My little XSS session went pretty well I think. It made me ask all kindo f questions, and really solidified the basics for me. I am going to give another session in a few weeks, this time on Host Header attacks #xss #bscp #portswigger #appsec #haecksen
#portswigger — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #portswigger, aggregated by home.social.
-
I've been studying for the bscp sine the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this trasnport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec
-
Lab: Information disclosure in version control history Merhaba arkadaşlar. Bu writeup’ta PortSwigger’ın “Information disclosure in version control history” labını çözeceğiz. Bu lab i...
#web-security #bug-bounty #github #portswigger #cybersecurity
Origin | Interest | Match -
🎙️ Join Federico’s Discord talk later today!
As part of #BurpExtensibilityMonth initiatives, our Research Lead and #BurpAmbassador @apps3c is joining #PortSwigger on Discord for “Restoring testability: Handling complex scenarios in Burp Suite with a custom extension”.
Most web and mobile backends and APIs can be assessed effectively with #BurpSuite out of the box. But testers sometimes hit scenarios where standard workflows become impractical, such as encryption, request signing, custom data formats, WAF controls, token handling, and other protections.
In this talk, Federico will explore how custom Burp Suite extensions can integrate those mechanisms directly into your testing workflow, so you can keep using tools like Repeater, Intruder, Scanner, and more as if the underlying complexity was not there.
Expect a real-world inspired scenario, practical design guidance, and plenty of extension-building inspiration.
👉 Register your interest here!
https://discord.com/events/1159124119074381945/1499761261750128670 -
Как я сдал BSCP за 2 часа. Методология подготовки
В каждой профессии есть ритуал инициации, о котором не принято говорить вслух. У хирургов — первая ночная смена с тяжёлым пациентом. У пилотов — посадка вслепую на тренажёре. У багхантеров и пентестеров есть Карлос. Да, тот самый Carlos, чей пароль или токен вы будете выгрызать из экзаменационного приложения PortSwigger, пока где-то на фоне тикает таймер, а Burp Collaborator хранит гробовое молчание. Меня зовут Султан. Первая попытка, два часа — экзамен сдан. Я знаю, о чём вы подумали: сдать BSCP с первого раза удаётся очень немногим, даже опытным специалистам. Так почему у меня получилось? Ответ — в методологии. Я не буду рассказывать о вещах, которые и так известны абсолютному большинству. Раскрывать уязвимости из экзамена смысла нет: существует около сотни различных комбинаций, запомнить их все невозможно.
-
When did #PortSwigger shut down the User Forum? There is still a link to the forum on the website, but it now redirects to the generic support page.
-
Information disclosure in error messages | Lab -01 portswigger Lab Information Disclosure is a security vulnerability where a system or application unintentionally exposes sensitive or internal inf...
#cybersecurity #information-disclosure #pentesting #portswigger #error-message
Origin | Interest | Match -
PortSwigger Academy Lab: Source code disclosure via backup files Description: This lab leaks its source code via backup files in a hidden directory. To solve the lab, identify and submit the databa...
#information-disclosure #web-security #portswigger-lab #portswigger #sensitive-data-exposure
Origin | Interest | Match -
Portswigger Web Security Academy | DOM-based Vulnerabilities Lab #1 Hi everyone! Today we’ll solve the first DOM-based vulnerabilities lab from the PortSwigger Web Security Academy. Let’s get ...
#vulnerability #portswigger #application-security #web-security #cybersecurity
Origin | Interest | Match -
-
-
🗺️ Where to Practice Ethical Hacking — Safe Learning Platforms 🔐
Sharpen your skills legally on platforms like TryHackMe (beginners), Hack The Box (intermediate/advanced), PortSwigger Academy (web), and CTF sites — safe, structured labs and communities for hands-on learning. 🎯💻
#ethicalhacking #TryHackMe #HackTheBox #PortSwigger #CTF #Infosec #CyberSecurity #LearnToHack #PenTesting #WhiteHat
-
Portswigger Web Security Academy | XSS Lab #1 Hi everyone! Today, we’ll be solving the first XSS lab from the PortSwigger Web Security Academy. Let’s get started! Before we dive into the lab, ...
#web-applications #application-security #cybersecurity #xss-attack #portswigger
Origin | Interest | Match -
Portswigger put up a video about flaws in HTTP 1.1. it's got John Hammond!
-
PortSwigger Lab Walkthrough: Blind OS Command Injection with Time Delays When it comes to exploiting web applications, nothing is more thrilling than turning a simple form input into a foothold on ...
#web-penetration-testing #portswigger #cybersecurity #application-security #portswigger-lab
Origin | Interest | Match -
One Third of the Web Will Stop Working in 4 Days: Massive-Scale CDN Compromise Starts Wednesday https://lowendbox.com/blog/one-third-of-the-web-will-stop-working-in-4-days-massive-scale-cdn-compromise-starts-wednesday/ #Editorial&News #portswigger #tedunangst #Security #HTTP #tedu
-
-
burplabs: Automated python package for portswigger labs burplabs is a modular, Python-based CLI tool that automates solving labs from PortSwigger Web Security Academy . Its like like netexec, but m...
#python #security #burpsuite #portswigger #appsec
Origin | Interest | Match -
🚨 Want to start learning ethical web hacking for FREE?
🎯 In this video, I break down 3 websites that offer hands-on labs, structured paths, and gamified learning - perfect for beginners in web application penetration testing and bug bounty!
🎓 Here’s who made the list:
✅ PortSwigger Web Security Academy
Learn real-world web vulnerabilities with interactive labs✅ TryHackMe
Gamified challenges + guided learning paths✅ Hack The Box
Academy modules, practice labs & certifications — all linked togetherBut I didn’t stop at listing them.
💡 I shared my professional take on:
1️⃣ Their unique strengths
2️⃣ What makes each platform great for beginners
3️⃣ And where they could improve to become even betterThis isn't just another list — they are insights from an active bug bounty hunter from Singapore 🇸🇬😊
📺 Watch here: https://www.youtube.com/watch?v=_LrpMiAD8rg
📌 Timestamps and useful links in the video description👇 Comment your favorite FREE hacking resources — let's share and help each other grow!
#BugBounty #BugBountyTips #CyberSecurity #EthicalHacking #TryHackMe #HackTheBox #PortSwigger
-
Latest lab write-up. Came out a bit long but very informative.
https://medium.com/@marduk.i.am/blind-sql-injection-with-conditional-responses-46ee90b5f2c0
#BugBounty #bugbountytips #SQL #SQLI #injection #informationsecurity #Portswigger
-
<script>alert(1)</script> - 403 Forbidden
<img src=x onerror=console.log(1)> - 403 Forbidden
<svg onload=print()> - 403 ForbiddenI've recently encountered a web application firewall in a pentest, blocking all my attempts to insert an XSS payload.
In such cases, I love to use the #PortSwigger cross-site scripting cheat sheet: https://portswigger.net/web-security/cross-site-scripting/cheat-sheet
I copied all payloads to the clipboard, pasted them into the Intruder's word list and hit the "Start attack" button.
Within seconds, I had a working proof of concept.
How do you use the XSS cheat sheet? I'm keen to know!
#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking
-
Bypassing CSRF defenses using XSS…and more | Portswigger XSS Practitioner Part 2 In this articl...
https://systemweakness.com/bypassing-csrf-defenses-using-xss-and-more-portswigger-xss-practitioner-part-2-b08965e0c039?source=rss----f20a9840e177---4
#cybersecurity #portswigger #writeup #javascript #cross-site-scripting
Result Details -
#portswigger has released some #ai thingy for #burpsuite. It doesn't do anything on it's own, but the feature is on by default. If you go to the settings to disable it they ask you for feedback why you turn that crap off. Isn't that obvious? No matter the pinky promiss you make to your customers, that you don't store the data or train on it, as soon as you hand it of to an #LLM company we have no idea what happens. AI and customer data don't mix. End. Of. Story. #infosec #security
-
Diving deeper into XSS: Portswigger XSS Practitioner Labs Part 1 Let’s continue to understand m...
https://systemweakness.com/diving-deeper-into-xss-portswigger-xss-practitioner-labs-part-1-7f61f254a1bb?source=rss----f20a9840e177---4
#portswigger #javascript #cybersecurity #writeup #xss-attack
Result Details -
Beginner Walk-through: Portswigger’s Cross Site Scripting All Apprentice Labs In this article, ...
https://systemweakness.com/beginner-walk-through-portswiggers-cross-site-scripting-all-apprentice-labs-b2efd5c497e0?source=rss----f20a9840e177---4
#javascript #xss-attack #cybersecurity #writeup #portswigger
Event Attributes -
Beginners Walk-through Portswigger Labs SQL Injection Lab 13-Lab 18 Let’s continue our series i...
https://systemweakness.com/beginners-walk-through-portswigger-labs-sql-injection-lab-13-lab-18-ccda16eb7ef6?source=rss----f20a9840e177---4
#portswigger #walkthrough #web-security #sql-injection #cybersecurity
Event Attributes -
HTTP Request Smuggling: как особенности в обработке HTTP-заголовков приводят к атакам CL.TE и TE.CL
HTTP Request Smuggling или контрабанда HTTP-запросов — тип уязвимости, который возникает из-за несоответствий в обработке HTTP-запросов между фронтендом и бэкендом. Каким образом различия в интерпретации заголовков позволяют атакующим использовать эту уязвимость? Как HTTP Request Smuggling можно использован в сочетании с Web Cache Poisoning? И на что обратить внимание, чтобы предотвратить подобные атаки? Разберем вместе на примере лабораторных работ с PortSwigger.
https://habr.com/ru/companies/jetinfosystems/articles/898788/
#http_request_smuggling #Web_Cache_Poisoning #безопасность_вебприложений #уязвимости #portswigger #cybersecurity
-
HTTP Request Smuggling: как особенности в обработке HTTP-заголовк...
https://habr.com/ru/companies/jetinfosystems/articles/898788/?utm_source=habrahabr&utm_medium=rss&utm_campaign=898788
#http #request #smuggling #Web #Cache #Poisoning #безопасность #веб-приложений #уязвимости #portswigger #cybersecurity
Event Attributes -
🔍 Geeksta CyberLab | S1E3 🔍
Today, we’re diving into PortSwigger—exploring web security, breaking things (ethically), and learning how to patch them. If you're into cybersecurity, this one’s for you.
I’ll be live soon, feel free to drop by.
#Geeksta #CyberLab #Cybersecurity #PortSwigger #EthicalHacking #WebSecurity
-
[Перевод] Топ-10 техник атак веб-приложений 2024 года
PortSwigger опубликовали топ-10 техник атак веб-приложений 2024 года - самых инновационных и важных исследований в области веб-безопасности, опубликованные за последний год. Данные техники атак представляют собой передовые исследования и могут стать хорошей основой для изучения и применения в багбаунти, тестировании на проникновение и защите веб-приложений.
-
PortSwigger have published the
Top 10 web hacking techniques of 2024
https://portswigger.net/research/top-10-web-hacking-techniques-of-2024
-
Nice to see Maxence Schmitt's CSPT research (a nominee for #Portswigger's top 10 web hacking techniques for 2024) getting a shout out on the Critical Thinking Bug Bounty podcast !
Check out the review and comments here: https://youtu.be/3rkg1CUDpjA?si=yu4AtH6eLwu0F5n8&t=2687
-
This year, Doyensec is excited to have 4⃣ great nominations in Portswigger's Top 10 Web Hacking Techniques! 🥳
Check them all out and vote for your favorites (hopefully ours🤞) today!
https://portswigger.net/research/top-10-web-hacking-techniques-of-2024-nominations-open
-
The doom is close ;-) #portswigger/#burpsuite closed their forum and use discord. :-(
-
Hello everyone.
In today's article we are talking about the most used successful plugins for burpsuitehttps://denizhalil.com/2024/08/05/top-10-burp-suite-extensions/
#burpsutie #ethicalhacking #bugbounty #bughunter #portswigger
-
PortSwigger Scores Hefty $112 Million Investment https://www.securityweek.com/portswigger-scores-hefty-112-million-investment/ #ApplicationSecurity #penetrationtesting #BrightonPark #Funding/M&A #PortSwigger #BurpSuite
-
PortSwigger Scores Hefty $112 Million Investment https://www.securityweek.com/portswigger-scores-hefty-112-million-investment/ #ApplicationSecurity #penetrationtesting #BrightonPark #Funding/M&A #PortSwigger #BurpSuite
-
BSCP — разгадываем тайны сертификации от академии PortSwigger
Привет, Хабр! Меня зовут Никита, я пентестер, специализируюсь на веб-тестировании. Наверняка многие из вас задумывались о подтверждении своей экспертизы с помощью некоторых сертификаций. Сегодня хочу поговорить о популярной сертификации от академии PortSwigger — BSCP, посвященной тестированию веб-приложений. Прежде чем приступить к изучению материалов для подготовки к BSCP, я уже имел хорошее представление об основных веб-уязвимостях из списка OWASP TOP-10. Также я знал, как эксплуатировать базовые уязвимости, такие как SQL-injection, XSS, Server-Side Template Injection и многие другие. Но на одном из этапов я задался вопросом: как всё-таки к нему эффективно подготовиться? В этой статье я поделюсь лайфхаками по подготовке к сертификации, покажу, как может помочь встроенный в Burp Suite сканер уязвимостей, и подробно разберу каждый из этапов самого экзамена.
https://habr.com/ru/companies/jetinfosystems/articles/805297/
#пентест #pentest #ctf #BSCP #sqlinjection #xss #PortSwigger #OWASP_TOP10
-
You can easily install the extension from the official #PortSwigger BApp Store: https://portswigger.net/bappstore/866df66d339d4bcd9b599772aff32efd
-
#BurpSuite is the number one tool for web application pentesters.
#PortSwigger also introduced an official certification for web security professionals: the Burp Suite Certified Practitioner (#BSCP).
Having failed the exam twice before passing it, I hope you can learn from my mistakes :)
Enjoy reading! 👇
#Infosec #CyberSecurity #BugBounty #Pentesting #Hacking #AppSec
-
🚨 Race Conditions for Web App Pentesters 🚨
I just finished reading "Smashing the state machine" by @albinowax and summarized its contents for my own notes.
This thread gives a short introduction into the topic.
I assume a basic knowledge of web application pentests.All credits goes to @albinowax for the great research!
https://portswigger.net/research/smashing-the-state-machine
#Infosec #CyberSecurity #BugBounty #Pentesting #Hacking #AppSec #BlackHat #PortSwigger #BurpSuite
-
I haven't read it myself yet, but I'm convinced that this is a must read for every web app pentester out there!
#InfoSec #CyberSecurity #AppSec #Pentesting #BlackHat #PortSwigger #BurpSuite https://infosec.exchange/@albinowax/110861316434417361
-
#BurpSuite's roadmap for the next 12 months was released today: https://portswigger.net/blog/burp-suite-roadmap-update-july-2023
#Infosec #CyberSecurity #BugBounty #Pentesting #Hacking #AppSec #PortSwigger
-
#wtf of the day in #portswigger #burpsuite : the crawler isn't crawling Apache directory listings if the folder name includes curly brackets crawl{burp}block
-
Solved my first SQLi challenge on Portswigger #infosec #owasp #portswigger #appsec #hacking https://portswigger.net/web-security/sql-injection/lab-retrieve-hidden-data
-
#PortSwigger provides a practice exam. Instead of two, there is just one application to solve.
In my preparation, I failed the practice exam several times. Don‘t get discouraged when you fail, but learn from your mistakes.https://portswigger.net/web-security/certification/practice-exam
-
Next, is adding in #portswigger #burp into the api to make the processes even easier. XD
-
For all my Burp Suite users on MacOS:
For all the Burp extensions that will run something "in terminal" and you want that terminal to be iTerm2, create a shell script with the following content, link it to /usr/local/bin/iterm or something, and set it as the terminal command in your Burp extensions.
Here I'm using it with the (awesome) Custom Send To extension for sending requests directly. from Burp to a number of different tools like SQLMap, Wfuzz, Gobuster etc. The script will open a new tab in iTerm and run the command specified.
You're welcome!
Script: https://gist.github.com/n0kovo/0e893c7b36f0209ffe971883064bee6f
Custom Send To:
https://github.com/bytebutcher/burp-send-to#iterm2 #burpsuite #appsec #burp #portswigger #bugbounty #infosec #pentesting #websecurity #techtips
-
Hmmm, best way to start from nothing to doing BB. Two years of study need to study for but may not need to pass or take exam Network plus. Doing lots of ctfs that are progressively harder, till you are comfortable. Do #portswigger academy labs all of them, you may skip secc5ions for sqli but you should be confident In technique. Xss depending, but more the better.
You may do BB and portswigger at same time, do one vuln a week then hunt for the vuln for a week. You should Learn it pretty well through repition
-
@Colin_Mac I just signed up for LetsDefend.io and so far I'm digging that. SOC analyst/Blue Team focused. I did a handful of lessons and then subscribed since they had a 50% off
Other resources I've signed up for but haven't fully explored yet:
PortSwigger, Hack the Box, TryHackMe
-
📬 Mastodon: Sicherheitslücke erlaubte den Diebstahl von Anmeldedaten
#Datenschutz #Kurznotiert #GarethHeyes #glitchsoc #HTMLInjection #infosecmastodon #infosecexchange #portswigger #Sicherheitslücke https://tarnkappe.info/artikel/datenschutz/mastodon-sicherheitsluecke-erlaubte-den-diebstahl-von-anmeldedaten-259218.html -
See a few people dunking on #mastodon for the #PortSwigger #disclosure.
Not many acknowledging the amazing effort to get remediation in place in < 48hrs for Glitch and 6 days for upstream.
#wow.
Oh and use #mfa plus don't reuse passwords!
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp