James Kettle(@albinowax) 's Twitter Profileg
James Kettle

@albinowax

Director of Research at PortSwigger Burp Suite

Check out my website for published research, other social platforms & contact details

ID:109850328

linkhttps://jameskettle.com/ calendar_today30-01-2010 14:01:28

4,3K Tweets

70,3K Followers

83 Following

Follow People
James Kettle(@albinowax) 's Twitter Profile Photo

Can't speak for everyone but it makes me quite uncomfortable when people send me sensitive info in collaboration requests before I've agreed to help. If their bug gets leaked/duped/patched I don't want them blaming me.

In the words of Schneier Blog, 'data is a toxic asset'

account_circle
PortSwigger Research(@PortSwiggerRes) 's Twitter Profile Photo

We've just published 'How to build custom scanners for web security automation', using a recent dive into automated race-condition detection by James Kettle as a case study. Enjoy!

portswigger.net/research/how-t…

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

Attendees at NULLCON also asked about cool upcoming Burp Suite features...

There's some crowd pleasers like 'Notes Everywhere', but I'm most excited about 'code your own view filters' - this innocuous feature has massive potential for power users: portswigger.net/burp/pro/roadm…

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

'How do you choose what topic to research?' This was the number one question I was asked at NULLCON. As it happens I've already published a post exploring this! Check it out here:

portswigger.net/research/how-i…

account_circle
Web Security Academy(@WebSecAcademy) 's Twitter Profile Photo

🔉New topic alert! 🔉

Dive into the world of NoSQL database security with the brand new NoSQL topic - read through the learning materials, then work through the labs to test your knowledge.

portswigger.net/web-security/n…

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

Thanks everyone for coming to my talk yesterday, hope you found it useful. It's been great meeting the NULLCON community!

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

Just confirmed my race-condition live demo works just fine from Goa! I know logically that the technique means distance to the target has no effect... but it still surprises me every time. See you at 11:45 tomorrow NULLCON!

Just confirmed my race-condition live demo works just fine from Goa! I know logically that the technique means distance to the target has no effect... but it still surprises me every time. See you at 11:45 tomorrow @nullcon!
account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

The recording for 'Smashing the state machine: the true potential of web race conditions' is now live, courtesy of DEF CON! Watch it here - or catch the updated edition in-person at NULLCON later this week!
youtube.com/watch?v=tKJzsa…

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

Really excited for the next 3 upcoming Web Security Academy topics! Got some much-requested hits and topics we've been afraid to tackle earlier (but not *that* topic)

account_circle
Web Security Academy(@WebSecAcademy) 's Twitter Profile Photo

Been trying to find the best way to get started on the Web Security Academy?

Introducing learning paths - a carefully curated, structured approach to develop knowledge and enhance your skills.

portswigger.net/blog/new-learn…

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

While the infosec community ponders where to settle, you can also find me at:

@[email protected]
bsky.app/profile/jamesk…
linkedin.com/in/james-kettl…

Can't wait till everyone's back on one platform. At least I don't have a newsletter yet!

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

I've just released an update to Backslash Powered Scanner which fixes some annoying false positives caused by WAFs. More updates incoming :)
github.com/PortSwigger/ba…

account_circle
James Kettle(@albinowax) 's Twitter Profile Photo

I'm pleased to announce the NULLCON edition of Smashing the State Machine will feature new content on adventures in race-condition automation, and applying the single-packet attack to other protocols!
nullcon.net/goa-2023/speak…

account_circle
PortSwigger Research(@PortSwiggerRes) 's Twitter Profile Photo

Burp Suite 2023.10 is harder to fingerprint than earlier versions as it now sets 'Accept-Encoding: gzip, deflate, br'. If you're still blocked, you might bypass it by tinkering with your TLS ciphers using 'Network->TLS -> Use custom protocols and ciphers'

portswigger.net/burp/documenta…

account_circle
PortSwigger(@PortSwigger) 's Twitter Profile Photo

Anyone going to be attending Nullcon Goa on 23 September?

If so, it's your last chance to catch the live presentation of James Kettle's 'Smashing the state machine: the true potential of web race conditions' … NULLCON

portswigger.net/research/talks

account_circle