Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
What's in a tag name? JavaScript, apparently (portswigger.net)
3 points by torutofu 32 days ago | past
CRLF-Powered Desync Attacks: Beheading HTTP Streams (portswigger.net)
3 points by chillax 37 days ago | past
Can AI do novel security research? Meet the HTTP Terminator (portswigger.net)
1 point by mahemm 45 days ago | past | 1 comment
CSS: The bomb inside your inbox (portswigger.net)
101 points by ashurandi 49 days ago | past | 44 comments
CSS: The bomb inside your inbox (portswigger.net)
2 points by OuterVale 50 days ago | past | 1 comment
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes (portswigger.net)
3 points by one33seven 57 days ago | past
The Fragile Lock: Novel Bypasses for SAML Authentication (portswigger.net)
3 points by todsacerdoti 9 months ago | past
HTTP desync attacks: request smuggling reborn (portswigger.net)
3 points by fanf2 11 months ago | past
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes (portswigger.net)
2 points by todsacerdoti on Sept 3, 2025 | past | 1 comment
Inline Style Exfiltration: leaking data with chained CSS conditionals (portswigger.net)
1 point by pentestercrab on Aug 27, 2025 | past
HTTP/1.1 must die: the desync endgame (portswigger.net)
42 points by sprawl_ on Aug 15, 2025 | past | 25 comments
HTTP/2: The Sequel is Always Worse (portswigger.net)
7 points by quicksilver03 on Aug 9, 2025 | past
HTTP/1.1 must die: the desync endgame (portswigger.net)
3 points by jsnell on Aug 8, 2025 | past
HTTP/1.1 must die: the desync endgame (portswigger.net)
7 points by 882542F3884314B on Aug 7, 2025 | past | 2 comments
HTTP/1.1 must die: the desync endgame (portswigger.net)
17 points by octagons on Aug 7, 2025 | past | 2 comments
Drag and Pwnd: Exploiting VS Code with ASCII (portswigger.net)
1 point by albinowax_ on May 7, 2025 | past
Welcome to the next generation of Burp Suite: elevate your testing with Burp AI (portswigger.net)
2 points by thomas34298 on April 3, 2025 | past
PESDv2 – diagram Burp traffic instantly with customizable Markdown/themes (portswigger.net)
1 point by tony-ds on Feb 6, 2025 | past
Top web hacking techniques of 2024 (portswigger.net)
3 points by chillax on Feb 5, 2025 | past
Splitting the email atom: exploiting parsers to bypass access controls (2024) (portswigger.net)
1 point by frizlab on Jan 30, 2025 | past
Stealing HttpOnly cookies with the cookie sandwich technique (portswigger.net)
6 points by chillax on Jan 23, 2025 | past
Listen to the whispers: web timing attacks that work (portswigger.net)
188 points by saikatsg on Nov 21, 2024 | past | 33 comments
New Doyensec Prototype Pollution BurpSuite Extension (portswigger.net)
2 points by tony-ds on Oct 24, 2024 | past
Listen to the whispers: web timing attacks that work (portswigger.net)
2 points by rrampage on Sept 25, 2024 | past
Splitting the email atom: exploiting parsers to bypass access controls (portswigger.net)
2 points by hackvertor on Sept 5, 2024 | past | 1 comment
Listen to the whispers: web timing attacks that work (portswigger.net)
5 points by dytir on Aug 8, 2024 | past
Listen to the whispers: web timing attacks that work (portswigger.net)
3 points by chillax on Aug 7, 2024 | past
SignSaboteur: forge signed web tokens with ease (portswigger.net)
2 points by jdmark on May 23, 2024 | past
HTTP/2 desync attacks. (2021) (portswigger.net)
1 point by fanf2 on April 3, 2024 | past
uBlock, I exfiltrate: exploiting ad blockers with CSS (2021) (portswigger.net)
3 points by ReadCarlBarks on March 29, 2024 | past

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: