![d4d Profile](https://pbs.twimg.com/profile_images/1766510263929364481/tG2LaDFV_x96.jpg)
d4d
@d4d89704243
Followers
1K
Following
149
Statuses
106
Zakhar Fedotkin All thought are mine and mine alone
Joined July 2019
@0xTib3rius @Rhynorater @dyak0xdb Agree, the payload exploit the mandatory / at hostname. Interestingly, that Q-encoding can be used at HTTP requests too. @garethheyes demonstrated the technique in his research
0
0
4
RT @PortSwiggerRes: The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
0
267
0
RT @t0xodile: Officially in the BApp store! The research is in the thread if you'd like to understand more. Otherwise, go ahead and try out…
0
2
0
Bypass Bot Detection now in BApp store! - The extension now parses the User-Agent header and suggests matching TLS ciphers in the context menu. - You can still manually set a TLS cipher suite if the User-Agent header is unknown. Stay stealthy!
Bypass Bot Detection, a @PortSwiggerRes extension, is now live in the BApp Store! This extension helps you bypass TLS fingerprinting by mimicking browser fingerprints and brute-forcing protocol/cipher combinations
1
2
13
@ankursundara While working on the Memcached Injections research I did not think about the client side of this attack. The great blog post by @ankursundara made me look at this class of vulnerabilities differently. But that's not all, part 3 is ahead!
0
0
5
RT @ankursundara: @d4d89704243 Love the name Cookie Sandwich. I talked a bit about this idea in this blog post and…
0
7
0
RT @albinowax: Thanks for your all your votes! The public vote is now closed, and we're kicking off the panel vote with fifteen quality nom…
0
9
0
@slonser_ @albinowax @kobi_hk I tested the Link header injection scenario in redirect response (30X) Unfortunately, payment handler ignores it 🫤
0
0
1
RT @albinowax: Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: http…
0
72
0
RT @albinowax: Nominations are now open for the Top 10 Web Hacking Techniques of 2024! Browse the contestants and submit your own here: htt…
0
89
0
RT @albinowax: I've just released HTTP Request Smuggler 2.17 which fixes a nasty Client-Side Desync false-negative. Big thanks to @t0xodile…
0
19
0
RT @albinowax: We’re finally live! You can now watch “Listen to the whispers: web timing attacks that actually work” on YouTube: https://t.…
0
99
0