Thomas Stacey
@t0xodile.com
310 followers
160 following
95 posts
Penetration tester trying to perform novel research. You can find all of my write-ups and research at https://thomas.stacey.se.
Posts
Media
Videos
Starter Packs
Pinned
Thomas Stacey
@t0xodile.com
· May 22
The Single-Packet Shovel: Digging for Desync-Powered Request Tunnelling
In this paper I will reveal the discovery of wide-spread cases of request tunnelling in applications powered by popular servers including IIS, Azure Front Door and AWS' application load balancer inclu...
www.assured.se
Reposted by Thomas Stacey
Reposted by Thomas Stacey
Thomas Stacey
@t0xodile.com
· 10d
Thomas Stacey
@t0xodile.com
· 11d
Thomas Stacey
@t0xodile.com
· 11d
Thomas Stacey
@t0xodile.com
· 11d
Thomas Stacey
@t0xodile.com
· 12d
Reposted by Thomas Stacey
Thomas Stacey
@t0xodile.com
· 17d
Thomas Stacey
@t0xodile.com
· 20d
Reposted by Thomas Stacey
Thomas Stacey
@t0xodile.com
· 25d
Reposted by Thomas Stacey
d4d
@zakfedotkin.bsky.social
· 26d
WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi
portswigger.net
Thomas Stacey
@t0xodile.com
· Sep 12
Thomas Stacey
@t0xodile.com
· Sep 11
Reposted by Thomas Stacey
Reposted by Thomas Stacey
d4d
@zakfedotkin.bsky.social
· Sep 3
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
portswigger.net
Thomas Stacey
@t0xodile.com
· Aug 27