Sign in

James Kettle

@jameskettle.com
4.5K followers 136 following 257 posts

Director of Research at @portswigger.net Also known as albinowax Portfolio: jameskettle.com

PostsRepliesMedia
James Kettle @jameskettle.com · 22/09/2026
My latest presentation has landed on YouTube, courtesy of SEC-T! Can AI do novel security research? You know it. www.youtube.com/watch?v=jCFZ...
youtube.com
SEC-T 0x12: James Kettle - Can AI do novel security research? Meet the HTTP Terminator
YouTube video by SEC-T
030
James Kettle @jameskettle.com · 09/09/2026
Just about to land in Stockholm for SEC-T! Can't wait to meet you all - you can catch the final public delivery of "Can AI Do Novel Security Research? Meet the HTTP Terminator" at 11:15 tomorrow! Do say hi - I'm very happy to chat research, AI, Burp, lifting... also I have stickers.
041
Reposted by James Kettle
Tom Stacey @t0xodile.com · 12/08/2026
Did you know you can use HTTP header injection to trigger response queue poisoning and make it rain credentials? Learn how with the new @portswiggerres.bsky.social whitepaper "CRLF-Powered Desync Attacks: Beheading HTTP Streams" by @turtlesec.io and I. Read the full paper below 👇
1103
James Kettle @jameskettle.com · 07/08/2026
90 minutes till "Can AI do novel security research? Meet the HTTP Terminator" kicks off at #DEFCON main stage 3! Watch the live-stream here at 1200 PDT www.youtube.com/watch?v=9go8...
youtube.com
DEFCON 34: Track 3 Talks
YouTube video by DEFCONConference
092
James Kettle @jameskettle.com · 30/07/2026
In "Can AI Do Novel Security Research?" I'll share: - A research-machine blueprint for AI enthusiasts - Clearly defined AI fail-points for AI dodgers - Extensive insight into what makes security research work - Many many novel desync goodies Choose your own adventure :)
040
James Kettle @jameskettle.com · 29/07/2026
Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at @defcon.bsky.social & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there!
093
Reposted by James Kettle
Richard Johnson @richinseattle.bsky.social · 28/05/2026
Please tell your friends, four weeks before @phrack.org submission deadline! We also are seeking both interior and cover art. We are working with our friends at @pagedout.bsky.social again to create a fancy interior design for our main annual release!! Be a part of hacker history!
065
James Kettle @jameskettle.com · 09/06/2026
I'm very happy to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" is coming to DEF CON 34! This research was a huge gamble and the result was glorious, can't wait to share!
281
Reposted by James Kettle
Patrick Gray @patrick.risky.biz · 04/05/2026
If you would like to see a preview of @jameskettle.com's Blackhat talk "the HTTP terminator" then check out this interview my colleague @jameswilson.io recorded with him. Some pretty freaky stuff! VIDEO: www.youtube.com/watch?v=GdFG... AUDIO: risky.biz/RBNEWSSI126/
youtube.com
Sponsored: James Kettle built an AI hacker
YouTube video by Risky Business Media
2157
James Kettle @jameskettle.com · 28/04/2026
I just did an interview with @mutantzombie.bsky.social with teasers for my upcoming #BHUSA presentation "Can AI Do Novel Vulnerability Research: Meet the HTTP Terminator", plus reflections on the Top Ten Web Hacking Techniques of 2025 & 2026. Watch it here: www.youtube.com/watch?v=fOWh...
youtube.com
Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380
YouTube video by Security Weekly - A CRA Resource
063
James Kettle @jameskettle.com · 27/04/2026
We've launched a new free Web Security Academy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains! Dive in here: portswigger.net/web-security...
portswigger.net
AI-powered scanner vulnerabilities | Web Security Academy
Application security teams often deploy AI-powered scanners that use Large Language Models (LLMs) to scan web applications for vulnerabilities. While ...
1159
James Kettle @jameskettle.com · 14/04/2026
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract: blackhat.com/us-26/briefi...
0135
Reposted by James Kettle
Mastering Burp Suite @mastering-burp.agarri.fr · 10/04/2026
Just discovered the "Find tag" functionnality of Hackvertor and I already find it very useful 🔥 It can be triggered from Burp's command palette or with the Ctrl-Alt-F keyboard shortcut 🐇
222
James Kettle @jameskettle.com · 08/04/2026
How is every doing? I wouldn't call it comfortable, but I'm starting to savor the experience of rediscovering where the new frontier is, every few weeks. It feels like replaying the early stages of my research career. Looking forward to making my own contribution at #BHUSA!🤞
030
James Kettle @jameskettle.com · 18/03/2026
I've just submitted my latest research to Black Hat USA! This one has been cooking since last June, can't wait to share it with the world... in fact I'm quite excited just to see the community reaction to the title reveal.
070
James Kettle @jameskettle.com · 25/02/2026
Access control bypass via header smuggling, with no desync required! Using header smuggling for more than HTTP desync like this is totally underrated - a lot of defences only filter the CL and TE headers. You can detect these with Parser Discrepancy Scan. www.linkedin.com/posts/jakedm...
linkedin.com
Excited to share that I recently identified and responsibly disclosed a security vulnerability in Akamai's edge servers, which has now been fully remediated and assigned CVE-2026-26365! The issue...
Excited to share that I recently identified and responsibly disclosed a security vulnerability in Akamai's edge servers, which has now been fully remediated and assigned CVE-2026-26365! The issue inv...
052
Reposted by James Kettle
Gareth Heyes @garethheyes.co.uk · 10/02/2026
New geolocation-based XSS vectors just landed in our XSS cheat sheet. Huge thanks to AmirMohammad Safari for the great submission. portswigger.net/web-security...
051
James Kettle @jameskettle.com · 05/02/2026
The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
1107
James Kettle @jameskettle.com · 29/01/2026
Thanks to everyone who nominated & voted in the top ten! The panel of @irsdl.bsky.social , @agarri.fr , @liveoverflow.bsky.social and myself are hard at work reviewing the 15 finalists... we're hoping to announce the winners next week!
081
Reposted by James Kettle
Gareth Heyes @garethheyes.co.uk · 28/01/2026
We've just hit a very important milestone - our XSS Cheat Sheet now has 1337 vectors! Browse them here: portswigger.net/web-security...
1143
James Kettle @jameskettle.com · 23/01/2026
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring! apply.workable.com/portswigger/...
088
Reposted by James Kettle
PentesterLab @pentesterlab.com · 21/01/2026
🔥 CVE-2026-23993: HarbourJwt JWT auth bypass via unknown alg. Not just alg=none: unsupported alg => empty signature, so forged token header.payload. passes. Write-up + fix: pentesterlab.com/blog/cve-202...
pentesterlab.com
CVE-2026-23993: JWT authentication bypass in HarbourJwt via “unknown alg”
I didn't know Harbour even existed as a language when I found this bug. The fun part is that I also ...
066
James Kettle @jameskettle.com · 15/01/2026
Voting is now live for the top ten web hacking techniques of 2025! Grab a brew, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques: portswigger.net/polls/top-10...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.
075
James Kettle @jameskettle.com · 06/01/2026
Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions & make your own nominations here: portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2025: call for nominations
Over the last year, security researchers have shared a huge amount of work with the community through blog posts, presentations, and whitepapers. This is great, but it also means genuinely reusable te
092
Reposted by James Kettle
Luke Jahnke @nastystereo.com · 29/12/2025
nastystereo.com/security/rub...
nastystereo.com
Ruby Array Pack Bleed / nastystereo.com
021
Reposted by James Kettle
Gareth Heyes @garethheyes.co.uk · 16/12/2025
Bypass CSP in a single click using my new Custom Action, powered by @renniepak.nl's excellent CSP bypass project.
1137
James Kettle @jameskettle.com · 15/12/2025
Turbo Intruder now has API docs! You can easily discover its many advanced features including - pauseMarker for pause-basd desync.. or DoS - decorators for easy response filtering - 'randomPlz' - wordlists.clipboard for lazy attack setup ...and many more! github.com/PortSwigger/...
131
Reposted by James Kettle
Gareth Heyes @garethheyes.co.uk · 09/12/2025
Meet AutoVader. It automates DOM Invader with Playwright Java and feeds results back into Burp. Faster client side bug hunting for everyone. 🚀 thespanner.co.uk/autovader
thespanner.co.uk
AutoVader - The Spanner
Four years ago we released DOM Invader, I added a feature called callbacks that enabled you to execute JavaScript and log when sinks, messages or sources are found. This was so powerful but over the y...
0127
Reposted by James Kettle
Rebane @rebane2001.bsky.social · 04/12/2025
my new blogpost is out!! this one talks about a new web vulnerability class i discovered that allows for complex interactive cross-origin attacks and data exfiltration and i've already used it to get a google docs bounty ^^ have fun <3 lyra.horse/blog/2025/12...
lyra.horse
SVG Filters - Clickjacking 2.0
A novel and powerful twist on an old classic.
818150
James Kettle @jameskettle.com · 04/12/2025
You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!
0153
Reposted by James Kettle
Gareth Heyes @garethheyes.co.uk · 18/11/2025
🚀 Shadow Repeater just got a big upgrade! It now detects response timing differences. thespanner.co.uk/shadow-repea...
thespanner.co.uk
Shadow Repeater v1.2.3 release - The Spanner
The new version of Shadow Repeater has been released with a couple of cool new features. Timing differences Shadow Repeater analyses your Repeater requests and looks for response differences but it wa...
052
James Kettle @jameskettle.com · 11/11/2025
I've just upgraded Turbo Intruder with a shiny new algorithm called HTTP Anomaly Rank, which automatically finds the most unusual responses in your attack! Here's a quick demo, full details in the writeup below: youtu.be/z92GobdN40Y
youtu.be
HTTP Anomaly Rank - a new Turbo Intruder feature
YouTube video by PortSwigger
2144
Reposted by James Kettle
PortSwigger Research @portswiggerres.bsky.social · 10/11/2025
We've updated our XSS cheat sheet to include 9 new vectors from @garethheyes.co.uk! Here are the top three, you can find the rest here: portswigger.net/web-security...
317419
James Kettle @jameskettle.com · 24/10/2025
Google Cloud Platform was vulnerable to a HTTP desync attack leading to "responses being misrouted between recipients for certain third-party models". Aka your LLM response goes to someone else. The Expect header strikes again! Context: http1mustdie.com cloud.google.com/support/bull...
cloud.google.com
Security Bulletins  |  Customer Care  |  Google Cloud
0145
James Kettle @jameskettle.com · 22/10/2025
HTTP is supposed to be stateless, but sometimes... it isn't! Some servers create invisible vulnerabilities by only validating the first request on each TCP/TLS connection. I've just published a Custom Action to help you detect & exploit this - here's a narrated demo: youtu.be/BAZ-z2fA8E4
youtu.be
HTTP is supposed to be stateless...
YouTube video by PortSwigger
1225
James Kettle @jameskettle.com · 17/10/2025
The official @defcon recording of HTTP/1.1 Must Die has landed - join me on the mission to help kill HTTP/1.1! www.youtube.com/watch?v=PUCy...
youtube.com
DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame - James 'albinowax' Kettle
YouTube video by DEFCONConference
051
James Kettle @jameskettle.com · 08/10/2025
The recording of "HTTP/1.1 must die: the desync endgame" has now landed on YouTube. Enjoy! www.youtube.com/watch?v=zr5y...
youtube.com
RomHack 2025 - James “albinowax” Kettle - HTTP/1.1 Must Die! The Desync Endgame
YouTube video by Cyber Saiyan
1153
Reposted by James Kettle
d4d @zakfedotkin.bsky.social · 07/10/2025
I’m excited to announce that I’ll be presenting The Fragile Lock: Novel Bypasses for SAML Authentication at Black Hat Europe! In this talk, I’ll show how I was able to continuously bypass security patches to achieve complete auth bypass for major libraries. #BHEU @blackhatevents.bsky.social
0266
James Kettle @jameskettle.com · 28/09/2025
It was an absolute privilege to present at #RomHack2025 with such a vibrant and welcoming community! Thanks to everyone who said hi and shared your stories!
1120
James Kettle @jameskettle.com · 27/09/2025
One hour till HTTP/1.1 Must Die kicks off at #romhack2025! Watch the livestream here: m.youtube.com/watch?v=T009...
m.youtube.com
RomHack Conference 2025 Live Stream
YouTube video by Cyber Saiyan
0132
James Kettle @jameskettle.com · 25/09/2025
I'm flying out to #romhack2025 tomorrow, for the final edition of HTTP/1.1 Must Die! Feel free to say hi if you'd like to chat.
0120
James Kettle @jameskettle.com · 18/09/2025
HTTP/1.1 Must Die is coming to #romhack2025 as the keynote! In-person tickets are sold out but you can still watch the livestream. This is your last chance to catch it live - register to watch here: www.youtube.com/watch?v=T009...
youtube.com
RomHack Conference 2025 Live Stream
YouTube video by Cyber Saiyan
094
Reposted by James Kettle
d4d @zakfedotkin.bsky.social · 17/09/2025
Dive into WebSocket Turbo Intruder 2.0 - fuzz at scale, automate complex multi-step attacks, and exploit faster. The blog post is live! Read it here: portswigger.net/research/web...
portswigger.net
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi
0136
Reposted by James Kettle
Compass Security @compass-security.com · 09/09/2025
We use @jameskettle.com Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF. Find out more here: blog.compass-security.com/2025/09/coll... #AppSec #BurpSuite #Pentesting
086
Reposted by James Kettle
d4d @zakfedotkin.bsky.social · 03/09/2025
We've just published a novel technique to bypass the __Host and __Secure cookie flags, to achieve maximum impact for your cookie injection findings: portswigger.net/research/coo...
portswigger.net
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
11214
Reposted by James Kettle
Gareth Heyes @garethheyes.co.uk · 28/08/2025
Imagine you have a XSS vulnerability but you have a undefined variable before your injection. Is all hope lost? Not at all you can use a technique called XSS Hoisting to declare the variable and continue your exploit. Thanks to ycam_asafety for the submission. portswigger.net/web-security...
<script>eval(myUndefVar);var inject="INJECTION_STARTS_HERE";var myUndefVar;alert(1);//";</script>
2187
James Kettle @jameskettle.com · 21/08/2025
When I condense nine months of research discoveries into a 40-min talk, it can make it seem easy. For a taster of the true experience, watch my battle to solve the 0-CL @WebSecAcademy lab! Research is persistence. www.youtube.com/live/B7p8dIB...
youtube.com
Novel HTTP/1 Request Smuggling/Desync Attacks with James Kettle
YouTube video by Off By One Security
0124
James Kettle @jameskettle.com · 20/08/2025
I just published a Repeater feature to make it easier to explore request smuggling. It repeats your request until the status code changes. It's called "Retry until success" and you can install it via the Extensibility helper bapp.
1145
James Kettle @jameskettle.com · 19/08/2025
Ever seen two responses to one request? That's just pipelining... or is it? I've just published "Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling" portswigger.net/research/how...
portswigger.net
Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling
Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining. This is usually a false positive, but sometimes there's actually a real
0136
Reposted by James Kettle
Tom Stacey @t0xodile.com · 13/08/2025
"This strategy creates an avalanche of desync research leads" is somehow an understatement. Take Smuggler for a spin on your largest burp file right now and just watch the issue counter 🔥. If you want even more results, adding new headers / perms looks to be trivial (it's one line of code).
041