Neal Poole
-
1
Welcome!
-
2
Connecting to a (network) shared USB printer using Vista
-
3
Converting data between character sets
-
4
How to Disable Wordpress’s Upgrade System
-
5
jQuery, getJSON, Firefox, and Google Visualization Madness
-
6
Tweeter: An Awesome Tool for Practicing SQL Injections
-
7
PHP and CSV Parsing
-
8
PHP Security Tip: Beware the Opening Tags
-
9
My Favorite Firefox Extensions
-
10
Turning Arbitrary PHP Execution into Shell Access
PortSwigger Blog
-
1
How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years
-
2
Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research
-
3
Case study: How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years
-
4
From capable AI models to trusted security testing
-
5
Introducing Burp AT: agentic AI, built on two decades of Burp Suite
-
6
Burp's new Ambassadors: learn from the people who use Burp Suite everyday
-
7
Heading to Vegas? Meet PortSwigger at Black Hat, BSides, and DEF CON 34.
-
8
What's new in Burp Suite Professional: A year of innovation
-
9
Elevate your testing with Burp AI: watch Clint Gibler’s exclusive interview with PortSwigger’s Dafydd Stuttard and James Kettle
-
10
Meet Burp Suite DAST: Your questions answered
Source Incite
-
1
Chasing a Dream :: Pre-authenticated Remote Code Execution in Dedecms
-
2
Unlocking the Vault :: Unauthenticated Remote Code Execution against CommVault Command Center
-
3
ZohOwned :: A Critical Authentication Bypass on Zoho ManageEngine Desktop Central
-
4
From Shared Dash to Root Bash :: Pre-Authenticated RCE in VMWare vRealize Operations Manager
-
5
IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit
-
6
Eat What You Kill :: Pre-authenticated Remote Code Execution in VMWare NSX Manager
-
7
JNDI Injection Remote Code Execution via Path Manipulation in MemoryUserDatabaseFactory
-
8
Remote Code Execution with Spring Properties
-
9
Samstung Part 2 :: Remote Code Execution in MagicINFO 9 Server
-
10
Samstung Part 1 :: Remote Code Execution in MagicINFO 9 Server
Staaldraad
-
1
Hipsters and data
-
2
Mongo Shell escape
-
3
Huawei Quidway Password Extraction
-
4
Abusing File Converters
-
5
Viewing, modifying and replaying websockets
-
6
Powershell Shells
-
7
tcpprox - An intercepting TCP proxy
-
8
XXE FTP Server - A {web,ftp}-server for XXE
-
9
NAT-to-NAT VPN with WireGuard
-
10
Phishing with OAuth and o365/Azure
Sucuri Blog
-
1
WordPress Security Plugins: How to Choose the Right One
-
2
Vulnerability & Patch Roundup — August 2026
-
3
Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk
-
4
What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk
-
5
The Illusion of a Lock – How AI is changing the speed and scale of hands-on WordPress vulnerability research.
-
6
How to Create a Secure WordPress Staging Site: Beginner’s Guide
-
7
Upgrading How You Sign In to Your Sucuri Account
-
8
Vulnerability & Patch Roundup — July 2026
-
9
Why Delaying WordPress Updates Increases Security Risks
-
10
Vulnerability & Patch Roundup — June 2026
The Recurity Lablog
-
1
Safari HSTS Circumvention
-
2
webOS Revisited - Even More Mistaken Identities
-
3
Uwazi.io Security Assessment
-
4
Discover - The good hackers
-
5
Farewell X/Twitter, Hello Bluesky
-
6
Lernraum Berlin - Security Review
-
7
Secure Coding Training
-
8
Recurity Labs Achieves ISO/IEC 27001 Certification – and Shares Lessons Learned
-
9
CVE-2025-54576 - Bypassing Cluster Authentication
-
10
Farewell, Felix
the world. according to koto
-
1
Geocommons.com admin account hijack
-
2
Beatthis! oracle crypto xmas challenge
-
3
Cursorjacking again
-
4
Intro to Chrome addons hacking: fingerprinting
-
5
Chrome addons hacking: want XSS on google.com?
-
6
Chrome addons hacking: Bye Bye AdBlock filters!
-
7
Fun with data: URLs
-
8
CodeIgniter <= 2.1.1 xss_clean() Cross Site Scripting filter bypass
-
9
XSS ChEF - Chrome extension exploitation framework
-
10
How Facebook lacked X-Frame-Options and what I did with it