Web Security Academy

1.8K posts

Web Security Academy banner
Web Security Academy

Web Security Academy

@WebSecAcademy

Free web security training from @PortSwigger

Katılım Nisan 2018
36 Takip Edilen142K Takipçiler
Web Security Academy
Web Security Academy@WebSecAcademy·
If you have a list of usernames and a list of passwords, and you want to try every combination, use the cluster bomb attack.
English
1
5
59
4K
Web Security Academy retweetledi
Burp Suite
Burp Suite@Burp_Suite·
Introducing Burp AT. Agentic AI for human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. Now live in public beta for Burp Suite Professional users. portswigger.net/blog/introduci…
English
9
51
108
32.8K
NetworkChuck
NetworkChuck@NetworkChuck·
Got a Raspberry Pi? (Any model works!) You can turn it into a portable hacking rig with Kali Linux. #RaspberryPi #KaliLinux
English
14
52
550
26.7K
Web Security Academy retweetledi
Tom Stacey
Tom Stacey@t0xodile·
Excited to share that I've just joined the @PortSwiggerRes team. Having gotten an early look at what the team is bringing to @BlackHatEvents, I can safely say this year is going to be epic!
English
1
3
22
9.2K
Web Security Academy retweetledi
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
I haven't posted a crazy XSS vector for a while... Works on every browser
Gareth Heyes \u2028 tweet media
English
12
75
623
31.2K
Web Security Academy
Web Security Academy@WebSecAcademy·
Our newest labs are all about hacking LLMs. You'll learn: 🟧 What's an LLM? 🟧 Prompt injection 🟧 Exploiting LLM APIs, functions, and plugins 🟧 AI-powered scanner vulnerabilities 🟧 Defending against LLM attacks Sound good? Get started here. 👇 portswigger.net/web-security/l…
Web Security Academy tweet media
English
3
51
274
8.7K
Web Security Academy
Web Security Academy@WebSecAcademy·
Burp Intruder has 4 attack types 👇 🔶 Sniper - One payload list in one position 🔶 Battering Ram - Same payload in multiple positions 🔶 Pitchfork - Different payload sets in parallel 🔶 Clusterbomb - All combinations of multiple payload sets Try it out 🧪
Web Security Academy tweet media
English
0
36
155
5.9K
Web Security Academy
Web Security Academy@WebSecAcademy·
A simple bypass through IP based application blocklisting 👇 X-Forwarded-For can be used to bypass the IP based blocklisting if the application is configured to trust this header.
English
4
51
308
16K
Web Security Academy
Web Security Academy@WebSecAcademy·
When you have an exam tomorrow but you can't stop Web Security Academy
Web Security Academy tweet media
English
11
24
246
8.8K
Web Security Academy
Web Security Academy@WebSecAcademy·
Ambiguous URLs are behind many SSRF, CORS, and redirect flaws, but most bypasses are scattered and undocumented. This cheat sheet consolidates payloads, encodings, and IP tricks into one place to assist your testing. Check it out: portswigger.net/web-security/s…
English
2
58
384
17.8K
Web Security Academy
Web Security Academy@WebSecAcademy·
Learn to hack with Portswigger Web Security Academy! Why? Our labs: 🔶 are based on real-world scenarios 🔶 have integrated learning paths 🔶 are 100% FREE You can literally start right now. 👇 portswigger.net/users/register
Web Security Academy tweet media
English
0
7
82
3.9K
Web Security Academy
Web Security Academy@WebSecAcademy·
"kid":"../../dev/null" That’s a classic path traversal payload weaponized inside a JWT Key ID (kid) header. Battle-tested libraries drop these requests, but custom or legacy JWT implementations may still fall for it. Try it out here! 👇 portswigger.net/web-security/j…
Web Security Academy tweet media
English
0
20
125
6K
Web Security Academy
Web Security Academy@WebSecAcademy·
<img src=x onerror=alert(1)> An alert box popped! ⚠️ What next? Popping an alert box is just the start. Dig deep and turn it into a full account takeover, data theft, or lateral movement. Find out how here 👇 portswigger.net/web-security/c…
Web Security Academy tweet media
English
0
14
81
5.2K
Web Security Academy retweetledi
James Kettle
James Kettle@albinowax·
The field of desync flaws arising from deep implementation bugs is absolutely wild. This finding from @calif_io using a fake pseudo-header than gets weaponized by a dodgy length calculation is a great example
Calif@calif_io

MAD Bugs: My Cousin Vinyl (CVE-2026-50052) So the story went like this: Squid was bleeding from a 29-year-old heap overread in her default config. Naturally, she did the only sensible thing: she called her cousin, Vinyl. It turns out Vinyl also had a family problem of his own. blog.calif.io/p/mad-bugs-my-…

English
3
12
78
12.6K
Alan
Alan@lanlico·
Depois de me lascar na parte de defesa (só 45k/mes) é hora de aprender um pouco mais de offsec e ganhar dinheiro igual o @1Iucas I completed the Web Security Academy lab: Unprotected admin functionality @WebSecAcademy portswigger.net/web-security/a…
Português
5
1
49
4.4K