
PortSwigger
@PortSwigger
Followers
100K
Following
163
Media
238
Statuses
4K
We are a leading provider of software and learning on web security. We make @Burp_Suite and @WebSecAcademy.
UK
Joined May 2008
24 million websites compromised. 🧵 PortSwigger's Director of Research, James Kettle (@albinowax), & AppSec expert John Hammond (@_JohnHammond) reveal the fatal flaws in HTTP/1.1 that attackers are abusing right now. #HTTP1MustDie
3
24
144
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: https://t.co/Tje8Ce8if0
13
86
353
It's been great to see people 'enjoying' the 0CL @WebSecAcademy lab! Tune in this Friday at 11AM PT to watch me livestream the solution with @offby1security - registration link below 👇
5
18
168
HTTP/1.1 is outdated and dangerous. And it’s time to kill it. 💀 James Kettle's new @PortSwiggerRes research exposes how attackers are still exploiting HTTP/1.1 flaws and how you can help end it (and earn while doing it). Learn + hack: https://t.co/d7TF6sdFh3
5
33
292
@orange_8361 @Arl_rose @PortSwigger @BugBountyDEFCON @d3vc0r3 Congrats, that research was top tier! I got one too 🙏
4
3
52
Massive thanks to everyone who came to watch HTTP/1.1 Must Die at @BlackHatEvents & @defcon! It was great to meet you all and hear your stories, had an absolute blast and I'm psyched to cook up some more madness for next year!
3
15
228
Today at DEF CON - the Top Ten Web Hacking Techniques of 2024 awards Don't miss these sought-after trophies being awarded at @BugBountyDEFCON's closing ceremony this afternoon! #DEFCON33 #BugBountyVillage
2
4
58
The team will be at @defcon again today! Don't miss out on your free HTTP/1.1 Must Die t-shirt in the Bug Bounty Village (while stocks last...👀 ). #DEFCON33 #BugBountyVillage #HTTP1MustDie #PortSwigger #BurpSuite
1
1
44
🚨 In case you missed it: #BHUSA research reveals upstream HTTP/1.1 is flawed. Are your CDNs still using HTTP/1.1 for upstream connections? If so, you may be severely exposed by future waves of request smuggling attacks. Learn how to protect your organization today:
1
13
89
The ground-breaking new research release HTTP/1.1 Must Die! The Desync Endgame will be hitting @defcon this afternoon at 4.30pm. Join the movement 👉 https://t.co/pIOerQPxTt
#HTTP1MustDie #DEFCON33
http1mustdie.com
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
1
3
19
Today at DEF CON 33 - don't miss @albinowax's new HTTP/1.1 Must Die talk! We're proudly sponsoring the @BugBountyDEFCON and are excited to be this year's CTF triage partner. Drop by, say hello, pick up some swag, and have fun! #DEFCON33 #BurpOnTour2025 #HTTP1MustDie
1
7
39
🚨New Black Hat research released: Over $200k in bounties earned in just two weeks. Join the movement to kill HTTP/1.1 today ⬇️ 🔍PortSwigger’s James Kettle (@albinowax) introduces two new classes of HTTP desync attacks capable of compromising credentials on tens of millions of
6
34
166
Join us for the Meet the Researchers casual drinks in 2 hours! We'll be at the Centra in the Luxor between 5-7pm. Drop by for a drink and some exclusive Burp swag (before they're gone 👀). #BurpOnTour2025
0
1
3
In Vegas this week? Join the @PortSwiggerRes team and Burp Suite creator @DafyddStuttard for a drink tomorrow! 5-7pm Centra at The Luxor @zakfedotkin @albinowax @tincho_508
#BurpOnTour2025
1
4
30
🕵️♂️ 🎩 The desync endgame has just begun. New expert lab has just dropped. Straight from @albinowax’s #BHUSA talk: Understand the latest request smuggling techniques, sharpen your skills, unlock new bounties, and solidify your organization’s defenses with the new expert lab ⬇️
0
9
86
🚨New Black Hat research released: Over $200k in bounties earned in just two weeks. Join the movement to kill HTTP/1.1 today ⬇️ 🔍PortSwigger’s James Kettle (@albinowax) introduces two new classes of HTTP desync attacks capable of compromising credentials on tens of millions of
6
34
166
In one hour, @tincho_508 and @zakfedotkin will presenting their brand new tools at Black Hat Arsenal! In Vegas? Don't miss these exclusive new showcases of... ⭐ HTTP Hacker ⭐ Web Socket Turbo Intruder #BlackHatUSA #BHUSA
0
0
8
5 hours until the desync endgame begins. https://t.co/pIOerQPxTt
#HTTP1MustDie
http1mustdie.com
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
0
2
19
Today at #BlackHatUSA - three major new releases from @PortSwiggerRes 1pm - 'HTTP Hacker' at Black Hat Arsenal with @tincho_508 1pm - 'WebSocket Turbo Intruder' at Black Hat Arsenal with @zakfedotkin 3.20m - 'HTTP/1.1 Must Die! The Desync Endgame' at Black Hat USA with
1
0
22