PortSwigger Profile Banner
PortSwigger Profile
PortSwigger

@PortSwigger

89,669
Followers
22
Following
132
Media
3,814
Statuses

We are a leading provider of software and learning on web security. We make @Burp_Suite and @WebSecAcademy .

UK
Joined May 2008
Don't wanna be here? Send us removal request.
@PortSwigger
PortSwigger
3 years
NEW CERTIFICATION ALERT! The new Burp Suite Certified Practitioner certification launches today! Learn more and get your exam here! 🎆 #burpsuitecertified
Tweet media one
24
203
566
@PortSwigger
PortSwigger
3 years
Fancy getting Burp Suite Certified for free? Book, take, and pass your exam before 15th Dec 2021 and we'll refund you your $99. Who's ready for the challenge? #burpsuitecertified
26
143
494
@PortSwigger
PortSwigger
5 years
To the very many people who’ve requested a third edition of The Web Application Hacker’s Handbook … I’ve decided not to do one. Instead I’m working on something way more exciting. Details to follow.
16
70
409
@PortSwigger
PortSwigger
2 years
Wait, could this actually be Burp Suite... #tease
Tweet media one
24
31
397
@PortSwigger
PortSwigger
4 years
To all the bug bounty hunters out there: How would you recommend bounty hunters find their very first bug? How did you find your first paid bug? #bugbounty #bugbountytips
21
78
344
@PortSwigger
PortSwigger
2 years
Manual testing with Burp Repeater is now more efficient than ever. Free up screen space by organizing tabs into color-coded groups and collapsing them into a single scrollable row. You can now even search for tabs and groups by name.
12
67
347
@PortSwigger
PortSwigger
6 years
Pressure’s on in the @Burp_Suite office.
Tweet media one
11
61
346
@PortSwigger
PortSwigger
5 years
We have added a new technique by @fasthm00 to Exploiting CORS misconfigurations for Bitcoins and bounties
3
135
330
@PortSwigger
PortSwigger
2 years
PortSwigger has today donated $225,000 to the International Red Cross @ICRC to support their work helping the victims of the attack on Ukraine. Half of this money came from the @PortSwiggerRes bug bounty fund, and this amount was matched by the @PortSwigger business.
4
50
309
@PortSwigger
PortSwigger
2 years
If you often find yourself dealing with too many Repeater tabs, then you're going to love Burp's new tab grouping feature.
Tweet media one
9
51
287
@PortSwigger
PortSwigger
5 years
We have updated our guide on how to become a web security researcher
0
107
280
@PortSwigger
PortSwigger
3 years
@rana__khalil We quite agree! And since we aren't crazy, we'd love to talk about this. Please could you email support @portswigger .net and we'll take things from there?
13
5
258
@PortSwigger
PortSwigger
2 months
Are CSP's getting in the way of scoring that Bug Bounty you have been working on? 😫 Lucky for you, our research team ( @PortSwiggerRes ) has released some new techniques using Form Hijacking to bypass that protection and get you hacking again; enjoy!
2
60
233
@PortSwigger
PortSwigger
3 years
On the first day, PortSwigger created Burp Suite. On the second day, we gave you the Web Security Academy. What do you think is next? #newproductlaunch #burpsuite #websecurityacademy
Tweet media one
22
30
199
@PortSwigger
PortSwigger
4 years
We're pleased to share our product roadmap for 2020, highlighting what's on the way for Burp Suite Enterprise Edition, Burp Suite Professional, and Burp Scanner.
12
71
195
@PortSwigger
PortSwigger
3 years
We’re excited to announce our “women in tech” university scholarship scheme, offering £70,000 of financial support to help young women get started in a tech career. (Near Manchester, UK.)
7
58
187
@PortSwigger
PortSwigger
4 years
It’s BlackHat week and we have some huge things to share: - Conference talk by @albinowax - Blog post with full details - @WebSecAcademy update with labs on brand new vulnerabilities - @Burp_Suite update with scan checks for new issues - Director’s cut of James’s talk on YouTube
3
39
176
@PortSwigger
PortSwigger
2 years
We've slashed the price of our Burp Suite Certified Practitioner exam for Black Friday, and we'll still refund you if you pass. What are you waiting for? #burpsuitecertified #BlackFriday
35
77
180
@PortSwigger
PortSwigger
3 years
Blog post: mapping out Burp Suite's crawler. This is a deep dive into the crawler, which is at the heart of Burp Suite's capabilities, and covers the crawler's origins, its current state and plans for the future.
2
72
178
@PortSwigger
PortSwigger
3 years
For the record, we have no plans ever to charge for access to Web Security Academy labs. The low price of the certification covers the exam proctoring and infrastructure costs.
8
17
173
@PortSwigger
PortSwigger
2 years
Introducing in-app recon to the Web Security Academy, with the brand new mystery lab challenge! This new feature gives academy users the chance to find and exploit vulnerabilities by generating a random lab to test their skills. #mysterylabchallenge
2
43
172
@PortSwigger
PortSwigger
3 years
We're looking for interesting and helpful videos/guides on using Burp Suite as a pentester - what have you all got? Share links to your favourites in the comments below ... #burpsuite
16
43
168
@PortSwigger
PortSwigger
2 years
Just to be clear. To pass the Burp Suite certification exam, you will need access to Burp Suite Pro. It doesn’t matter if it is paid or trial or your work license or anything else. We don’t check your subscription. It’s just impossible to pass the exam without Burp Suite Pro.
11
29
170
@PortSwigger
PortSwigger
4 years
Blog post: Finding your first bug: bounty hunting tips from the Burp Suite community
2
71
158
@PortSwigger
PortSwigger
7 years
I originally wrote Burp to make my day job easier. Glad to hear it’s helping others.
@LaNMaSteR53
Tim Tomes
7 years
Was just sitting here pondering how difficult my job would be without Burp Suite. Thank you @PortSwigger . Seriously. Thank you.
1
5
35
6
19
155
@PortSwigger
PortSwigger
4 years
Burp Scanner now lets you record login sequences using your browser, so you can work with non-standard login mechanisms, single sign-on services, and other challenges.
@Burp_Suite
Burp Suite
4 years
Burp Suite Pro/Community 2020.9.2 released, with support for recorded login sequences in Burp Scanner and various bug/security fixes.
5
45
149
2
40
149
@PortSwigger
PortSwigger
2 years
For everyone who has a Burp Suite Certified Practitioner exam ready to take, we wanted to share a couple of exam pre-prep top tips. We've added some advice from people who've passed already - if you've got any tips then share them below! #burpsuitecertified
14
34
144
@PortSwigger
PortSwigger
3 years
Burp Suite Professional has plenty to learn - so we put our heads together and created a list of resources to help you get started. Anything to add to the list? #BurpSuiteTips #burpsuite
Tweet media one
4
43
140
@PortSwigger
PortSwigger
2 years
"Hunting evasive vulnerabilities: finding flaws that others miss" - from @albinowax - will be premiering at @nullcon Berlin in just a few days. If you can't catch the live event, it'll be available on YouTube post-conference.
9
25
138
@PortSwigger
PortSwigger
3 years
Wondering how to enable DOM Invader? Well, it's available in the early adopter release. So you get it by using the early adopter channel.
4
37
132
@PortSwigger
PortSwigger
2 years
Evaluating an automated web vulnerability scanner? Use our new to put your scanner to the test. This is a realistic example of a modern website, containing serious vulnerabilities you might encounter in the wild.
4
28
125
@PortSwigger
PortSwigger
2 years
This is a Burp extension, and it's only a prototype currently - check it out and feel free to share your thoughts with us!
@PortSwiggerRes
PortSwigger Research
2 years
We've prototyped a new feature in repeater where we are diffing the last response with the current and showing different colours depending on what changes. Please check it out we'd love your feedback!
22
86
574
1
14
124
@PortSwigger
PortSwigger
5 years
It’s official. Burp Suite detects everything except pregnancy.
@_whit_ney_m
whitney🧜🏽‍♀️
5 years
@Burp_Suite Why can’t you detect pregnancy 🤰 LOL
Tweet media one
1
6
28
6
21
119
@PortSwigger
PortSwigger
3 years
🎵 If you're having cert issues I feel bad for ya son, I got $99 problems but the bill ain't one...🎵 All you have to do is pass the Burp Suite cert exam before 15th Dec and we'll refund you your $99 exam fee. #burpsuitecertified #99problems
7
37
120
@PortSwigger
PortSwigger
3 years
Want more attack surface? DOM Invader's got you covered. It'll help discover JavaScript based parameters automatically, and show them in the URLSearchParameters source in the tree view.
3
32
108
@PortSwigger
PortSwigger
4 years
You asked, we answered. Watch Burp Suite creator @DafyddStuttard talk about how Burp started, where the name PortSwigger came from, who Peter Wiener is, getting started in pen testing, the sinister Carlos, and more. #AskMeAnything
7
28
109
@PortSwigger
PortSwigger
3 years
Want to see if a sink is vulnerable?? Either inject the canary and additional characters, or set the canary to include them. You could even use JavaScript URLs as a canary - "javascript:burpdomxss".
0
28
106
@PortSwigger
PortSwigger
3 years
Want to find JSON data structures automatically? Settings > "generate automated messages", to set DOM Invader guessing message structures using specially crafted JavaScript. Click the link below with DOM Invader and post message options enabled:
1
21
93
@PortSwigger
PortSwigger
3 months
Interested in learning how to extract sensitive data from websites when JavaScript is not an option? Our very own @garethheyes has published some new techniques on how to achieve this using Blind CSS Exfiltration. Come and take a look 👀
2
19
92
@PortSwigger
PortSwigger
9 months
Introducing multiple new classes of web race condition, that go far beyond limit-overrun exploits and expose previously overlooked attack surface, alongside new Burp Suite tooling and a brand new set of labs and learning materials.
0
24
91
@PortSwigger
PortSwigger
2 years
It's no bug folks, we actually are offering our certification for just $9 - and if you pass before 15 December '21 we'll still refund you! #burpsuitecertified
Tweet media one
8
24
89
@PortSwigger
PortSwigger
8 months
Calling all Pro/Community users... As part of our table enhancement work, we'd like to know - are tables easier to read with or without zebra stripes? Follow this link to cast your vote 👉
Tweet media one
26
10
88
@PortSwigger
PortSwigger
4 years
PortSwigger is now on YouTube! Do subscribe to see updates on Burp Suite, the Web Security Academy, and PortSwigger research.
0
18
86
@PortSwigger
PortSwigger
6 years
Burp’s UI is getting nicer.
Tweet media one
@Burp_Suite
Burp Suite
6 years
Blog post: The new dashboard #MoBP #BurpSuite
9
129
345
6
20
78
@PortSwigger
PortSwigger
2 years
At Black Hat 2021 @PortSwiggerRes introduced ​​multiple new classes of HTTP/2-exclusive threats and showed how these flaws enable desync attacks. Catch up on these before @albinowax presents the next stage of the journey, Browser-Powered Desync Attacks.
8
21
78
@PortSwigger
PortSwigger
2 years
You can now use DOM Invader to test for client-side prototype pollution. For an overview of how to use the exciting new features from PortSwigger researcher and creator of DOM Invader, Gareth Heyes, check out the following video.
Tweet media one
2
20
77
@PortSwigger
PortSwigger
1 year
Despite being seemingly counterintuitive, starting again from scratch actually presented us with an opportunity to improve code and functionality at a scale not normally possible. And now? It's time to welcome browser-powered scanning 2.0.
0
26
77
@PortSwigger
PortSwigger
3 years
Burp Suite Pro users, we're talking to you. Are there any videos or blogs that you would recommend to first-time users to help them get to know Burp?? #burpsuite
14
10
78
@PortSwigger
PortSwigger
4 years
ICYMI @Burp_Suite Professional and Community Edition now pretty-print JSON, CSS, JavaScript, HTML, and XML automatically.
4
20
70
@PortSwigger
PortSwigger
3 years
For anyone who started using Burp this year, what has been the hardest part of getting started? #burpsuite
30
7
72
@PortSwigger
PortSwigger
3 years
Who's geared up to take their certification exam? Don't forget, if you book and pass before 15th Dec we'll refund your exam fee! Put your skills to the test now with our practice exam ... 💻📖 #burpsuitecertified
2
15
68
@PortSwigger
PortSwigger
2 years
Our expensive lawyers have brought it to our attention that you are passing off a bodily part as a PortSwigger product. We demand that you desist and remove our trademark from your limb (or the limb itself) within 7 days. #April1
6
6
64
@PortSwigger
PortSwigger
4 years
Are you familiar with all of Burp Suite's WebSockets features? Watch this video to see why Burp is so powerful for WebSockets security testing and can find bugs that other tools miss.
@Burp_Suite
Burp Suite
4 years
Burp Suite essentials #10 : How to test WebSockets
0
75
163
0
19
67
@PortSwigger
PortSwigger
30 days
Scanning from an API definition is now possible in Burp Suite Pro. Thanks for having a little patience 😉
1
14
70
@PortSwigger
PortSwigger
3 years
Be one of the first 100 people to become a Burp Suite Certified Practitioner, and get a limited-edition, exclusive swag bundle to show off your new certification! #burpsuitecertified
Tweet media one
1
8
69
@PortSwigger
PortSwigger
7 years
If you see any of the @Burp_Suite team at #bhusa17 come say hello.
Tweet media one
3
23
67
@PortSwigger
PortSwigger
3 years
You asked. We delivered. Well, we will be very soon. The latest workings from the incredible minds of PortSwigger Research, coming soon to a computer near you. #newproductlaunch #burpsuite #websecurityacademy
Tweet media one
2
2
67
@PortSwigger
PortSwigger
3 years
Help us to shape the future of Burp Suite, and build your very best product experience... #burpsuite #productexperience #feedbackmatters
7
24
63
@PortSwigger
PortSwigger
3 years
Let's close the week out with something useful - thanks to a fantastic tweet thread from Burp user @codingo_ we've got a great list of tips and tricks for you all 👌 #BurpSuiteTips #burpsuite
Tweet media one
0
22
63
@PortSwigger
PortSwigger
2 years
It's that funny time of year when life is in limbo, so why not work through some of the labs in our Web Security Academy? Follow the learning path, track your progress, and make sure to delete Carlos! #websecurityacademy #vulnerabilities
4
12
62
@PortSwigger
PortSwigger
3 years
One of our team's most popular breakthroughs so far is now six years old. Don't let age fool you though, Burp Collaborator still rules the roost. #burpsuite
Tweet media one
0
8
62
@PortSwigger
PortSwigger
1 year
So long, and thanks for all the fish. A sad day today as we say goodbye to The Daily Swig - the team have provided the community (and us) with five and a half years' worth of high-quality news, and we're sorry tto announce that this journey has ended.
5
8
62
@PortSwigger
PortSwigger
3 years
Want to see every sink that a site uses? Simply enable DOM Invader, set the canary value to an empty string, then sit back and observe the site sinks …
1
10
60
@PortSwigger
PortSwigger
4 years
Learn how to bypass password logins, avoid account lockout, and defeat two-factor authentication in our awesome new #WebSecurityAcademy topic and labs.
@WebSecAcademy
Web Security Academy
4 years
We've added a brand new topic on authentication vulnerabilities, including 14 new labs!
6
113
386
5
13
60
@PortSwigger
PortSwigger
3 years
How to get real good at hacking: 1. Turn on dark mode in Burp Suite. 2. Follow our @WebSecAcademy learning path. 3. Smash those labs. #hacking #advice #darkmode
4
17
61
@PortSwigger
PortSwigger
4 years
Anybody in the mood for a PortSwigger promo party? Watch this space to find out what we’ve got in store for you next week … #WebSecurityAcademy #LockdownLearning #getswiggywithit
1
7
57
@PortSwigger
PortSwigger
3 years
Find out how browser-powered scanning works under the hood, why this approach is essential for scanning modern web applications, and our exciting plans for building on this foundation.
0
21
56
@PortSwigger
PortSwigger
5 years
The state of the art on blind XXE exploitation has come a long way since I wrote WAHH. Learn about the latest techniques, including one from @_mohemiv that features in @Burp_Suite ’s top ten hacking techniques of 2018.
@WebSecAcademy
Web Security Academy
5 years
We've added a huge new topic, on XXE (XML external entity) injection. Lots of new content and 9 new labs!
5
274
603
0
17
55
@PortSwigger
PortSwigger
3 years
Have you booked your Burp Suite Certified Practitioner exam yet? If you can complete all the "Apprentice" and "Practitioner" level labs in our Web Security Academy you're already well on your way … #burpsuitecertified
Tweet media one
2
9
57
@PortSwigger
PortSwigger
2 years
😂
@D1AL__T0NE
Jess
2 years
All day Dark Mode then bam 💥 Burp Suite documentation @PortSwigger
0
1
3
2
4
54
@PortSwigger
PortSwigger
3 years
Blog post: API scanning with Burp Suite. The web is increasingly reliant on APIs, and this post shows how Burp Suite's Scanner overcomes the problems of crawling them.
0
16
54
@PortSwigger
PortSwigger
3 years
One more day to go folks - keep your eyes peeled tomorrow for our big announcement … #newproductlaunch #burpsuite #websecurityacademy
Tweet media one
6
3
54
@PortSwigger
PortSwigger
2 years
Dastardly is a free, lightweight web application security scanner for your CI/CD pipeline. It looks at your application from the outside - just like an attacker - giving it the sort of accuracy that most static analysis tools can only dream of.
0
15
54
@PortSwigger
PortSwigger
2 years
HTTP Request Smuggling was first documented in 2004 but largely forgotten until @PortSwiggerRes revisited it in 2019. Read up on the original research before @albinowax unveils the latest instalment, Browser-Powered Desync Attacks…
2
12
52
@PortSwigger
PortSwigger
3 years
Has everyone had their minds blown by the latest HTTP/2 research from @albinowax yet?
Tweet media one
4
9
52
@PortSwigger
PortSwigger
4 years
Hackers unite in an amazing display of non-conformity, which is just what we like. No basement, no black hoodie. Just happy hackers. Share your pictures of #ThisIsWhatHackerLooksLike and let's all agree to not follow the herd!
Tweet media one
4
9
52
@PortSwigger
PortSwigger
4 years
New PortSwigger merch store
Tweet media one
8
11
50
@PortSwigger
PortSwigger
8 months
The Burp Suite Certified Practitioner exam is challenging - that means that not only is there no shame in failing, but you're likely to learn something from your failed attempts. Don't worry though; we can help you be better prepared for next time. 👇
0
14
51
@PortSwigger
PortSwigger
8 months
Anyone going to be attending Nullcon Goa on 23 September? If so, it's your last chance to catch the live presentation of @albinowax 's "Smashing the state machine: the true potential of web race conditions" … @nullcon #NullconGoa2023
1
9
49
@PortSwigger
PortSwigger
3 years
Did you know, DOM Invader can inject the canary into every source automatically? Set the canary to an injection and improve automated bug hunting - let DOM Invader do it for you!
1
8
49
@PortSwigger
PortSwigger
6 months
Been trying to find the best way to get started on the Web Security Academy? Introducing learning paths - a carefully curated, structured approach to develop knowledge and enhance skills.
4
8
48