Web Security Academy
1.8K posts

Web Security Academy
@WebSecAcademy
Free web security training from @PortSwigger
Katılım Nisan 2018
36 Takip Edilen142K Takipçiler

IDORs & BACs are still the most reported vulnerabilities 🔝
Explore our free lab to understand how this vulnerability works, guided by @hacksplained 👇
portswigger.net/web-security/a…
English
Web Security Academy retweetledi

Introducing Burp AT.
Agentic AI for human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills.
Now live in public beta for Burp Suite Professional users.
portswigger.net/blog/introduci…
English

Got a Raspberry Pi? (Any model works!) You can turn it into a portable hacking rig with Kali Linux.
#RaspberryPi #KaliLinux
English
Web Security Academy retweetledi

Excited to share that I've just joined the @PortSwiggerRes team. Having gotten an early look at what the team is bringing to @BlackHatEvents, I can safely say this year is going to be epic!
English
Web Security Academy retweetledi

Our newest labs are all about hacking LLMs. You'll learn:
🟧 What's an LLM?
🟧 Prompt injection
🟧 Exploiting LLM APIs, functions, and plugins
🟧 AI-powered scanner vulnerabilities
🟧 Defending against LLM attacks
Sound good?
Get started here. 👇
portswigger.net/web-security/l…

English

Ambiguous URLs are behind many SSRF, CORS, and redirect flaws, but most bypasses are scattered and undocumented.
This cheat sheet consolidates payloads, encodings, and IP tricks into one place to assist your testing.
Check it out: portswigger.net/web-security/s…
English

Learn to hack with Portswigger Web Security Academy!
Why? Our labs:
🔶 are based on real-world scenarios
🔶 have integrated learning paths
🔶 are 100% FREE
You can literally start right now. 👇
portswigger.net/users/register

English

"kid":"../../dev/null"
That’s a classic path traversal payload weaponized inside a JWT Key ID (kid) header.
Battle-tested libraries drop these requests, but custom or legacy JWT implementations may still fall for it.
Try it out here! 👇
portswigger.net/web-security/j…

English

<img src=x onerror=alert(1)>
An alert box popped! ⚠️ What next?
Popping an alert box is just the start. Dig deep and turn it into a full account takeover, data theft, or lateral movement.
Find out how here 👇
portswigger.net/web-security/c…

English
Web Security Academy retweetledi

The field of desync flaws arising from deep implementation bugs is absolutely wild. This finding from @calif_io using a fake pseudo-header than gets weaponized by a dodgy length calculation is a great example
Calif@calif_io
MAD Bugs: My Cousin Vinyl (CVE-2026-50052) So the story went like this: Squid was bleeding from a 29-year-old heap overread in her default config. Naturally, she did the only sensible thing: she called her cousin, Vinyl. It turns out Vinyl also had a family problem of his own. blog.calif.io/p/mad-bugs-my-…
English

Depois de me lascar na parte de defesa (só 45k/mes) é hora de aprender um pouco mais de offsec e ganhar dinheiro igual o @1Iucas
I completed the Web Security Academy lab:
Unprotected admin functionality
@WebSecAcademy
portswigger.net/web-security/a…
Português

I completed the Web Security Academy lab:
Cross-site WebSocket hijacking
@WebSecAcademy
portswigger.net/web-security/w…
English

Day 10/200
I completed the Web Security Academy lab:
HTTP request smuggling, basic CL.TE vulnerability
@WebSecAcademy
portswigger.net/web-security/r…
#200daysshowupchallenge
English



