Web Hack List

Top 10 winner

Hunting ASynchronous Vulnerabilities

Hunting asynchronous vulnerabilities

Bugs in background threads and second-order flows produce no output and no measurable delay, so they survive normal scanning. Sending payloads that make the target itself call back out of band, usually over DNS, exposes them, with context-agnostic callbacks given for XML injection and XXE, SQL injection on PostgreSQL, MySQL, SQLite, MSSQL and Oracle, shell command injection and blind XSS.

Record

Document
Hunting asynchronous vulnerabilities
Researcher
James Kettle
Published by
PortSwigger Research
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .