the whispers: web timing attacks that work (portswigger.net) |
| 5 points by dytir on Aug 8, 2024 | past |
|
| | Listen to the whispers: web timing attacks that work (portswigger.net) |
| 3 points by chillax on Aug 7, 2024 | past |
|
| | SignSaboteur: forge signed web tokens with ease (portswigger.net) |
| 2 points by jdmark on May 23, 2024 | past |
|
| | HTTP/2 desync attacks. (2021) (portswigger.net) |
| 1 point by fanf2 on April 3, 2024 | past |
|
| | uBlock, I exfiltrate: exploiting ad blockers with CSS (2021) (portswigger.net) |
| 3 points by ReadCarlBarks on March 29, 2024 | past |
|
|
| More |