Sign in

Tom Stacey

@t0xodile.com
347 followers 160 following 132 posts

Security researcher at PortSwigger. You can find all of my write-ups and research at thomas.stacey.se.

PostsRepliesMedia
Tom Stacey @t0xodile.com · 23/09/2026
Turbo Intruder 2 has landed! You can now surpass 100,000 RPS over WiFi using the new HTTP/3 engine, test HTTP/3 exclusive targets with the Burp adapter, and deploy new research-grade race condition techniques! Check out the post below for full details:
142
Tom Stacey @t0xodile.com · 12/08/2026
Did you know you can use HTTP header injection to trigger response queue poisoning and make it rain credentials? Learn how with the new @portswiggerres.bsky.social whitepaper "CRLF-Powered Desync Attacks: Beheading HTTP Streams" by @turtlesec.io and I. Read the full paper below 👇
1103
Tom Stacey @t0xodile.com · 29/07/2026
Come and see Tobia from @turtlesec.io and I at @blackhatevents.bsky.social and @defcon.bsky.social next week! We cannot wait to share what we've found!
011
Tom Stacey @t0xodile.com · 29/06/2026
Thrilled to announce that @turtlesec.io and I are bringing "CRLF-Powered Desync Attacks: Beheading HTTP Streams" to @defcon.bsky.social. These techniques are producing some truly horrific case studies and we can't wait to share them with you from the main stage!
072
Tom Stacey @t0xodile.com · 19/05/2026
Completely flabbergasted... but over the moon to announce with @turtlesec.io that "CRLF-Powered Desync Attacks: Beheading HTTP Streams" is coming to #BHUSA @blackhatevents.bsky.social
320
Tom Stacey @t0xodile.com · 28/10/2025
Well then... I can tell by looking at the vulnerable domains that this is working. Interestingly, the PDS scan may be identifying things my own tool has missed. Even if not, its ability to go ahead and try out 0.CL / CL.0 is super fancy. I suspect I'll submit a pull request when the time is right 😁
020
Tom Stacey @t0xodile.com · 08/04/2025
Excited to announce I will be speaking at BSides Exeter this year! If you like web research, novel detection techniques and nerding out about desync attacks, feel free to come and listen!
080