Elektrine lite

← Feed

James Kettle

albinowax@infosec.exchange

<p>Director of Research at PortSwigger aka <br />Burp Suite</p>

Posts

  • View post

    My latest presentation has landed on YouTube, courtesy of SEC-T! Can AI do novel security research? You know it. https://www.youtube.com/watch?v=jCFZFDHnZrQ

  • View post

    The whitepaper is live! Read &quot;Can AI Do Novel Security Research? Meet the HTTP Terminator&quot; here: https://portswigger.net/research/http-terminator

  • View post

    In &quot;Can AI Do Novel Security Research?&quot; I&#39;ll share: - A research-machine blueprint for AI enthusiasts - Clearly defined AI fail-points for AI dodgers - Extensive insight into what makes security research work - Many many novel desync goodies I&#39;ll also publish major updates to Turbo Intruder, Param Miner and HTTP Request Smuggler. Plus the full source of the HTTP Terminator itself. Choose your own adventure :)

  • View post

    Next week I&#39;ll present &quot;Can AI Do Novel Security Research? Meet the HTTP Terminator&quot; at DEF CON &amp; Black Hat USA! I&#39;m really excited to share this one - got some spectacular outcomes from a wild research journey. See you there! #DEFCON

  • View post

    I just did an interview with Application Security Weekly with teasers for my upcoming #BHUSA presentation &amp;quot;Can AI Do Novel Vulnerability Research: Meet the HTTP Terminator&amp;quot;, plus reflections on the Top Ten Web Hacking Techniques of 2025 &amp;amp; 2026. Watch it here: https://www.youtube.com/watch?v=fOWhhTrGtoI

  • View post

    You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!

  • View post

    Turbo Intruder now has API docs! You can easily discover its many advanced features including - pauseMarker for pause-basd desync.. or DoS - decorators for easy response filtering - &amp;#39;randomPlz&amp;#39; - wordlists.clipboard for lazy attack setup ...and many more! https://github.com/PortSwigger/turbo-intruder/blob/dev/docs/index.md

  • View post

    Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions &amp;amp; make your own nominations here: https://portswigger.net/research/top-10-web-hacking-techniques-of-2025-nominations-open

  • View post

    Voting is now live for the top ten web hacking techniques of 2025! Grab a brew, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques: https://portswigger.net/polls/top-10-web-hacking-techniques-2025

  • View post

    Love web &amp;amp; AI security research? Want to do it full time on-site with myself, Gareth Heyes &amp;amp; Zak Fedotkin? Join the PortSwigger Research team - we&amp;#39;re hiring! https://apply.workable.com/portswigger/j/FC27ED6166/

  • View post

    Access control bypass via header smuggling, with no desync required! Using header smuggling for more than HTTP desync like this is totally underrated - a lot of defences only filter the CL and TE headers. You can detect these with Parser Discrepancy Scan. https://www.linkedin.com/posts/jakedmurphy1_excited-to-share-that-i-recently-identified-activity-7431735557115789313-xhnA/

  • View post

    I&amp;#39;ve just submitted my latest research to Black Hat USA! This one has been cooking since last June, can&amp;#39;t wait to share it with the world... in fact I&amp;#39;m quite excited just to see the community reaction to the title reveal.

  • View post

    How is every doing? I wouldn&amp;#39;t call it comfortable, but I&amp;#39;m starting to savor the experience of rediscovering where the new frontier is, every few weeks. It feels like replaying the early stages of my research career. Looking forward to making my own contribution at #BHUSA!🤞

  • View post

    Have you ever been tempted to dive down the security research rabbit-hole? I&amp;#39;ll be sharing insights on how to navigate the rewards and hazards with legendary researchers Natalie Silvanovich and @raistlin in a community panel session at Black Hat USA next week!

  • View post

    I&amp;#39;m thrilled to announce &amp;quot;Can AI Do Novel Security Research? Meet the HTTP Terminator&amp;quot; will premiere at Black Hat USA! Check out the abstract: https://blackhat.com/us-26/briefings/schedule/?#can-ai-do-novel-security-research-meet-the-http-terminator-51894

  • View post

    The voting has concluded, and we&amp;#39;re thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! https://portswigger.net/research/top-10-web-hacking-techniques-of-2025