Sign in

Tom Stacey

@t0xodile.com
347 followers 160 following 132 posts

Security researcher at PortSwigger. You can find all of my write-ups and research at thomas.stacey.se.

PostsRepliesMedia
Tom Stacey @t0xodile.com · 23/09/2026
Turbo Intruder 2 has landed! You can now surpass 100,000 RPS over WiFi using the new HTTP/3 engine, test HTTP/3 exclusive targets with the Burp adapter, and deploy new research-grade race condition techniques! Check out the post below for full details:
142
Reposted by Tom Stacey
James Kettle @jameskettle.com · 09/09/2026
Just about to land in Stockholm for SEC-T! Can't wait to meet you all - you can catch the final public delivery of "Can AI Do Novel Security Research? Meet the HTTP Terminator" at 11:15 tomorrow! Do say hi - I'm very happy to chat research, AI, Burp, lifting... also I have stickers.
041
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 25/08/2026
I put a JavaScript URL inside an HTML tag name, and every browser executed it. Apparently, tag names are code now. portswigger.net/research/wha...
<JAVASCRIPT:ALERT(1) onfocus=location=localName autofocus tabindex=1>
1104
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 13/08/2026
I stole an Outlook password with nothing but CSS inside an email 👀 Whitepaper below 👇 This video is from my research "CSS: the bomb inside your inbox". Whitepaper & slides: portswigger.net/research/css...
174
Tom Stacey @t0xodile.com · 12/08/2026
Did you know you can use HTTP header injection to trigger response queue poisoning and make it rain credentials? Learn how with the new @portswiggerres.bsky.social whitepaper "CRLF-Powered Desync Attacks: Beheading HTTP Streams" by @turtlesec.io and I. Read the full paper below 👇
1103
Reposted by Tom Stacey
James Kettle @jameskettle.com · 29/07/2026
Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at @defcon.bsky.social & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there!
093
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 29/07/2026
Next week I'm going to make you terrified of opening your emails...Join me at Black Hat USA for CSS:the bomb inside your inbox
CSS: the bomb inside your inbox
052
Tom Stacey @t0xodile.com · 29/07/2026
Come and see Tobia from @turtlesec.io and I at @blackhatevents.bsky.social and @defcon.bsky.social next week! We cannot wait to share what we've found!
011
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 21/07/2026
I haven't posted a crazy XSS vector for a while... Works on every browser
1396
Tom Stacey @t0xodile.com · 30/06/2026
Finding a technique that initially seems to be a one-off "oh cool that worked" case, but then works on other apps with a few small tweaks is what research is all about, and it is so. much. fun. 🔥
010
Tom Stacey @t0xodile.com · 29/06/2026
Thrilled to announce that @turtlesec.io and I are bringing "CRLF-Powered Desync Attacks: Beheading HTTP Streams" to @defcon.bsky.social. These techniques are producing some truly horrific case studies and we can't wait to share them with you from the main stage!
072
Tom Stacey @t0xodile.com · 18/06/2026
Asked claude to write a basic scan check for a weird variation of my research topic on my pipeline that I've checked *several* times myself... Instantly spat out another horrendous RQP case. 🤦‍♂️ There is a lesson in here somewhere...
010
Reposted by Tom Stacey
Jorian @jorianwoltjer.com · 28/05/2026
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)
jorianwoltjer.com
Finding XSS on Shazzer (literally) | Jorian Woltjer
How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...
096
Reposted by Tom Stacey
Rebane @rebane2001.bsky.social · 22/05/2026
i should frame this
Mastodon thread:
Anton: @rebane2001 Am I missing something or is this still very much exploitable
Rebane: @atjn i haven't tried lmao, i hope not
Rebane: @atjn oh no..
213210
Reposted by Tom Stacey
Rebane @rebane2001.bsky.social · 20/05/2026
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
518229
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 19/05/2026
You may have noticed I've been a bit quiet on social media recently, this is why...I'm going to present at Black Hat! Can't wait to present these techniques! Here is a link to the abstract in case the screenshot is hard to read: blackhat.com/us-26/briefi...
182
Tom Stacey @t0xodile.com · 19/05/2026
Completely flabbergasted... but over the moon to announce with @turtlesec.io that "CRLF-Powered Desync Attacks: Beheading HTTP Streams" is coming to #BHUSA @blackhatevents.bsky.social
320
Reposted by Tom Stacey
Assured Security Consultants @assuredab.bsky.social · 11/05/2026
Do you have experience in penetration testing, perhaps primarily within web security, and want to continue developing your skills? We are looking for a Senior Penetration Tester to join Assured! Read more and apply: www.assured.se/careers/open... #cybersecurity #pentest #infosec #jobs
assured.se
Open position: Senior Penetration Tester
We are currently searching for an experienced pentester who wants to strengthen our clients' resilience in today's digital society. You enjoy analysis, testing and digging deep to really understand th...
143
Tom Stacey @t0xodile.com · 05/05/2026
If there's one thing researchers need more of, it's time. Ironically by automating huge parts of the research process, it sounds like you end up with too many new leads... That's a nicer problem to have though 😁.
020
Reposted by Tom Stacey
James Kettle @jameskettle.com · 28/04/2026
I just did an interview with @mutantzombie.bsky.social with teasers for my upcoming #BHUSA presentation "Can AI Do Novel Vulnerability Research: Meet the HTTP Terminator", plus reflections on the Top Ten Web Hacking Techniques of 2025 & 2026. Watch it here: www.youtube.com/watch?v=fOWh...
youtube.com
Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380
YouTube video by Security Weekly - A CRA Resource
063
Reposted by Tom Stacey
James Kettle @jameskettle.com · 14/04/2026
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract: blackhat.com/us-26/briefi...
0135
Reposted by Tom Stacey
mastersplinter @turtlesec.io · 23/03/2026
Me and @t0xodile.com submitted our latest research to DEF CON 34 CFP, hopefully we get to present it on the big stage! But regardless, it's going to be a banger 🔥
021
Tom Stacey @t0xodile.com · 11/03/2026
The idea that you can go from "0.CL expect-detection v2: 0/200" to a full desync in minutes if the target lets you know that it's running IIS is absolutely bonkers...
020
Tom Stacey @t0xodile.com · 07/03/2026
Prepping CFPs this year has been a great feeling. Something about actually writing down everything we've discovered / built during research from tooling, novel techniques and even bounties gives you that perspective of what we've actually achieved... Mega excited for this one!
000
Tom Stacey @t0xodile.com · 05/03/2026
Love it when someone mentions a vuln class to you that sounds cool and then is suddenly applicable in your very next test! SSRF blacklist bypass using DNS rebinding. The Single-packet attack continues to make my stupid race condition ideas a reality.
030
Tom Stacey @t0xodile.com · 16/02/2026
I'm making a habit of writing down literally any thought that suddenly pops into my head related to research leads. I'm finding it fun to laugh at my own ideas. But all of a sudden, I also have a long list of fun/interesting ideas to try before I need to panic about running out of ideas.
000
Tom Stacey @t0xodile.com · 10/02/2026
The fact that I can use claude in the background to adjust custom tooling on the fly to test out relatively insane theories on the off chance they work all without losing any measurable time for my actual test is really really powerful.
110
Reposted by Tom Stacey
Nicolas Grégoire @agarri.fr · 31/01/2026
Spring is just around the corner, and that's when I offer online training courses on Burp Suite Pro 👨‍🏫 Two sessions are planned (in English and French), and there are still a few spots left in each. Contact me to get an early-bird discount code! 💰
hackademy.agarri.fr
Agarri
Training
065
Reposted by Tom Stacey
Assured Security Consultants @assuredab.bsky.social · 06/02/2026
Our embedded security and cryptography expert Joachim Strömbergson guested a Swedish security podcast (Bli Säker @nikkasystems.com) and discussed Post Quantum Cryptography. Find our English summary and the link to the episode in our blog. www.assured.se/posts/podcas... #pqc #security #cryptography
assured.se
Podcast Spotlight: The Threat from Quantum Computers
Our embedded security and cryptography expert Joachim Strömbergson guested a Swedish security podcast (Bli Säker) and discussed Post Quantum Cryptography.
055
Tom Stacey @t0xodile.com · 06/02/2026
Going here github.com/vladko312/Re... and implementing a selection / all of these into Backslash-Powered Scanner (or a custom scan check...) is probably very useful. The real work comes from creating a safe but syntactically similar payload for the probe pair. Bring back SSTI!
github.com
000
Reposted by Tom Stacey
James Kettle @jameskettle.com · 05/02/2026
The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
1107
Tom Stacey @t0xodile.com · 04/02/2026
Got one of our most impactful cases re-opened and accepted after a quick email chain. Always happy to see programs supporting researchers in this way. Going to try writing my reports with a public disclosure section right at the top to see if this helps in these cases.
020
Tom Stacey @t0xodile.com · 01/02/2026
Spent a long time on a case over the last few weeks getting absolutely nowhere. Remember to try this, instant RQP... I must remember to take my own advise occasionally.
030
Reposted by Tom Stacey
Assured Security Consultants @assuredab.bsky.social · 29/01/2026
Celebrating 100 #security assessments, over 1000 findings, and over 2000 pages of #pentest reports in 2025! www.assured.se/posts/100-se...
assured.se
100 Security Assessments in One Year! Looking back at 2025
In 2025, Assured completed 100 security assessments covering many different industries and technologies. Here are the numbers, and what records we’re aiming to break in 2026.
033
Reposted by Tom Stacey
James Kettle @jameskettle.com · 23/01/2026
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring! apply.workable.com/portswigger/...
088
Tom Stacey @t0xodile.com · 23/01/2026
We got our "bigmac" 🍔 AI machine up and running today! Time to find out if I can start using shadow-repeater every day 🔥
000
Reposted by Tom Stacey
Assured Security Consultants @assuredab.bsky.social · 23/01/2026
Cybersecurity in #MedTech is no longer something you "add later." Under #MDR / #IVDR, security is a prerequisite for market access, not an optional feature. When addressed too late, the result is rework, delays, or products that never make it to market. Read more: www.assured.se/areas/medtec...
assured.se
EU Tightens Cybersecurity Requirements for Medtech - MDR and IVDR
The EU is strengthening cybersecurity requirements in MDR and IVDR. Manufacturers must embed cybersecurity from the start, document processes, and ensure security throughout the entire device lifecycl...
011
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 22/01/2026
🐛 Built a simple RSS reader called Feedworm that runs in DevTools and never phones home. Keep up with blogs and research without selling your data. thespanner.co.uk/introducing-...
thespanner.co.uk
Introducing Feedworm: A Privacy-First RSS Reader That Lives in DevTools - The Spanner
I've been using RSS readers for years. They're the best way to keep up with blogs, news sites, and security research without being at the mercy of algorithmic feeds. But every time I found a reader I ...
153
Tom Stacey @t0xodile.com · 21/01/2026
Needed a custom hackvertor tag for reasons. IIRC there's this AI integration now right? **enter prompt**. Oh okay it works and I'm done. I suspect I've been sleeping on this... One of my favourite extensions atm.
010
Reposted by Tom Stacey
James Kettle @jameskettle.com · 15/01/2026
Voting is now live for the top ten web hacking techniques of 2025! Grab a brew, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques: portswigger.net/polls/top-10...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.
075
Tom Stacey @t0xodile.com · 10/01/2026
On a whim I asked Gemini a ridiculously specific question. "Give me a response that has length X and is text/html for X proxy". And while it basically made up the answer (I assume) it still pointed me to a solution I've needed for months! I Guess trying "stupid ideas" can work for LLMs too.
010
Reposted by Tom Stacey
mjidhage.bsky.social @mjidhage.bsky.social · 08/01/2026
Kom och jobba med mig! @assuredab.bsky.social söker nytt blod. Bland annat en säljansvarig för #securityengineering #allthecybers #cra #nis2 #dora #sdlc www.assured.se/sv/jobb/ledi...
assured.se
Ledig tjänst: Säljansvarig Security Engineering
Vi söker en teknisk konsultsäljare som vill ta ett större ansvar och vara med och bygga upp ett växande affärsområde inom utvecklingsnära säkerhet.
021
Reposted by Tom Stacey
James Kettle @jameskettle.com · 06/01/2026
Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions & make your own nominations here: portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2025: call for nominations
Over the last year, security researchers have shared a huge amount of work with the community through blog posts, presentations, and whitepapers. This is great, but it also means genuinely reusable te
092
Reposted by Tom Stacey
Lauritz @lauritz-holtmann.de · 23/12/2025
[Blog Post] Turning the List-Unsubscribe SMTP Header into an SSRF/XSS Gadget security.lauritz-holtmann.de/post/xss-ssr... Once again, ancient RFCs and overlooked security hot spots in specifications turned out to be worthwhile for security research. Read the spec!
security.lauritz-holtmann.de
Turning List-Unsubscribe into an SSRF/XSS Gadget
The List-Unsubscribe SMTP header is standardized but often overlooked during security assessments. It allows email clients to provide an easy way for end-users to unsubscribe from mailing lists. This ...
022
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 16/12/2025
Bypass CSP in a single click using my new Custom Action, powered by @renniepak.nl's excellent CSP bypass project.
1137
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 09/12/2025
Meet AutoVader. It automates DOM Invader with Playwright Java and feeds results back into Burp. Faster client side bug hunting for everyone. 🚀 thespanner.co.uk/autovader
thespanner.co.uk
AutoVader - The Spanner
Four years ago we released DOM Invader, I added a feature called callbacks that enabled you to execute JavaScript and log when sinks, messages or sources are found. This was so powerful but over the y...
0127
Reposted by Tom Stacey
0xacb @0xacb.com · 25/11/2025
When looking for postMessage vulnerabilities, the FancyTracker Firefox extension can be very useful. It has built-in syntax highlighting and sortes out duplicates. Check it out 👇 github.com/Zeetaz/FancyTracker-FF And the original for Chrome: github.com/fransr/postMessage-track…
011
Reposted by Tom Stacey
jub0bs @jub0bs.com · 21/11/2025
Your weekly reminder to migrate from rs/cors to jub0bs/cors. 😇 github.com/rs/cors/issu...
github.com
With some CORS configurations, some handlers can introduce synchronisation bugs and cause data races · Issue #198 · rs/cors
Problem Presumably for performance, the library (v1.11.1 and some older versions) reuses some non-exported slice variables and struct field from one middleware call to the next: package-level var h...
052
Tom Stacey @t0xodile.com · 20/11/2025
Desync issues are so finicky which is exceptionally fun. I really love the fact that at any point "you might be 1 byte away from a desync". However, you can also be a few hundred connections in turbo-intruder away from a desync as it turns out. If in doubt, (carefully) increase your connection pool.
030
Reposted by Tom Stacey
Gareth Heyes @garethheyes.co.uk · 18/11/2025
🚀 Shadow Repeater just got a big upgrade! It now detects response timing differences. thespanner.co.uk/shadow-repea...
thespanner.co.uk
Shadow Repeater v1.2.3 release - The Spanner
The new version of Shadow Repeater has been released with a couple of cool new features. Timing differences Shadow Repeater analyses your Repeater requests and looks for response differences but it wa...
052