James Kettle
@jameskettle
Director of Research at @portswigger.net Also known as albinowax Portfolio:
In "Can AI Do Novel Security Research?" I'll share: - A research-machine blueprint for AI enthusiasts - Clearly defined AI fail-points for AI dodgers - Extensive insight into what makes security research work - Many many novel desync goodies Choose your own adventure :)
Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at @defcon.bsky.social & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there!
I'm very happy to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" is coming to DEF CON 34! This research was a huge gamble and the result was glorious, can't wait to share!
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract: blackhat.com/us-26/briefi...
I've just submitted my latest research to Black Hat USA! This one has been cooking since last June, can't wait to share it with the world... in fact I'm quite excited just to see the community reaction to the title reveal.
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring! apply.workable.com/portswigger/...
Turbo Intruder now has API docs! You can easily discover its many advanced features including - pauseMarker for pause-basd desync.. or DoS - decorators for easy response filtering - 'randomPlz' - wordlists.clipboard for lazy attack setup ...and many more! github.com/PortSwigger/...
You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!
I just published a Repeater feature to make it easier to explore request smuggling. It repeats your request until the status code changes. It's called "Retry until success" and you can install it via the Extensibility helper bapp.
Massive thanks to everyone who came to watch HTTP/1.1 Must Die at Black Hat USA & DEF CON! It was great to meet you all and hear your stories, had an absolute blast and I'm psyched to cook up some more madness for next year!
Watch HTTP/1.1 Must Die live today at 1630 PST! - In person at #defcon33 track 1, main stage - Livestream via YouTube: www.youtube.com/watch?v=ssln...
At #BlackHat? Catch "HTTP/1.1 Must Die! The Desync Endgame" today at 3:20 in Oceanside A, Level 2. Hope to see you there!
Let me know if you'd like to chat research at Black Hat or #defcon33! Also feel free to say hi if you see me about, I've got a not-very-subtle laptop cover to aid recognition 😂
Ever seen a header injection where achieving a desync seemed impossible? I think I've finally identified the cause - nginx doesn't reuse upstream connections by default, and often has header injection. This means you're left with a blind request tunneling vulnerability 👇
We've just released a massive update to Collaborator Everywhere! This is a complete rewrite by @compass-security.com which adds loads of features including in-tool payload customization. Massive thanks to Compass for this epic project takeover. Check out the new features:
How to make $$$ from request smuggling Step 1) Pick the right target:
Concerned about LLM-powered pentesters stealing your job? We've made improving your workflow with AI easier than ever - you can now build your own AI features directly inside Repeater with Custom Actions. Here's one I built for myself:
The upcoming "HTTP/1 must die" WebSecAcademy lab is no longer impossible! This is good news because I'm planning to attempt to live-stream solving it...
Now I just need to turn my 20gb Burp Suite project file with 73,000 Organizer entries into an enticing slide deck 😂
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame" is coming to #DEFCON33! This talk will feature multiple new classes of desync attack, mass exploitation spanning multiple CDNs, and over $200k in bug bounties. See you there!
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser ↓
When selecting a research topic, it's crucial to consider where the profit potential comes from. Re-reading this old post, it almost feels like a guide to my latest unannounced research! portswigger.net/research/how...
Quarterly deadlift update time! Since setting the goal last June I’ve gone from 2.3x to 2.7x bodyweight, made harder as I gained 5kg 😂 Final 0.3x will probably be much tougher.
I just built a custom action to let you test for race conditions with a single click! No tab groups required, and it uses the cutting edge single-packet attack under the hood: gist.github.com/albinowax/10... For more info check out portswigger.net/research/sma...
Are you a Burp Repeater power user? The latest release introduces a new feature called 'Custom actions'. With these you can quickly build your own repeater features. Here's a few samples I made for you:
Are you cooking some quality technical research, and tempted by a trip to Rome in September? Submit it to the RomHack CFP! See you there :) cfp.romhack.io/romhack-2025...
Sadly, my attempt to perform WAF onboarding on the target website failed 😂
Per popular demand, Turbo Intruder 1.51 now inserts results at the top of the table so you can watch them arrive without scrolling! Let me know how you find it. If you prefer the old behaviour, you can change it back using: table.setSortOrder(0, False)
ICYMI: Burp Intruder 2024.12 EA now has a capture filter! This enables extremely long-running attacks by stopping junk responses from consuming memory. You might recognise this feature from Turbo Intruder :)
I'll be at Black Hat Europe next week - let me know if you'd like to meet up... or just collect one of these highly exclusive desync-themed tshirts #BHEU