Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5128Exploiting CORS misconfigurations for Bitcoins and bounties CORS misconfiguration NA James Kettle (@albinowax) Bug Bounty2016-10-122023-06-13
5124Backslash Powered Scanning: hunting unknown vulnerability classes - NA James Kettle (@albinowax) Bug Bounty2016-11-042023-06-13
5016Cracking the lens: targeting HTTP%27s hidden attack-surface Reflected XSS SSRF Yahoo! / Verizon Media BT New Relic James Kettle (@albinowax) Bug Bounty2017-07-272023-06-13
4644Practical Web Cache Poisoning Web cache poisoning Mozilla HubSpot Cloudflare Binary.com Amazon (CloudFront) James Kettle (@albinowax) Bug Bounty2018-08-092023-06-13
4545Bypassing Web Cache Poisoning Countermeasures Web cache poisoning Cloudflare James Kettle (@albinowax) Bug Bounty2018-10-052023-06-13
3866Responsible denial of service with web cache poisoning DoS Web cache poisoning Tesla HackerOne Deliveroo Bitbucket Paypal Meta / Facebook Twitter James Kettle (@albinowax) Bug Bounty2019-10-242023-06-13
3819Cracking reCAPTCHA, Turbo Intruder style Captcha bypass Race condition Google James Kettle (@albinowax) Bug Bounty2019-11-202023-06-13
1254Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling HTTP Request Smuggling Desync attack AWS Amazon Akamai Cisco Verisign Pulse Secure Varnish James Kettle (@albinowax) Bug Bounty2022-08-102023-06-13
1121How to turn security research into profit: a CL.0 case study HTTP request smuggling Desync attack NA James Kettle (@albinowax) Bug Bounty2022-09-082023-06-13
1048Making HTTP header injection critical via response queue poisoning HTTP header injection HTTP request smuggling NA James Kettle (@albinowax) Bug Bounty2022-09-222023-06-13
932HTTP/3 connection contamination: an upcoming threat? HTTP connection contamination NA James Kettle (@albinowax) Bug Bounty2022-10-192023-06-13