Top 10 winner
Hunting ASynchronous Vulnerabilities
Bugs in background threads and second-order flows produce no output and no measurable delay, so they survive normal scanning. Sending payloads that make the target itself call back out of band, usually over DNS, exposes them, with context-agnostic callbacks given for XML injection and XXE, SQL injection on PostgreSQL, MySQL, SQLite, MSSQL and Oracle, shell command injection and blind XSS.
Record
- Researcher
- James Kettle
- Published by
- PortSwigger Research
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host.