Web Hack List

Collected research

Hunting Asynchronous Vulnerabilities

Hunting asynchronous vulnerabilities

Vulnerabilities in background threads and second-order flows produce no visible output, so ordinary scanning misses them. The write-up finds them with exploit-induced out-of-band callbacks, giving environment-independent payloads for XXE and XInclude, SQL injection across five databases, file-write tricks, shell command injection and blind XSS.

Record

Document
Hunting asynchronous vulnerabilities
Researcher
James Kettle
Published by
PortSwigger Research
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .