Sign in

James Kettle

@jameskettle.com
4.5K followers 136 following 257 posts

Director of Research at @portswigger.net Also known as albinowax Portfolio: jameskettle.com

PostsRepliesMedia
James Kettle @jameskettle.com · 09/09/2026
Just about to land in Stockholm for SEC-T! Can't wait to meet you all - you can catch the final public delivery of "Can AI Do Novel Security Research? Meet the HTTP Terminator" at 11:15 tomorrow! Do say hi - I'm very happy to chat research, AI, Burp, lifting... also I have stickers.
041
James Kettle @jameskettle.com · 30/07/2026
In "Can AI Do Novel Security Research?" I'll share: - A research-machine blueprint for AI enthusiasts - Clearly defined AI fail-points for AI dodgers - Extensive insight into what makes security research work - Many many novel desync goodies Choose your own adventure :)
040
James Kettle @jameskettle.com · 29/07/2026
Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at @defcon.bsky.social & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there!
093
James Kettle @jameskettle.com · 09/06/2026
I'm very happy to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" is coming to DEF CON 34! This research was a huge gamble and the result was glorious, can't wait to share!
281
James Kettle @jameskettle.com · 14/04/2026
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract: blackhat.com/us-26/briefi...
0135
James Kettle @jameskettle.com · 18/03/2026
I've just submitted my latest research to Black Hat USA! This one has been cooking since last June, can't wait to share it with the world... in fact I'm quite excited just to see the community reaction to the title reveal.
070
James Kettle @jameskettle.com · 23/01/2026
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring! apply.workable.com/portswigger/...
088
James Kettle @jameskettle.com · 15/12/2025
Turbo Intruder now has API docs! You can easily discover its many advanced features including - pauseMarker for pause-basd desync.. or DoS - decorators for easy response filtering - 'randomPlz' - wordlists.clipboard for lazy attack setup ...and many more! github.com/PortSwigger/...
131
James Kettle @jameskettle.com · 04/12/2025
You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!
0153
James Kettle @jameskettle.com · 20/08/2025
I just published a Repeater feature to make it easier to explore request smuggling. It repeats your request until the status code changes. It's called "Retry until success" and you can install it via the Extensibility helper bapp.
1145
James Kettle @jameskettle.com · 10/08/2025
Massive thanks to everyone who came to watch HTTP/1.1 Must Die at Black Hat USA & DEF CON! It was great to meet you all and hear your stories, had an absolute blast and I'm psyched to cook up some more madness for next year!
0160
James Kettle @jameskettle.com · 08/08/2025
Watch HTTP/1.1 Must Die live today at 1630 PST! - In person at #defcon33 track 1, main stage - Livestream via YouTube: www.youtube.com/watch?v=ssln...
272
James Kettle @jameskettle.com · 06/08/2025
At #BlackHat? Catch "HTTP/1.1 Must Die! The Desync Endgame" today at 3:20 in Oceanside A, Level 2. Hope to see you there!
081
James Kettle @jameskettle.com · 01/08/2025
Let me know if you'd like to chat research at Black Hat or #defcon33! Also feel free to say hi if you see me about, I've got a not-very-subtle laptop cover to aid recognition 😂
0111
James Kettle @jameskettle.com · 28/07/2025
Ever seen a header injection where achieving a desync seemed impossible? I think I've finally identified the cause - nginx doesn't reuse upstream connections by default, and often has header injection. This means you're left with a blind request tunneling vulnerability 👇
180
James Kettle @jameskettle.com · 14/07/2025
We've just released a massive update to Collaborator Everywhere! This is a complete rewrite by @compass-security.com which adds loads of features including in-tool payload customization. Massive thanks to Compass for this epic project takeover. Check out the new features:
1187
James Kettle @jameskettle.com · 11/07/2025
How to make $$$ from request smuggling Step 1) Pick the right target:
2292
James Kettle @jameskettle.com · 26/06/2025
Concerned about LLM-powered pentesters stealing your job? We've made improving your workflow with AI easier than ever - you can now build your own AI features directly inside Repeater with Custom Actions. Here's one I built for myself:
261
James Kettle @jameskettle.com · 20/06/2025
The upcoming "HTTP/1 must die" WebSecAcademy lab is no longer impossible! This is good news because I'm planning to attempt to live-stream solving it...
0101
James Kettle @jameskettle.com · 11/06/2025
Now I just need to turn my 20gb Burp Suite project file with 73,000 Organizer entries into an enticing slide deck 😂
1240
James Kettle @jameskettle.com · 10/06/2025
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame" is coming to #DEFCON33! This talk will feature multiple new classes of desync attack, mass exploitation spanning multiple CDNs, and over $200k in bug bounties. See you there!
04311
James Kettle @jameskettle.com · 14/05/2025
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser ↓
23918
James Kettle @jameskettle.com · 09/05/2025
When selecting a research topic, it's crucial to consider where the profit potential comes from. Re-reading this old post, it almost feels like a guide to my latest unannounced research! portswigger.net/research/how...
072
James Kettle @jameskettle.com · 26/04/2025
Quarterly deadlift update time! Since setting the goal last June I’ve gone from 2.3x to 2.7x bodyweight, made harder as I gained 5kg 😂 Final 0.3x will probably be much tougher.
070
James Kettle @jameskettle.com · 23/04/2025
I just built a custom action to let you test for race conditions with a single click! No tab groups required, and it uses the cutting edge single-packet attack under the hood: gist.github.com/albinowax/10... For more info check out portswigger.net/research/sma...
0162
James Kettle @jameskettle.com · 17/04/2025
Are you a Burp Repeater power user? The latest release introduces a new feature called 'Custom actions'. With these you can quickly build your own repeater features. Here's a few samples I made for you:
4266
James Kettle @jameskettle.com · 20/03/2025
Are you cooking some quality technical research, and tempted by a trip to Rome in September? Submit it to the RomHack CFP! See you there :) cfp.romhack.io/romhack-2025...
0111
James Kettle @jameskettle.com · 06/03/2025
Sadly, my attempt to perform WAF onboarding on the target website failed 😂
060
James Kettle @jameskettle.com · 10/02/2025
Per popular demand, Turbo Intruder 1.51 now inserts results at the top of the table so you can watch them arrive without scrolling! Let me know how you find it. If you prefer the old behaviour, you can change it back using: table.setSortOrder(0, False)
2232
James Kettle @jameskettle.com · 09/01/2025
ICYMI: Burp Intruder 2024.12 EA now has a capture filter! This enables extremely long-running attacks by stopping junk responses from consuming memory. You might recognise this feature from Turbo Intruder :)
2101
James Kettle @jameskettle.com · 06/12/2024
I'll be at Black Hat Europe next week - let me know if you'd like to meet up... or just collect one of these highly exclusive desync-themed tshirts #BHEU
1323
James Kettle @jameskettle.com · 16/11/2024
1100
James Kettle @jameskettle.com · 15/11/2024
How's your day going?
2252
James Kettle @jameskettle.com · 08/11/2024
You can bypass path-based WAF restrictions by appending raw/unencoded non-printable and extended-ASCII characters like \x09 (Spring), \xA0 (Express), and \x1C-1F (Flask):
0171
James Kettle @jameskettle.com · 05/11/2024
Ever wanted to fuzz a WebSocket? We've just updated WebSocket Turbo Intruder with some new features. If you've used Turbo Intruder already, it should feel familiar :)
083
James Kettle @jameskettle.com · 31/10/2023
Wrote a bamda to detect HTTP responses containing a space in the header name... not sure what we were expecting to find but it definitely worked: return requestResponse.response().headers().stream().anyMatch(e -> e.name().contains(" "));
030
James Kettle @jameskettle.com · 26/10/2023
Here's a Bambda we wrote to identify responses with multiple </html> tags. It got some false-positives due to inline JS, but also revealed a page that we're pretty sure is meant to be behind authentication, and a completely unexpected source code leak!
075
James Kettle @jameskettle.com · 17/10/2023
The new 'Bambda' feature that just landed in @burpsuite.bsky.social 2023.10.3 early-adopter is crazy powerful. I just filtered through 250,000 requests in my proxy history to find ~70 with an incorrect response Content-Length!
0100