PortSwigger Profile Banner
PortSwigger Profile
PortSwigger

@PortSwigger

Followers
98K
Following
125
Media
207
Statuses
4K

We are a leading provider of software and learning on web security. We make @Burp_Suite and @WebSecAcademy.

Joined May 2008
Don't wanna be here? Send us removal request.
@PortSwigger
PortSwigger
4 years
Introducing DOM Invader: DOM XSS just got a whole lot easier to find.
9
234
583
@PortSwigger
PortSwigger
4 years
NEW CERTIFICATION ALERT! The new Burp Suite Certified Practitioner certification launches today! Learn more and get your exam here! 🎆 .#burpsuitecertified .
Tweet media one
24
198
552
@PortSwigger
PortSwigger
4 years
Fancy getting Burp Suite Certified for free? Book, take, and pass your exam before 15th Dec 2021 and we'll refund you your $99. Who's ready for the challenge?.#burpsuitecertified.
26
134
468
@PortSwigger
PortSwigger
6 years
To the very many people who’ve requested a third edition of The Web Application Hacker’s Handbook … . I’ve decided not to do one. Instead I’m working on something way more exciting. Details to follow.
16
68
391
@PortSwigger
PortSwigger
3 years
Wait, could this actually be Burp Suite. #tease
Tweet media one
22
27
379
@PortSwigger
PortSwigger
5 years
Blog post: Burp Suite tips from power user and "hackfluencer" Stök.
4
88
365
@PortSwigger
PortSwigger
5 years
To all the bug bounty hunters out there: How would you recommend bounty hunters find their very first bug? How did you find your first paid bug? . #bugbounty #bugbountytips.
20
73
335
@PortSwigger
PortSwigger
3 years
Manual testing with Burp Repeater is now more efficient than ever. Free up screen space by organizing tabs into color-coded groups and collapsing them into a single scrollable row. You can now even search for tabs and groups by name.
11
64
340
@PortSwigger
PortSwigger
7 years
Pressure’s on in the @Burp_Suite office.
Tweet media one
11
58
329
@PortSwigger
PortSwigger
6 years
We have added a new technique by @fasthm00 to Exploiting CORS misconfigurations for Bitcoins and bounties .
2
128
324
@PortSwigger
PortSwigger
3 years
PortSwigger has today donated $225,000 to the International Red Cross @ICRC to support their work helping the victims of the attack on Ukraine. Half of this money came from the @PortSwiggerRes bug bounty fund, and this amount was matched by the @PortSwigger business.
4
50
299
@PortSwigger
PortSwigger
3 years
If you often find yourself dealing with too many Repeater tabs, then you're going to love Burp's new tab grouping feature.
Tweet media one
9
49
271
@PortSwigger
PortSwigger
6 years
We have updated our guide on how to become a web security researcher.
0
103
266
@PortSwigger
PortSwigger
1 year
Simulate manual testing and relax 😎
4
34
258
@PortSwigger
PortSwigger
4 years
@rana__khalil We quite agree! And since we aren't crazy, we'd love to talk about this. Please could you email support@portswigger.net and we'll take things from there?.
12
5
245
@PortSwigger
PortSwigger
1 year
Are CSP's getting in the way of scoring that Bug Bounty you have been working on? 😫. Lucky for you, our research team (@PortSwiggerRes) has released some new techniques using Form Hijacking to bypass that protection and get you hacking again; enjoy!.
2
60
232
@PortSwigger
PortSwigger
5 years
PortSwigger is now on YouTube. Please do check us out and subscribe, to watch the latest updates on @Burp_Suite, @WebSecAcademy, @PortSwiggerRes, and more.
8
54
208
@PortSwigger
PortSwigger
6 months
In case you missed it, @albinowax 's amazing talk "Listen to the Whispers: Web Timing Attacks that Actually Work" from Def Con is now available to watch on YouTube.
2
36
208
@PortSwigger
PortSwigger
11 months
🕵️ 🤫 #BlackHat #Defcon32
5
30
196
@PortSwigger
PortSwigger
4 years
On the first day, PortSwigger created Burp Suite. On the second day, we gave you the Web Security Academy. What do you think is next? .#newproductlaunch #burpsuite #websecurityacademy
Tweet media one
22
28
197
@PortSwigger
PortSwigger
5 years
We're pleased to share our product roadmap for 2020, highlighting what's on the way for Burp Suite Enterprise Edition, Burp Suite Professional, and Burp Scanner.
12
69
189
@PortSwigger
PortSwigger
1 year
There was a lot announced at Apple #WWDC yesterday, and we’re obviously hard at work supporting the latest OS updates 👀
11
24
194
@PortSwigger
PortSwigger
8 months
Another really awesome example of the PortSwigger Research team’s new findings being used, this time to win a bounty! Well done, @_0x999 🎉. Ready to try these new techniques for yourself? Check out Splitting the Email Atom by @garethheyes 👉
Tweet media one
1
23
194
@PortSwigger
PortSwigger
4 years
We’re excited to announce our “women in tech” university scholarship scheme, offering £70,000 of financial support to help young women get started in a tech career. (Near Manchester, UK.).
7
56
179
@PortSwigger
PortSwigger
4 years
We've slashed the price of our Burp Suite Certified Practitioner exam for Black Friday, and we'll still refund you if you pass. What are you waiting for?.#burpsuitecertified #BlackFriday
34
77
179
@PortSwigger
PortSwigger
5 years
It’s BlackHat week and we have some huge things to share:. - Conference talk by @albinowax.- Blog post with full details.- @WebSecAcademy update with labs on brand new vulnerabilities.- @Burp_Suite update with scan checks for new issues.- Director’s cut of James’s talk on YouTube.
3
37
171
@PortSwigger
PortSwigger
4 years
Blog post: mapping out Burp Suite's crawler. This is a deep dive into the crawler, which is at the heart of Burp Suite's capabilities, and covers the crawler's origins, its current state and plans for the future.
2
72
173
@PortSwigger
PortSwigger
4 years
For the record, we have no plans ever to charge for access to Web Security Academy labs. The low price of the certification covers the exam proctoring and infrastructure costs.
8
15
163
@PortSwigger
PortSwigger
3 years
Introducing in-app recon to the Web Security Academy, with the brand new mystery lab challenge! This new feature gives academy users the chance to find and exploit vulnerabilities by generating a random lab to test their skills. #mysterylabchallenge.
2
42
170
@PortSwigger
PortSwigger
4 years
Just to be clear. To pass the Burp Suite certification exam, you will need access to Burp Suite Pro. It doesn’t matter if it is paid or trial or your work license or anything else. We don’t check your subscription. It’s just impossible to pass the exam without Burp Suite Pro.
11
28
164
@PortSwigger
PortSwigger
4 years
We're looking for interesting and helpful videos/guides on using Burp Suite as a pentester - what have you all got? Share links to your favourites in the comments below . #burpsuite.
15
41
161
@PortSwigger
PortSwigger
5 years
Blog post: Finding your first bug: bounty hunting tips from the Burp Suite community.
2
64
150
@PortSwigger
PortSwigger
2 years
Introducing BChecks - a new, faster way to add your own scan checks to Burp Scanner. Create your first BCheck today:.
6
43
153
@PortSwigger
PortSwigger
8 years
I originally wrote Burp to make my day job easier. Glad to hear it’s helping others.
@LaNMaSteR53
Tim Tomes
8 years
Was just sitting here pondering how difficult my job would be without Burp Suite. Thank you @PortSwigger. Seriously. Thank you.
6
18
145
@PortSwigger
PortSwigger
3 years
Finding Client-Side Prototype Pollution (CSPP) with DOM Invader by @garethheyes - now available on the Early Adopter channel.
2
46
146
@PortSwigger
PortSwigger
5 years
Burp Scanner now lets you record login sequences using your browser, so you can work with non-standard login mechanisms, single sign-on services, and other challenges.
@Burp_Suite
Burp Suite
5 years
Burp Suite Pro/Community 2020.9.2 released, with support for recorded login sequences in Burp Scanner and various bug/security fixes.
2
39
145
@PortSwigger
PortSwigger
3 years
For everyone who has a Burp Suite Certified Practitioner exam ready to take, we wanted to share a couple of exam pre-prep top tips. We've added some advice from people who've passed already - if you've got any tips then share them below! #burpsuitecertified.
14
34
143
@PortSwigger
PortSwigger
1 year
Kiss, marry, kill . Proxy, Intruder, Repeater?.
21
13
132
@PortSwigger
PortSwigger
1 year
Hunting bugs is an important job for all citizens of Super Earth!.#Bugbounty #Helldivers2
12
26
137
@PortSwigger
PortSwigger
4 years
Burp Suite Professional has plenty to learn - so we put our heads together and created a list of resources to help you get started. Anything to add to the list?.#BurpSuiteTips #burpsuite
Tweet media one
4
41
136
@PortSwigger
PortSwigger
3 years
"Hunting evasive vulnerabilities: finding flaws that others miss" - from @albinowax - will be premiering at @nullcon Berlin in just a few days. If you can't catch the live event, it'll be available on YouTube post-conference.
8
25
136
@PortSwigger
PortSwigger
4 years
Wondering how to enable DOM Invader? Well, it's available in the early adopter release. So you get it by using the early adopter channel.
3
37
129
@PortSwigger
PortSwigger
3 years
Evaluating an automated web vulnerability scanner? Use our new to put your scanner to the test. This is a realistic example of a modern website, containing serious vulnerabilities you might encounter in the wild.
4
27
119
@PortSwigger
PortSwigger
3 years
This is a Burp extension, and it's only a prototype currently - check it out and feel free to share your thoughts with us!.
@PortSwiggerRes
PortSwigger Research
3 years
We've prototyped a new feature in repeater where we are diffing the last response with the current and showing different colours depending on what changes. Please check it out we'd love your feedback!.
1
13
121
@PortSwigger
PortSwigger
4 years
Burp house, in the middle of Burp street . we’re getting pretty excited about our new office now!.
9
15
115
@PortSwigger
PortSwigger
6 years
It’s official. Burp Suite detects everything except pregnancy.
@_whit_ney_m
whitney🧜🏽‍♀️
6 years
@Burp_Suite Why can’t you detect pregnancy 🤰 LOL
Tweet media one
6
20
114
@PortSwigger
PortSwigger
4 years
🎵 If you're having cert issues I feel bad for ya son, I got $99 problems but the bill ain't one. 🎵. All you have to do is pass the Burp Suite cert exam before 15th Dec and we'll refund you your $99 exam fee. #burpsuitecertified #99problems.
7
36
115
@PortSwigger
PortSwigger
3 years
Last few days to try your hand at @RealTryHackMe's Advent of Cyber challenge. There are Burp Suite certification exams up for grabs as part of the prize pool. #adventofcyber #burpsuitecertified.
3
17
106
@PortSwigger
PortSwigger
4 years
Want more attack surface? DOM Invader's got you covered. It'll help discover JavaScript based parameters automatically, and show them in the URLSearchParameters source in the tree view.
3
31
106
@PortSwigger
PortSwigger
4 years
Want to see if a sink is vulnerable?? Either inject the canary and additional characters, or set the canary to include them. You could even use JavaScript URLs as a canary - "javascript:burpdomxss".
0
27
105
@PortSwigger
PortSwigger
5 years
You asked, we answered. Watch Burp Suite creator @DafyddStuttard talk about how Burp started, where the name PortSwigger came from, who Peter Wiener is, getting started in pen testing, the sinister Carlos, and more. #AskMeAnything.
7
26
105
@PortSwigger
PortSwigger
10 months
The official PortSwigger Discord is now open! 🎉👾. Join for access to exclusive events, feature previews, research releases, and to hang out with Burp Suite developers. Join for free here:
7
27
100
@PortSwigger
PortSwigger
4 months
🍪 Introducing the “Cookie Sandwich” technique. This vulnerability manipulates how servers parse cookies, potentially exposing sensitive user information like session IDs. Read more:
1
22
99
@PortSwigger
PortSwigger
3 years
Blog post: Burp Suite roadmap for 2022.
0
22
93
@PortSwigger
PortSwigger
4 years
Want to find JSON data structures automatically? Settings > "generate automated messages", to set DOM Invader guessing message structures using specially crafted JavaScript. Click the link below with DOM Invader and post message options enabled:
1
20
90
@PortSwigger
PortSwigger
1 year
Interested in learning how to extract sensitive data from websites when JavaScript is not an option?. Our very own @garethheyes has published some new techniques on how to achieve this using Blind CSS Exfiltration. Come and take a look 👀.
2
18
88
@PortSwigger
PortSwigger
2 years
Introducing multiple new classes of web race condition, that go far beyond limit-overrun exploits and expose previously overlooked attack surface, alongside new Burp Suite tooling and a brand new set of labs and learning materials.
0
23
88
@PortSwigger
PortSwigger
4 years
It's no bug folks, we actually are offering our certification for just $9 - and if you pass before 15 December '21 we'll still refund you! #burpsuitecertified
Tweet media one
8
24
88
@PortSwigger
PortSwigger
2 years
Calling all Pro/Community users. As part of our table enhancement work, we'd like to know - are tables easier to read with or without zebra stripes?. Follow this link to cast your vote 👉
Tweet media one
24
8
85
@PortSwigger
PortSwigger
2 years
Using the Server-Side Prototype Pollution Scanner.
0
19
85
@PortSwigger
PortSwigger
1 year
We work at PortSwigger, of course we're late to this trend .
4
8
79
@PortSwigger
PortSwigger
5 years
PortSwigger is now on YouTube! Do subscribe to see updates on Burp Suite, the Web Security Academy, and PortSwigger research.
0
17
77
@PortSwigger
PortSwigger
11 months
For the first time, three members of our research team are presenting at BlackHat USA and DEF CON 32! Get a sneak peek at the latest from @albinowax, @garethheyes, and @tincho_508. Check it out: . #BlackHat #DEFCON #Cybersecurity.
3
18
79
@PortSwigger
PortSwigger
3 years
At Black Hat 2021 @PortSwiggerRes introduced ​​multiple new classes of HTTP/2-exclusive threats and showed how these flaws enable desync attacks. Catch up on these before @albinowax presents the next stage of the journey, Browser-Powered Desync Attacks.
2
21
79
@PortSwigger
PortSwigger
7 years
Burp’s UI is getting nicer.
Tweet media one
@Burp_Suite
Burp Suite
7 years
Blog post: The new dashboard.#MoBP #BurpSuite.
6
21
75
@PortSwigger
PortSwigger
7 months
Watch research presentations on demand 🧵👇. PortSwigger recently presented three ground-breaking releases at Black Hat USA and DEF CON, uncovering a range of new techniques that could be used to exploit applications - and now two of these talks are available publicly!.
3
16
79
@PortSwigger
PortSwigger
3 years
You can now use DOM Invader to test for client-side prototype pollution. For an overview of how to use the exciting new features from PortSwigger researcher and creator of DOM Invader, Gareth Heyes, check out the following video.
Tweet media one
2
19
74
@PortSwigger
PortSwigger
2 years
Despite being seemingly counterintuitive, starting again from scratch actually presented us with an opportunity to improve code and functionality at a scale not normally possible. And now? It's time to welcome browser-powered scanning 2.0.
0
25
72
@PortSwigger
PortSwigger
4 years
Blog post: Web Security Academy - your questions answered. @WebSecAcademy.
0
19
75
@PortSwigger
PortSwigger
4 years
Burp Suite Pro users, we're talking to you. Are there any videos or blogs that you would recommend to first-time users to help them get to know Burp??.#burpsuite.
13
10
77
@PortSwigger
PortSwigger
4 years
A sneak preview of the latest research from @albinowax - that he'll be unveiling at this year's BlackHat USA event - along with some very exciting product development news! .#blackhatusa #burpsuite #appsec.
0
18
73
@PortSwigger
PortSwigger
4 years
We're excited to share our Burp Suite roadmap for 2021.
6
21
73
@PortSwigger
PortSwigger
10 months
What a week it’s been for @PortSwiggerRes at Black Hat USA! . Three major releases debuted at the conference, containing a range of new techniques that attackers are using to exploit applications. Take a look at all three white papers below 👇.
3
20
72
@PortSwigger
PortSwigger
5 years
ICYMI @Burp_Suite Professional and Community Edition now pretty-print JSON, CSS, JavaScript, HTML, and XML automatically.
4
20
67
@PortSwigger
PortSwigger
4 years
For anyone who started using Burp this year, what has been the hardest part of getting started? #burpsuite.
29
7
72
@PortSwigger
PortSwigger
4 years
Who's geared up to take their certification exam? Don't forget, if you book and pass before 15th Dec we'll refund your exam fee! Put your skills to the test now with our practice exam . 💻📖.#burpsuitecertified.
2
12
66
@PortSwigger
PortSwigger
4 years
Be one of the first 100 people to become a Burp Suite Certified Practitioner, and get a limited-edition, exclusive swag bundle to show off your new certification! .#burpsuitecertified .
Tweet media one
1
8
69
@PortSwigger
PortSwigger
1 year
Scanning from an API definition is now possible in Burp Suite Pro. Thanks for having a little patience 😉.
1
14
69
@PortSwigger
PortSwigger
3 years
Our expensive lawyers have brought it to our attention that you are passing off a bodily part as a PortSwigger product. We demand that you desist and remove our trademark from your limb (or the limb itself) within 7 days. #April1.
6
6
62
@PortSwigger
PortSwigger
5 years
Are you familiar with all of Burp Suite's WebSockets features? Watch this video to see why Burp is so powerful for WebSockets security testing and can find bugs that other tools miss.
@Burp_Suite
Burp Suite
5 years
Burp Suite essentials #10: How to test WebSockets.
0
18
64
@PortSwigger
PortSwigger
1 year
This is something else
1
7
65
@PortSwigger
PortSwigger
4 years
Tweet media one
2
2
66
@PortSwigger
PortSwigger
4 years
Tweet media one
7
3
67
@PortSwigger
PortSwigger
4 years
1
17
64
@PortSwigger
PortSwigger
4 years
You asked. We delivered. Well, we will be very soon. The latest workings from the incredible minds of PortSwigger Research, coming soon to a computer near you. #newproductlaunch #burpsuite #websecurityacademy
Tweet media one
2
2
65
@PortSwigger
PortSwigger
8 years
If you see any of the @Burp_Suite team at #bhusa17 come say hello.
Tweet media one
3
21
66
@PortSwigger
PortSwigger
4 years
Let's close the week out with something useful - thanks to a fantastic tweet thread from Burp user @codingo_ we've got a great list of tips and tricks for you all 👌.#BurpSuiteTips #burpsuite.
Tweet media one
0
22
63
@PortSwigger
PortSwigger
3 years
It's that funny time of year when life is in limbo, so why not work through some of the labs in our Web Security Academy? Follow the learning path, track your progress, and make sure to delete Carlos! .#websecurityacademy #vulnerabilities .
4
12
61
@PortSwigger
PortSwigger
4 years
One of our team's most popular breakthroughs so far is now six years old. Don't let age fool you though, Burp Collaborator still rules the roost. #burpsuite.
Tweet media one
0
7
62
@PortSwigger
PortSwigger
4 years
Help us to shape the future of Burp Suite, and build your very best product experience. #burpsuite #productexperience #feedbackmatters.
7
24
59
@PortSwigger
PortSwigger
2 years
So long, and thanks for all the fish. A sad day today as we say goodbye to The Daily Swig - the team have provided the community (and us) with five and a half years' worth of high-quality news, and we're sorry tto announce that this journey has ended.
5
8
61
@PortSwigger
PortSwigger
4 years
We interviewed three of the high flyers in our Hall of Fame, to find out exactly what inspired them to get ahead of the game in web security. #websecurity .
1
15
60
@PortSwigger
PortSwigger
10 months
1/ There will be three major releases from @PortSwiggerRes at Black Hat USA and DEF CON this August!. Read more below for an insight into this groundbreaking innovation, and keep an eye out for the related @WebSecAcademy labs that will be released next month. 👀.
2
17
58
@PortSwigger
PortSwigger
5 years
Learn how to bypass password logins, avoid account lockout, and defeat two-factor authentication in our awesome new #WebSecurityAcademy topic and labs.
@WebSecAcademy
Web Security Academy
5 years
We've added a brand new topic on authentication vulnerabilities, including 14 new labs!.
5
13
58
@PortSwigger
PortSwigger
4 years
Want to see every sink that a site uses? Simply enable DOM Invader, set the canary value to an empty string, then sit back and observe the site sinks …
1
10
59
@PortSwigger
PortSwigger
4 years
We recently caught up with Corey Ball - cybersecurity consultant, author, and API hacker extraordinaire - to discuss all things API security. #APIsecurity.
0
17
61
@PortSwigger
PortSwigger
4 years
How to get real good at hacking:.1. Turn on dark mode in Burp Suite. 2. Follow our @WebSecAcademy learning path. 3. Smash those labs. #hacking #advice #darkmode.
4
16
57
@PortSwigger
PortSwigger
4 months
🚨 Reminder: Results for the Top 10 Web Hacking Techniques of 2024 are near!. Joining the voting panel are @LiveOverflow and @stokfredrik alongside @Agarri_FR and @irsdl. Their expertise makes this year’s panel stronger than ever. Top 10 revealed on February 4th, stay tuned!
Tweet media one
2
15
57
@PortSwigger
PortSwigger
4 years
Find out how browser-powered scanning works under the hood, why this approach is essential for scanning modern web applications, and our exciting plans for building on this foundation.
0
21
53
@PortSwigger
PortSwigger
4 years
Have you booked your Burp Suite Certified Practitioner exam yet? If you can complete all the "Apprentice" and "Practitioner" level labs in our Web Security Academy you're already well on your way … #burpsuitecertified
Tweet media one
2
8
57