Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

James Kettle

@albinowax@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Director of Research at PortSwigger aka
Burp Suite

3922 Followers
26 Following
17 Posts
Joined November 07, 2022
Homepage:
https://jameskettle.com/
Twitter:
https://twitter.com/albinowax
LinkedIn:
https://www.linkedin.com/in/james-kettle-albinowax/
PortSwigger:
https://portswigger.net/research
Open post
James Kettle @albinowax@infosec.exchange
· 2w ago
My latest presentation has landed on YouTube, courtesy of SEC-T! Can AI do novel security research? You know it. https://www.youtube.com/watch?v=jCFZFDHnZrQ

SEC-T 0x12: James Kettle - Can AI do novel security research? Meet the HTTP Terminator

6
0
6
1
Open post
James Kettle @albinowax@infosec.exchange
· 2mo ago
The whitepaper is live! Read "Can AI Do Novel Security Research? Meet the HTTP Terminator" here: https://portswigger.net/research/http-terminator
portswigger.net
5
1
10
0
Open post
James Kettle @albinowax@infosec.exchange
· 2mo ago
Next week I'll present "Can AI Do Novel Security Research? Meet the HTTP Terminator" at DEF CON & Black Hat USA! I'm really excited to share this one - got some spectacular outcomes from a wild research journey. See you there! #DEFCON
5
0
2
0
Open post
James Kettle @albinowax@infosec.exchange
· 2mo ago

In "Can AI Do Novel Security Research?" I'll share:

  • A research-machine blueprint for AI enthusiasts
  • Clearly defined AI fail-points for AI dodgers
  • Extensive insight into what makes security research work
  • Many many novel desync goodies

I'll also publish major updates to Turbo Intruder, Param Miner and HTTP Request Smuggler. Plus the full source of the HTTP Terminator itself. Choose your own adventure :)

4
0
5
0
Open post
James Kettle @albinowax@infosec.exchange
· 6mo ago

I've just submitted my latest research to Black Hat USA! This one has been cooking since last June, can't wait to share it with the world... in fact I'm quite excited just to see the community reaction to the title reveal.

10
1
2
1
Open post
James Kettle @albinowax@infosec.exchange
· 10mo ago

You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!

infosec.exchange

Infosec Exchange

17
0
13
0
Open post
James Kettle @albinowax@infosec.exchange
· 8mo ago

The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! https://portswigger.net/research/top-10-web-hacking-techniques-of-2025

portswigger.net
9
0
9
1
Open post
James Kettle @albinowax@infosec.exchange
· 5mo ago

I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract:
https://blackhat.com/us-26/briefings/schedule/?#can-ai-do-novel-security-research-meet-the-http-terminator-51894

blackhat.com
5
0
5
0
Open post
James Kettle @albinowax@infosec.exchange
· 5mo ago

I just did an interview with Application Security Weekly with teasers for my upcoming #BHUSA presentation "Can AI Do Novel Vulnerability Research: Meet the HTTP Terminator", plus reflections on the Top Ten Web Hacking Techniques of 2025 & 2026. Watch it here:
https://www.youtube.com/watch?v=fOWhhTrGtoI

Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380

3
0
4
0
Open post
James Kettle @albinowax@infosec.exchange
· 8mo ago

Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring!

https://apply.workable.com/portswigger/j/FC27ED6166/

apply.workable.com
6
2
11
0
Open post
James Kettle @albinowax@infosec.exchange
· 8mo ago

Voting is now live for the top ten web hacking techniques of 2025! Grab a brew, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques:
https://portswigger.net/polls/top-10-web-hacking-techniques-2025

portswigger.net
6
0
2
1
Open post
James Kettle @albinowax@infosec.exchange
· 6mo ago

How is every doing? I wouldn't call it comfortable, but I'm starting to savor the experience of rediscovering where the new frontier is, every few weeks. It feels like replaying the early stages of my research career. Looking forward to making my own contribution at #BHUSA!🤞

infosec.exchange

Infosec Exchange

3
0
0
0
Open post
James Kettle @albinowax@infosec.exchange
· 9mo ago

Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions & make your own nominations here: https://portswigger.net/research/top-10-web-hacking-techniques-of-2025-nominations-open

portswigger.net
4
0
6
0
Open post
James Kettle @albinowax@infosec.exchange
· 7mo ago

Access control bypass via header smuggling, with no desync required! Using header smuggling for more than HTTP desync like this is totally underrated - a lot of defences only filter the CL and TE headers. You can detect these with Parser Discrepancy Scan.
https://www.linkedin.com/posts/jakedmurphy1_excited-to-share-that-i-recently-identified-activity-7431735557115789313-xhnA/

LinkedIn

Excited to share that I recently identified and responsibly disclosed a security vulnerability in Akamai's edge servers, which has now been fully remediated and assigned CVE-2026-26365! The issue… | Jake M. | 11 comments

Excited to share that I recently identified and responsibly disclosed a security vulnerability in Akamai

2
0
4
0
Open post
James Kettle @albinowax@infosec.exchange
· 26mo ago

Have you ever been tempted to dive down the security research rabbit-hole? I'll be sharing insights on how to navigate the rewards and hazards with legendary researchers Natalie Silvanovich and @raistlin@sociale.network in a community panel session at Black Hat USA next week!

sociale.network

Stefano Zanero (@raistlin@sociale.network) - sociale.network

12
1
6
0
Open post
James Kettle @albinowax@infosec.exchange
· 9mo ago

Turbo Intruder now has API docs! You can easily discover its many advanced features including
- pauseMarker for pause-basd desync.. or DoS
- decorators for easy response filtering
- 'randomPlz'
- wordlists.clipboard for lazy attack setup
...and many more!
https://github.com/PortSwigger/turbo-intruder/blob/dev/docs/index.md

github.com
1
0
0
0
Open post
James Kettle @albinowax@infosec.exchange
· 15mo ago
Replying to
@jduck@infosec.exchange Ack, sorry to hear that. Hope everyone gets better soon.
1
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 12:16:17 UTC