Sign in

d4d

@zakfedotkin.bsky.social
689 followers 102 following 26 posts

Zak Fedotkin All thought are mine and mine alone

PostsRepliesMedia
d4d @zakfedotkin.bsky.social · 08/12/2025
The Fragile Lock: Novel Bypasses for SAML Authentication will premiere this Wednesday at 10:20 at Black Hat Europe! I'll show you how to chain XML parser quirks to achieve complete authentication bypasses on multiple popular libraries #BHEU @blackhatevents.bsky.social
040
d4d @zakfedotkin.bsky.social · 20/11/2025
I am very proud of this h1 achievement!
081
d4d @zakfedotkin.bsky.social · 07/10/2025
I’m excited to announce that I’ll be presenting The Fragile Lock: Novel Bypasses for SAML Authentication at Black Hat Europe! In this talk, I’ll show how I was able to continuously bypass security patches to achieve complete auth bypass for major libraries. #BHEU @blackhatevents.bsky.social
0266
d4d @zakfedotkin.bsky.social · 17/09/2025
Dive into WebSocket Turbo Intruder 2.0 - fuzz at scale, automate complex multi-step attacks, and exploit faster. The blog post is live! Read it here: portswigger.net/research/web...
portswigger.net
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi
0136
d4d @zakfedotkin.bsky.social · 11/09/2025
WebSocket security testing is so painful that this ever -expanding attack surface is largely overlooked. Learn how to dive where others fear to tread with WebSocket Turbo Intruder. Join me live on Sept 17 at 4PM (GMT+1) discord.gg/portswigger?...
discord.gg
Join the PortSwigger Discord Server!
A place where security professionals, hobbyists, and passionate Burp users can hang out, chat, and collaborate. | 12858 members
041
d4d @zakfedotkin.bsky.social · 03/09/2025
We've just published a novel technique to bypass the __Host and __Secure cookie flags, to achieve maximum impact for your cookie injection findings: portswigger.net/research/coo...
portswigger.net
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
11214
d4d @zakfedotkin.bsky.social · 25/07/2025
I love discrepancies so much that I decided to introduce them to my nickname too @d4d89704243.bsky.social → @zakfedotkin.bsky.social Because why be consistent when you can keep people guessing?
010
d4d @zakfedotkin.bsky.social · 26/06/2025
Thrilled to announce: I’ll be presenting a major new version of WebSocket Turbo Intruder at Black Hat Arsenal 2025! This open-source toolkit makes high-speed, advanced WebSocket attacks practical and painless.
193
d4d @zakfedotkin.bsky.social · 28/05/2025
Active Scan++ just got sharper - we’ve added new checks for OS command injection, powered by our latest ASCII Control Characters research. Install via Extensions -> BApp Store
1106
d4d @zakfedotkin.bsky.social · 07/05/2025
I'm thrilled to announce my talk "Cookie Chaos: Exploiting Parser Discrepancies" at @steelcon.info ! Catch it live in Sheffield, or later on YoutTube. Check out the full abstract here: portswigger.net/research/tal...
portswigger.net
Upcoming Conference Talks - PortSwigger Research
Find details of upcoming talks from the PortSwigger Research team. We also have research papers and recordings available from previous conferences and events.
0245
d4d @zakfedotkin.bsky.social · 30/04/2025
Think you’ve seen every OS command injection trick? Think again, read our latest blog post! Link in the comments👇
1279
d4d @zakfedotkin.bsky.social · 18/03/2025
I’m excited to introduce Namespace Confusion, a novel attack discovered during Gareth's and mySAML Roulette: The Hacker Always Wins research. We uncovered a brutal attack on XML signature validation that destroys authentication in Ruby-SAML!
0236
d4d @zakfedotkin.bsky.social · 05/03/2025
Today's update to the URL Validation Bypass Cheat Sheet includes a new trick: bypassing domain allow lists using a full URL in the query, submitted by Alexis Hapiot! This idea came after our previous update from @dyak0xdb, which sparked great discussions! More updates are live. Link in the reply 👇
1185
d4d @zakfedotkin.bsky.social · 06/02/2025
We've updated our URL validation bypass cheat sheet with this shiny Domain allow list bypass payload contributed by dyak0xdb!
1289
Reposted by d4d
Gareth Heyes @garethheyes.co.uk · 28/01/2025
Discover blocklist bypasses via unicode overflows using the latest updates to ActiveScan++, Hackvertor & Shazzer! Thanks to Ryan Barnett and Neh Patel for sharing this technique. portswigger.net/research/byp...
GET /%0D%0ASet-Cookie: foo=bar
403 Forbidden

GET /%E4%BC%8D%E4%BC%8ASet-Cookie: foo=bar
200 OK
Set-Cookie: foo=bar
03822
d4d @zakfedotkin.bsky.social · 22/01/2025
Hot out of the oven! The Cookie Sandwich – a technique that lets you bypass the HttpOnly protection! This isn't your average dessert; it’s a recipe for disaster if your app isn’t prepared: portswigger.net/research/ste...
portswigger.net
Stealing HttpOnly cookies with the cookie sandwich technique
In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie
03413
d4d @zakfedotkin.bsky.social · 20/12/2024
New in SignSaboteur v1.0.6! Now supports Ruby on Rails Encrypted Cookies: - Brute force secret keys - Decrypt cookie values Update now:
182
d4d @zakfedotkin.bsky.social · 04/12/2024
I really liked how this research turned out. I hope you did too.
1144
d4d @zakfedotkin.bsky.social · 27/11/2024
Hi, Blue Sky! I am a web security researcher at PortSwigger. You can find my latest researches and tools at portswigger.net/research/zak...
portswigger.net
Researcher - Zakhar Fedotkin
Zakhar Fedotkin is a security researcher at PortSwigger, known for his work in exploiting vulnerabilities in image processing libraries and HTTP clients.
0393