Last week I published a number of novel CL.0 desync techniques, alongside advice on tuning your research to outwit the competition.
Next week, a way to turn a 'medium' severity flaw into a crit with a $12k case study. And no it's not XSS :)
https://t.co/S51X5RgKGL
Hope you enjoyed the talk, thanks for coming! Always a pleasure to present to a @defcon crowd. Time for a couple drinks, then on to the next research for me. You can find the sides&whitepaper here: https://t.co/9mykMqxfPh
Burp Suite 2022.8.1 released to the Stable channel, with new scan checks based on the Browser-Powered Desync Attacks presented by @albinowax at Black Hat 2022, as well as new Repeater capabilities that let you test for these vulnerabilities manually.
https://t.co/MdOIOshQNf
We've prototyped a new feature in repeater where we are diffing the last response with the current and showing different colours depending on what changes. Please check it out we'd love your feedback!
https://t.co/sfSRrzrQtF
Burp Suite 2022.7.1 released to the Stable channel. You can now configure tab-specific options for Repeater and automatically detect client-side prototype pollution sources using Burp Scanner.
https://t.co/wOxHIQBIb8
It's worth knowing @Burp_Suite project files are memory mapped. This means they reduce RAM consumption, but don't support garbage collection (yet) so deleting requests frees up RAM for Burp, but doesn't reduce file size. For long-term storage, use 'Project->Save copy' then zip.
How we tune @Burp_Suite's performance:
- "Proxy->Options->Misc->Don't send items to Proxy history or live tasks, if out of scope"
- Enable "Project Options->HTTP->{keep-alive,HTTP/2}"
- Disable live-tasks & extensions
Hey, Folks! Check this weekly series with Zachary Stashis called "There's a BApp for that". It shows a technical how-to-use of certain Burp Suite Plugins to help with Penetration Testing and Bug hunting.
https://t.co/kaG1kXPKnR
#cybersecurity#pentesting#HackRedCon