Collected research
Hunting Asynchronous Vulnerabilities
Hunting asynchronous vulnerabilities
Vulnerabilities in background threads and second-order flows produce no visible output, so ordinary scanning misses them. The write-up finds them with exploit-induced out-of-band callbacks, giving environment-independent payloads for XXE and XInclude, SQL injection across five databases, file-write tricks, shell command injection and blind XSS.
Record
- Document
- Hunting asynchronous vulnerabilities
- Researcher
- James Kettle
- Published by
- PortSwigger Research
- Date
- Topic
- Other
In the archive
Related sources
- Hunting Asynchronous Vulnerabilities Whitepaper
- 2016 - James Kettle - Hunting Asynchronous Vulnerabilities
Tags
This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .