James Kettle of PortSwigger on Advancing Web-Attack Research
October 12, 2022
nowthisispodcasting@rapid7.com (James Kettle, Tod Beardsley, Jen Ellis, Jennifer Carson)
Season 5
Episode 20
Interview Links
- Prior Security Nation episode in which loads of PortSwigger references were dropped:
- https://www.rapid7.com/blog/post/2021/08/18/security-nation-daniel-crowley/
- New research from James about browser-powered desync attacks:
- https://portswigger.net/research/browser-powered-desync-attacks
Rapid Rundown Links
- Semi-secret Fortinet advisory:
- CVE Details as they come:
- Existence of Fortinet CVE-2022-40684 PoC posted, but not the PoC itself:
- The Hidden Harms of Silent Patches:
Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.