I won't post here anymore. Feel free to join Bluesky or to read the content I post there by simply browsing my profile at bsky.app/profile/mastering-b…
Only one public on-site training session this year, and it will be in RomHack 🇮🇹 (registration link in replies)
And if you're not sure this course would fit you, just give a look at @carbonmanx feedback
I dont post that much, but I do when I feel like its worth it - I have to say having taken the Burp suite Pro training by @Agarri_FR I was totally blown away. I have used burp for over 20 years and have learnt so much that will immediately help me, totally recommend the course!
Come to Roma 🇮🇹 in September and attend the only in-person public training session I'll give in 2026! 👨🏫
And if you like camping with other hackers (as I do), stay over the weekend for the 3-day long RomHack Camp 🏕️
RomHack Training registration is officially open.
Join us in Rome from September 28 to October 1 for six intensive technical tracks led by industry experts:
Full details and registration:
romhack.training#RomHack2026#RomHackTraining
Since EA 2026.2, there's a a search bar in Proxy History and it doesn't work exactly like the usual display filter. Let me explain...
- the filter searches in requests, responses and notes
- the search bar looks for the keyword in the table of entries itself
An interesting piece of trivia: the search bar works on custom columns (the ones created via bambdas) and also on hidden ones (whatever they are custom or not)
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published
- March 24th to 27th, in French 🇫🇷
- April 14th to 17th, in English 🇬🇧
hackademy.agarri.fr/2026
PS: ping me if you'd like to temporarily block a seat or are looking for a 10% coupon 🎁
I won't post here anymore. Feel free to join Bluesky or to read the content I post there by simply browsing my profile at bsky.app/profile/mastering-b…
Plenty of new followers today 📈
To be honest, I don’t really use X anymore, and I invite all of you to follow me on Bluesky, where I post regularly
bsky.app/profile/did:plc:beq…
I just added the 15-minute talk I gave at Tumpicon to the "Freebies" section
This talk covers the extensions Piper and Scalpel, and allows users to easily manipulate encrypted data by shuffling blocks around
hackademy.agarri.fr/freebies
Basically allows you to execute **any** tool/command on **any** part of an HTTP request/réponse. It can pipe tools together as well as automatically execute pipelines. You can even launch GUI tools such as meld for easy diffing @Agarri_FR mentioned it a while ago and it's awesome
The Early Adopter v2025.1 of Burp Suite Pro fixes the bug where the Home and End keys caused the cursor to jump to a different line 🥳
portswigger.net/burp/release…
Burp PSA:
If you want to use a large file of payloads in Intruder, *DO NOT* use Simple list's "Load" feature. Simple list is designed for "simple" lists, and it loads the entire file into a GUI JList. This is fine for small wordlists, but will absolutely become a memory issue for larger ones.
Use Runtime file instead!
Hackvertor now supports tags `<@space/>` and `<@newline/>`
That doesn't look like a game-changer, but it's incredibly useful when you want to avoid that these raw characters break Burp's HTTP parsing
1️⃣ Find XXE vulnerabilities
XXE vulnerabilities are becoming quite rare to spot these days
But with this simple rule, we can increase our chances of coming across one