1. WAF(不)可信任 研究 | 2026-03-25 23:00 | blog.quarkslab.com | 原文 ↗ | #appsec | #web-security | #command-obfuscation
2. HTTP/1.1 必须消亡:攻克 0.CL 挑战 博客 | 2026-03-13 09:21 | portswigger.net | 原文 ↗ | #appsec | #burp-suite | #web-security
3. CORS 安全:超越基本配置 博客 | 2025-11-21 00:00 | aikido.dev | 原文 ↗ | #appsec | #browser-security | #web-security
4. HTTP Anomaly Rank 介绍 研究 | 2025-11-11 14:41 | portswigger.net | 原文 ↗ | #ai-security | #burp-suite | #web-security
5. 破解“透镜”:瞄准 HTTP 隐藏的攻击面 研究 | 2025-09-03 07:38 | portswigger.net | 原文 ↗ | #bug-bounty | #attack-surface | #portswigger
6. 警惕假阴性:如何区分HTTP流水线与请求走私 研究 | 2025-08-19 14:31 | portswigger.net | 原文 ↗ | #burp-suite | #request-smuggling | #false-positives
7. Burp Suite初学者终极指南 博客 | 2024-11-20 13:00 | bugcrowd.com | 原文 ↗ | #bug-bounty | #burp-suite | #web-security
8. Web计时攻击、Apache HTTP混淆攻击、电子邮件解析差异——道德黑客新闻 研究 | 2024-09-30 15:25 | yeswehack.com | 原文 ↗ | #rce | #web-security | #apache
9. 用 TRACE 让 desync 攻击变得简单 研究 | 2024-06-19 13:58 | portswigger.net | 原文 ↗ | #bug-bounty | #request-smuggling | #exploitation
10. 用 bambdas 重塑你的 HTTP 视角 研究 | 2024-05-29 15:03 | portswigger.net | 原文 ↗ | #burp-suite | #graphql | #tooling
11. 理解 HTTP 以及向 HTTPS 的关键转变 博客 | 2024-03-28 01:58 | hackerone.com | 原文 ↗ | #web-security | #networking | #tls
13. 用 Bambdas 找到那个古怪的端点 研究 | 2023-12-12 14:11 | portswigger.net | 原文 ↗ | #burp-suite | #information-disclosure | #bambdas
14. Twisted 19.10.0 版 博客 | 2020-03-11 00:00 | bishopfox.com | 原文 ↗ | #request-smuggling | #python | #advisory