We love a bit of competition here at the Web Security Academy, and that's why we have the Hall of Fame! We announce each of our labs on X, so don't miss out.
3
47
3,374
Absolutely incredible research by @garethheyes One email, two readers. :before and :after inject text into the page. An AI browser reading the message does not see that text. opacity:0.00000001 does the reverse. The victim cannot read the element, but the AI browser can. Read CSS:the bomb inside your inbox by Gareth to learn more 👇 portswigger.net/research/css…
1
14
57
5,080
Just because there's no XML in the body, doesn't mean it won't be parsed as XML! It's rare, but it happens. Learn more here 👇 portswigger.net/web-security…
6
33
311
18,616
Nothing makes us prouder than educating the world's next generation of hackers! Over the years we've: 👨‍💻 Released 247 free labs 👨‍💻 Served 90,000 up and coming hackers 👨‍💻 Ran an 18,000 strong Discord community 👨‍💻 Served hackers in 170 countries Hackers are more important than they've ever been. Keep at it 💪
4
11
136
4,858
SQL injection is great, but what if you can't see the response? Enter Blind SQL Injection! In this walkthrough, we exfiltrate the administrator's password from the database from a blind SQLi using DNS 👀 Check it out, and follow along here (it's free) 👇 portswigger.net/web-security…
2
14
110
6,366
Hackers asked for a third edition of The Web Hacker’s Handbook. Rather than releasing another book which will quickly get out-dated, we created the Web Security Academy, a living, constantly updated learning hub with hands-on labs and video walk-throughs so you can learn by doing, not just reading. portswigger.net/web-security…
1
27
276
10,950
Getting a pingback on Burp Collaborator might just be the best feeling in the world.
3
1
95
6,510
Wheeeeeeee!
13
30
325
8,933
The thing about XSS, is that the correct payload varies wildly depending on exactly where the injection lands on the page. This video walks through one of our DOM XSS challenges, you can follow along in the free lab here 👇 portswigger.net/web-security…
5
50
5,124
The app your testing might have CSRF tokens - but are those CSRF tokens tied to a session? If not, we can use a token from our own session to make the victim perform actions they never intended. Let me show you! Test it out yourself here 👇 portswigger.net/web-security…
1
8
85
5,452
Single-use actions like coupons, one-time transactions, votes, and discount codes are checked by the application for limits. For example - a coupon code should only be applied if it hasn't already been used. Often there is a gap between checking if the coupon is applied, and applying the coupon, like this: - Check if coupon has been applied *** GAP *** - If it hasn't been applied, apply the coupon If you send the request multiple times within that gap, you can potentially apply the coupon multiple times. This is called a "race condition", and it's a type of vulnerability that is often overlooked. In this video, we squeeze over 20 requests into that gap to see how the application handles it. You can try it yourself here: portswigger.net/web-security…
2
5
94
5,204
We've been getting a lot of enquiries about hacking AI / LLMs recently. The best place to start is our "Web LLM Attacks" section, which contains 8 lessons and hands-on labs that will leave you well equipped for the real world. Check it out here 👇 portswigger.net/web-security…
5
48
5,002
There's no place like 127.0.0.1, but this IP address is often blocked for SSRF payloads. Thankfully - IP addresses are super weird, so you can write them in a bunch of different formats, some of which might bypass SSRF protections. Try these, which are all the same as 127.0.0.1: 👉 2130706433 👉 017700000001 👉 127.1 👉 Any hostname that resolves to 127.0.0.1 Learn more about circumventing common SSRF defenses here: portswigger.net/web-security…
3
6
67
5,446
We're lucky to have so many great folks in the hacker community creating content about the Web Security Academy! Daniel Lowrie (@daniellowrie_) has a YouTube playlist of lab walkthroughs which you can find here. The best part is that he doesn't just *do* the labs, he explains his thought process, so the whole thing becomes an interactive learning experience. We'd recommend following along in the labs as you go! piped.video/watch?v=rY-7gT4S…
5
53
6,484
GraphQL introspection made easy: once you identify a GraphQL endpoint, send a request to Burp Repeater and use the GraphQL tab. Right-click in the request pane → GraphQL → Set introspection query, then click Send. The server’s JSON response will contain the full schema if introspection is allowed 🤞 Now you can right-click the response and “Save GraphQL queries to site map”, and all of the queries will magically populate your site map 🎉
1
14
122
5,983
If you're looking for some more advanced reading, @garethheyes figured out how to use CSS in emails to steal passwords. This is what platinum tier security research looks like. portswigger.net/research/css…
1
20
146
7,381
Web Security Academy retweeted
“Burp AT re-wrote the book.” Mario Contestabile used Burp AT to investigate potential IDOR and XSS findings in seconds, while keeping testing decisions firmly in his hands. Share your best Burp AT story with #BurpAT for a chance to win exclusive swag. We want to hear yours too!
5
18
6,729
The hacking community is incredible. We're so lucky to be involved with such a diverse group of genius rebels every day. If you're the type of person who is intelligent, curious and endlessly persistent, hacking might just be your "thing". Join us! 👇 portswigger.net/web-security
9
62
4,967
Why do you need to know how many columns a SQL query returns before we can exploit it? How do you figure it out? Here's a good explainer, and you can follow along yourself in our free lab 👇 portswigger.net/web-security…
3
62
5,796