Tom Stacey

@t0xodile.com

Security researcher at PortSwigger. You can find all of my write-ups and research at https://thomas.stacey.se.

Finding a technique that initially seems to be a one-off "oh cool that worked" case, but then works on other apps with a few small tweaks is what research is all about, and it is so. much. fun. 🔥

Asked claude to write a basic scan check for a weird variation of my research topic on my pipeline that I've checked *several* times myself... Instantly spat out another horrendous RQP case. 🤦‍♂️ There is a lesson in here somewhere...

I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)

Finding XSS on Shazzer (literally) | Jorian Woltjer

How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...

jorianwoltjer.com

Gareth Heyes@garethheyes.co.uk · 2mo ago

Just want to say @jorianwoltjer.com is awesome. You'll find out why soon...

back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

If there's one thing researchers need more of, it's time. Ironically by automating huge parts of the research process, it sounds like you end up with too many new leads... That's a nicer problem to have though 😁.

Patrick Gray@patrick.risky.biz · 3mo ago

If you would like to see a preview of @jameskettle.com's Blackhat talk "the HTTP terminator" then check out this interview my colleague @jameswilson.io recorded with him. Some pretty freaky stuff! VIDEO: www.youtube.com/watch?v=GdFG... AUDIO: risky.biz/RBNEWSSI126/

The idea that you can go from "0.CL expect-detection v2: 0/200" to a full desync in minutes if the target lets you know that it's running IIS is absolutely bonkers...

Prepping CFPs this year has been a great feeling. Something about actually writing down everything we've discovered / built during research from tooling, novel techniques and even bounties gives you that perspective of what we've actually achieved... Mega excited for this one!

Love it when someone mentions a vuln class to you that sounds cool and then is suddenly applicable in your very next test! SSRF blacklist bypass using DNS rebinding. The Single-packet attack continues to make my stupid race condition ideas a reality.

I'm making a habit of writing down literally any thought that suddenly pops into my head related to research leads. I'm finding it fun to laugh at my own ideas. But all of a sudden, I also have a long list of fun/interesting ideas to try before I need to panic about running out of ideas.

The fact that I can use claude in the background to adjust custom tooling on the fly to test out relatively insane theories on the off chance they work all without losing any measurable time for my actual test is really really powerful.

The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! portswigger.net/research/top...

Top 10 web hacking techniques of 2025

Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

portswigger.net

Got one of our most impactful cases re-opened and accepted after a quick email chain. Always happy to see programs supporting researchers in this way. Going to try writing my reports with a public disclosure section right at the top to see if this helps in these cases.