<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <lastBuildDate>Tue, 25 Dec 2018 01:17:41 GMT</lastBuildDate>
    <title><![CDATA[PortSwigger Web Security Blog]]></title>
    <description><![CDATA[]]></description>
    <link>https://portswigger.net/blog</link>
    <image>
      <url>https://portswigger.net/blog/rss/icon</url>
      <title><![CDATA[PortSwigger Web Security Blog]]></title>
      <link>https://portswigger.net/blog</link>
    </image>
    <language><![CDATA[en-gb]]></language>
    <atom:link href="https://portswigger.net/blog/rss" rel="self" type="application/rss+xml" />
    <item>
      <guid isPermaLink="false">exposing-intranets-with-reliable-browser-based-port-scanning</guid>
      <pubDate>Fri, 09 Nov 2018 14:47:51 GMT</pubDate>
      <title><![CDATA[Exposing Intranets with reliable Browser-based Port scanning]]></title>
      <description><![CDATA[In this blog post I describe how I created a port scanner using JavaScript. If you are just interested in the tool you can get it here: Port scanner proof of concept Scanning for ports on Chrome There]]></description>
      <link>https://portswigger.net/blog/exposing-intranets-with-reliable-browser-based-port-scanning</link>
      <media:thumbnail url="https://portswigger.net" />
    </item>
    <item>
      <guid isPermaLink="false">top-10-web-hacking-techniques-of-2017</guid>
      <pubDate>Thu, 11 Oct 2018 14:40:39 GMT</pubDate>
      <title><![CDATA[Top 10 Web Hacking Techniques of 2017]]></title>
      <description><![CDATA[The verdict is in! Following 37 nominations whittled down to a shortlist of 15 by a community vote, our panel of experts has conferred and selected the top 10 web hacking techniques of 2017 (and 2016)]]></description>
      <link>https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017</link>
      <media:thumbnail url="https://portswigger.net/cms/images/37/aa/5d56cc39864a-twittercard-top-10-hacking-techniques-winners-twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-2-0-how-do-i-throttle-requests</guid>
      <pubDate>Wed, 10 Oct 2018 15:04:26 GMT</pubDate>
      <title><![CDATA[Burp 2.0: How do I throttle requests?]]></title>
      <description><![CDATA[When performing scans, you might want to limit the rate at which requests are made. Burp 1.x had settings for request throttling within the Spider and Scanner tools. These settings applied to all requ]]></description>
      <link>https://portswigger.net/blog/burp-2-0-how-do-i-throttle-requests</link>
      <media:thumbnail url="https://portswigger.net/cms/images/8d/25/b6b1c7f958a2-twittercard-screenshot_2018-10-09_at_16.04.28.png" />
    </item>
    <item>
      <guid isPermaLink="false">bypassing-wafs-and-cracking-xor-with-hackvertor</guid>
      <pubDate>Tue, 09 Oct 2018 14:53:21 GMT</pubDate>
      <title><![CDATA[Bypassing WAFs and cracking XOR with Hackvertor]]></title>
      <description><![CDATA[You might not be aware of the Hackvertor extension I've been working on lately. It features tag based conversion that is far more powerful than the inbuilt decoder in Burp. The idea behind tag based c]]></description>
      <link>https://portswigger.net/blog/bypassing-wafs-and-cracking-xor-with-hackvertor</link>
      <media:thumbnail url="https://portswigger.net/cms/images/55/6c/80a5e539dc48-twittercard-hackvertor-2x1.png" />
    </item>
    <item>
      <guid isPermaLink="false">bypassing-web-cache-poisoning-countermeasures</guid>
      <pubDate>Fri, 05 Oct 2018 15:00:50 GMT</pubDate>
      <title><![CDATA[Bypassing Web Cache Poisoning Countermeasures]]></title>
      <description><![CDATA[Following my presentation and whitepaper on Web Cache Poisoning last month, various companies have deployed defences in an attempt to mitigate cache poisoning attacks. In this post I’ll take a look at]]></description>
      <link>https://portswigger.net/blog/bypassing-web-cache-poisoning-countermeasures</link>
      <media:thumbnail url="https://portswigger.net/cms/images/19/a3/1420b6920c27-twittercard-cache-poisoning-mitigation-article.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-2-0-where-is-live-scanning</guid>
      <pubDate>Thu, 04 Oct 2018 14:00:00 GMT</pubDate>
      <title><![CDATA[Burp 2.0: Where is live scanning?]]></title>
      <description><![CDATA[Burp 1.x had some features tucked away within the Spider and Scanner tools that controlled the automated processing that Burp performed on traffic passing through the Proxy. Where have these features ]]></description>
      <link>https://portswigger.net/blog/burp-2-0-where-is-live-scanning</link>
      <media:thumbnail url="https://portswigger.net/cms/images/9f/30/9976fb3cb220-twittercard-b9995a6db86e-article-screen_shot_2018-09-14_at_12.11.57.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-2-0-how-do-i-scan-individual-items</guid>
      <pubDate>Wed, 03 Oct 2018 14:00:00 GMT</pubDate>
      <title><![CDATA[Burp 2.0: How do I scan individual items?]]></title>
      <description><![CDATA[When manually testing an application you often want to perform a scan of a single item of interest or a small range of requests. Burp 2 gives you more powerful ways of doing this. Burp 1.x In Burp 1.x]]></description>
      <link>https://portswigger.net/blog/burp-2-0-how-do-i-scan-individual-items</link>
      <media:thumbnail url="https://portswigger.net/cms/images/d6/f2/e772fdb7963f-twittercard-screen_shot_2018-09-13_at_14.49.47.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-2-0-where-is-the-scan-queue</guid>
      <pubDate>Tue, 02 Oct 2018 14:00:00 GMT</pubDate>
      <title><![CDATA[Burp 2.0: Where is the scan queue?]]></title>
      <description><![CDATA[Burp 1.x had a fairly prominent view of the active scan queue, which you could monitor to see how your scanning was progressing. Where has this gone? Burp 1.x Previously, the top-level Scanner tab let]]></description>
      <link>https://portswigger.net/blog/burp-2-0-where-is-the-scan-queue</link>
      <media:thumbnail url="https://portswigger.net/cms/images/d7/a0/5176ca272d76-twittercard-8d8ec8d1f44b-article-screen_shot_2018-09-20_at_11.11.53.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-2-0-where-are-the-spider-and-scanner</guid>
      <pubDate>Mon, 01 Oct 2018 14:00:00 GMT</pubDate>
      <title><![CDATA[Burp 2.0: Where are the Spider and Scanner?]]></title>
      <description><![CDATA[This week, we'll be publishing a series of blog posts aimed at helping people move from Burp 1.x to Burp 2.0. We'll be looking at various Burp features that work in a different way in Burp 2.0, and he]]></description>
      <link>https://portswigger.net/blog/burp-2-0-where-are-the-spider-and-scanner</link>
      <media:thumbnail url="https://portswigger.net/cms/images/b3/32/4a10a92056fe-twittercard-229561eb8d25-article-screen_shot_2018-09-14_at_14.14.50.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-suite-enterprise-edition-beta-now-available</guid>
      <pubDate>Fri, 31 Aug 2018 10:34:20 GMT</pubDate>
      <title><![CDATA[Burp Suite Enterprise Edition beta now available]]></title>
      <description><![CDATA[Burp Suite Enterprise Edition 1.0 beta is now available, for purchase and free trial. This is a brand new product with the following key features: Server installation with a scalable architecture, and]]></description>
      <link>https://portswigger.net/blog/burp-suite-enterprise-edition-beta-now-available</link>
      <media:thumbnail url="https://portswigger.net/cms/images/b8/85/12895e89aab9-twittercard-enterprise_logo_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">enterprise-edition-ci-integration</guid>
      <pubDate>Thu, 30 Aug 2018 15:41:00 GMT</pubDate>
      <title><![CDATA[Enterprise Edition: CI integration]]></title>
      <description><![CDATA[Burp Suite Enterprise Edition has full support for integration with CI/CD systems. There is a REST API that can be used to initiate scans and obtain the results: There is a native Burp CI plugin&nbsp;]]></description>
      <link>https://portswigger.net/blog/enterprise-edition-ci-integration</link>
      <media:thumbnail url="https://portswigger.net/cms/images/db/7b/b837179ad6c0-twittercard-team_city_ci_plugin_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">enterprise-edition-configuring-your-team</guid>
      <pubDate>Wed, 29 Aug 2018 15:48:00 GMT</pubDate>
      <title><![CDATA[Enterprise Edition: configuring your team]]></title>
      <description><![CDATA[Burp Suite Enterprise Edition supports simultaneous access by multiple users, and lets you configure role-based access control (RBAC). You can define roles within the application, or use the predefine]]></description>
      <link>https://portswigger.net/blog/enterprise-edition-configuring-your-team</link>
      <media:thumbnail url="https://portswigger.net/cms/images/48/42/297eaeb278b2-twittercard-users_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">enterprise-edition-agents</guid>
      <pubDate>Tue, 28 Aug 2018 16:16:00 GMT</pubDate>
      <title><![CDATA[Enterprise Edition: agents]]></title>
      <description><![CDATA[The key to Burp Suite Enterprise Edition's extreme scalability is the pool of agents: Agents can be installed on indefinitely many computers, including the main Enterprise server itself. Each agent co]]></description>
      <link>https://portswigger.net/blog/enterprise-edition-agents</link>
      <media:thumbnail url="https://portswigger.net/cms/images/e0/d7/5eced2e06684-twittercard-agents_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">enterprise-edition-performing-scans</guid>
      <pubDate>Mon, 27 Aug 2018 16:10:00 GMT</pubDate>
      <title><![CDATA[Enterprise Edition: performing scans]]></title>
      <description><![CDATA[Burp Suite Enterprise Edition can scan multiple web sites in parallel. Scans can be performed on demand, or on a schedule, or using the REST API. Today, we're going to look at how you perform scans us]]></description>
      <link>https://portswigger.net/blog/enterprise-edition-performing-scans</link>
      <media:thumbnail url="https://portswigger.net/cms/images/2e/fa/f8269cedf44e-twittercard-scans_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">enterprise-edition-configuring-web-sites</guid>
      <pubDate>Sun, 26 Aug 2018 15:57:00 GMT</pubDate>
      <title><![CDATA[Enterprise Edition: configuring web sites]]></title>
      <description><![CDATA[Burp Suite Enterprise Edition will let you configure details of all your organization's web sites, so that they are available for scheduled scanning. Sites can be organized into a tree structure using]]></description>
      <link>https://portswigger.net/blog/enterprise-edition-configuring-web-sites</link>
      <media:thumbnail url="https://portswigger.net/cms/images/8b/4f/a86da3b864b6-twittercard-sites_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">enterprise-edition-architecture</guid>
      <pubDate>Sat, 25 Aug 2018 16:05:00 GMT</pubDate>
      <title><![CDATA[Enterprise Edition architecture]]></title>
      <description><![CDATA[Burp Suite Enterprise Edition comprises the following components: Enterprise server – This coordinates between the other components, manages scan scheduling, and performs software updates. Agents – Th]]></description>
      <link>https://portswigger.net/blog/enterprise-edition-architecture</link>
      <media:thumbnail url="https://portswigger.net/cms/images/dc/72/3d1909705775-twittercard-enterprise-1_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-suite-enterprise-edition</guid>
      <pubDate>Fri, 24 Aug 2018 15:50:00 GMT</pubDate>
      <title><![CDATA[Burp Suite Enterprise Edition]]></title>
      <description><![CDATA[We're pleased to announce the forthcoming availability of Burp Suite Enterprise Edition. The key features of this new product are: Server installation, accessed via a modern web interface and REST API]]></description>
      <link>https://portswigger.net/blog/burp-suite-enterprise-edition</link>
      <media:thumbnail url="https://portswigger.net/cms/images/57/11/123177d1a536-twittercard-enterprise_logo_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">one-more-thing</guid>
      <pubDate>Thu, 23 Aug 2018 15:25:59 GMT</pubDate>
      <title><![CDATA[One more thing ...]]></title>
      <description><![CDATA[Wait a minute, this was supposed to be a month&nbsp;of Burp pr0n, right? There's still a week to go, and you've released Burp Suite 2.0 already. Quite right. We aren't done yet. Not by a long way. Tun]]></description>
      <link>https://portswigger.net/blog/one-more-thing</link>
      <media:thumbnail url="https://portswigger.net/cms/images/a0/c2/c9e7fe437987-twittercard-steve_jobs_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">burp-suite-2-0-beta-now-available</guid>
      <pubDate>Thu, 23 Aug 2018 13:36:32 GMT</pubDate>
      <title><![CDATA[Burp Suite 2.0 beta now available]]></title>
      <description><![CDATA[Burp Suite 2.0 beta is now available to Professional users. This is a major upgrade, with a host of new features, including: A new crawler, able to automatically handle sessions, detect changes in app]]></description>
      <link>https://portswigger.net/blog/burp-suite-2-0-beta-now-available</link>
      <media:thumbnail url="https://portswigger.net/cms/images/47/8c/af09df9ff651-twittercard-burp2_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">new-response-renderer</guid>
      <pubDate>Wed, 22 Aug 2018 15:39:00 GMT</pubDate>
      <title><![CDATA[New response renderer]]></title>
      <description><![CDATA[Burp's "Render" tab is getting a little makeover. See if you can spot the difference. Before ... After ...]]></description>
      <link>https://portswigger.net/blog/new-response-renderer</link>
      <media:thumbnail url="https://portswigger.net/cms/images/93/ca/f330169b8ed7-twittercard-new_renderer_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">goodbye-state-files-we-wont-miss-you</guid>
      <pubDate>Tue, 21 Aug 2018 15:41:00 GMT</pubDate>
      <title><![CDATA[Goodbye state files, we won't miss you]]></title>
      <description><![CDATA[It's over two years since we introduced Burp project files as the long-term replacement for state files.&nbsp; Project files are vastly superior to the old state files: Data is saved automatically, in]]></description>
      <link>https://portswigger.net/blog/goodbye-state-files-we-wont-miss-you</link>
      <media:thumbnail url="https://portswigger.net/cms/images/0a/cc/4e86d6f2d235-twittercard-burp-state-files-twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">burps-new-rest-api</guid>
      <pubDate>Mon, 20 Aug 2018 16:19:00 GMT</pubDate>
      <title><![CDATA[Burp's new REST API]]></title>
      <description><![CDATA[Burp is getting a brand new REST API, which can be used by other tools to integrate with Burp Suite: In the initial release, the REST API supports launching vulnerability scans and obtaining the resul]]></description>
      <link>https://portswigger.net/blog/burps-new-rest-api</link>
      <media:thumbnail url="https://portswigger.net/cms/images/b3/f6/05ecad8ab59d-twittercard-rest_api_documentation_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">live-scanning</guid>
      <pubDate>Sun, 19 Aug 2018 15:56:00 GMT</pubDate>
      <title><![CDATA[Live scanning]]></title>
      <description><![CDATA[For a very long time, Burp has had two cool capabilities that are of huge value to manual testers: Automatically scan requests that are made via the Proxy. Automatically add items to the site map as y]]></description>
      <link>https://portswigger.net/blog/live-scanning</link>
      <media:thumbnail url="https://portswigger.net/cms/images/59/f0/d5d50f3ef2fa-twittercard-live_task_config_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">the-new-dashboard</guid>
      <pubDate>Sat, 18 Aug 2018 15:42:00 GMT</pubDate>
      <title><![CDATA[The new dashboard]]></title>
      <description><![CDATA[Burp Suite is getting a brand new dashboard, which lets you monitor and control its automated activity: The dashboard shows the currently configured tasks, with a summary of their progress and results]]></description>
      <link>https://portswigger.net/blog/the-new-dashboard</link>
      <media:thumbnail url="https://portswigger.net/cms/images/ac/83/0aa6db7b4e06-twittercard-dashboard_-_full_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">launching-scans</guid>
      <pubDate>Fri, 17 Aug 2018 16:08:00 GMT</pubDate>
      <title><![CDATA[Launching scans]]></title>
      <description><![CDATA[In the past few days, we've been describing Burp's forthcoming support for multiple parallel scans, improved management of system resources, and the new configuration library. Today, we'll look at how]]></description>
      <link>https://portswigger.net/blog/launching-scans</link>
      <media:thumbnail url="https://portswigger.net/cms/images/b0/9c/b12d8ed95354-twittercard-scan_launcher_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">the-new-configuration-library</guid>
      <pubDate>Thu, 16 Aug 2018 15:35:00 GMT</pubDate>
      <title><![CDATA[The new configuration library]]></title>
      <description><![CDATA[Burp's current Spider and Scanner tools have their own configuration options which apply globally to all spidering and scanning activity. You can save these options in project configuration files, whi]]></description>
      <link>https://portswigger.net/blog/the-new-configuration-library</link>
      <media:thumbnail url="https://portswigger.net/cms/images/8a/d4/a7cfdd2de283-twittercard-configuration_library_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">improved-management-of-system-resources</guid>
      <pubDate>Wed, 15 Aug 2018 15:37:00 GMT</pubDate>
      <title><![CDATA[Improved management of system resources]]></title>
      <description><![CDATA[Here are a few problems that some users regularly run into when using Burp: It's easy to overload either the local machine, the network connection, or the application being tested, by kicking off too ]]></description>
      <link>https://portswigger.net/blog/improved-management-of-system-resources</link>
      <media:thumbnail url="https://portswigger.net/cms/images/8e/25/38c1d8192153-twittercard-task_execution_settings_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">top-10-web-hacking-techniques-of-2017-voting-open</guid>
      <pubDate>Wed, 15 Aug 2018 13:50:15 GMT</pubDate>
      <title><![CDATA[Top 10 Web Hacking Techniques of 2017 - Voting Open]]></title>
      <description><![CDATA[The nominations are in for the Top 10 Web Hacking Techniques of 2017, so it's time to start the community vote. We're inviting everyone to select their personal top 10, and the votes will be used to b]]></description>
      <link>https://portswigger.net/blog/top-10-web-hacking-techniques-of-2017-voting-open</link>
      <media:thumbnail url="https://portswigger.net/cms/images/ed/8f/9eac03e19a8e-twittercard-top10websectech2017.png" />
    </item>
    <item>
      <guid isPermaLink="false">multiple-parallel-scans</guid>
      <pubDate>Tue, 14 Aug 2018 15:57:00 GMT</pubDate>
      <title><![CDATA[Multiple parallel scans]]></title>
      <description><![CDATA[The current Spider and Scanner tools are pretty good at letting you do one thing at a time. They let you define your configuration and scope. They each employ a single queue of work. They can be pause]]></description>
      <link>https://portswigger.net/blog/multiple-parallel-scans</link>
      <media:thumbnail url="https://portswigger.net/cms/images/99/f6/c70b3b4415b5-twittercard-multiple_parallel_scans_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">dynamic-analysis-of-javascript</guid>
      <pubDate>Mon, 13 Aug 2018 15:47:00 GMT</pubDate>
      <title><![CDATA[Dynamic analysis of JavaScript]]></title>
      <description><![CDATA[Burp's current Scanner can report a wide range of DOM-based vulnerabilities using static analysis techniques. Static analysis of JavaScript involves parsing the code to construct an abstract syntax tr]]></description>
      <link>https://portswigger.net/blog/dynamic-analysis-of-javascript</link>
      <media:thumbnail url="https://portswigger.net/cms/images/cc/85/7b612da142ab-twittercard-dynamic_javascript_analysis_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">handling-application-errors-during-scans</guid>
      <pubDate>Sun, 12 Aug 2018 15:37:00 GMT</pubDate>
      <title><![CDATA[Handling application errors during scans]]></title>
      <description><![CDATA[How many times have you seen this? As we have already described, Burp's current Scanner processes each item in the scan queue in isolation. If it runs into connection errors and transmission timeouts,]]></description>
      <link>https://portswigger.net/blog/handling-application-errors-during-scans</link>
      <media:thumbnail url="https://portswigger.net/cms/images/8c/60/2ab95b161362-twittercard-handling_application_errors_during_audit_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">frequently-occurring-insertion-points</guid>
      <pubDate>Sat, 11 Aug 2018 15:53:00 GMT</pubDate>
      <title><![CDATA[Frequently occurring insertion points]]></title>
      <description><![CDATA[As we've already described, Burp's current Scanner audits each individual request in isolation, performing all of the configured checks, and reporting all of the resulting issues. This includes carryi]]></description>
      <link>https://portswigger.net/blog/frequently-occurring-insertion-points</link>
      <media:thumbnail url="https://portswigger.net/cms/images/2e/04/0771d4df2acf-twittercard-frequently_occurring_insertion_points_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">consolidation-of-site-wide-passive-issues</guid>
      <pubDate>Fri, 10 Aug 2018 16:13:00 GMT</pubDate>
      <title><![CDATA[Consolidation of site-wide passive issues]]></title>
      <description><![CDATA[How many times have you seen Burp reporting hundreds or thousands&nbsp;of instances of the same passive issue on the same web site? This happens because some passively-detected issues are liable to ex]]></description>
      <link>https://portswigger.net/blog/consolidation-of-site-wide-passive-issues</link>
      <media:thumbnail url="https://portswigger.net/cms/images/ff/5c/d7175a568dd0-twittercard-clickjacking_old_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">practical-web-cache-poisoning</guid>
      <pubDate>Thu, 09 Aug 2018 23:20:00 GMT</pubDate>
      <title><![CDATA[Practical Web Cache Poisoning]]></title>
      <description><![CDATA[Abstract Web cache poisoning has long been an elusive vulnerability, a 'theoretical' threat used mostly to scare developers into obediently patching issues that nobody could actually exploit. In this ]]></description>
      <link>https://portswigger.net/blog/practical-web-cache-poisoning</link>
      <media:thumbnail url="https://portswigger.net/cms/images/d0/43/5e5ed09ea718-twittercard-cache-poisoning-article.png" />
    </item>
    <item>
      <guid isPermaLink="false">improved-detection-of-stored-input</guid>
      <pubDate>Thu, 09 Aug 2018 16:29:00 GMT</pubDate>
      <title><![CDATA[Improved detection of stored input]]></title>
      <description><![CDATA[Burp Scanner is already capable of detecting when applications store input from one request and return it in the response to another request. When storage and retrieval of input is detected, Burp then]]></description>
      <link>https://portswigger.net/blog/improved-detection-of-stored-input</link>
      <media:thumbnail url="https://portswigger.net/cms/images/98/d1/7b6699d2192c-twittercard-stored_xss-twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">multi-phase-scanning</guid>
      <pubDate>Wed, 08 Aug 2018 16:14:00 GMT</pubDate>
      <title><![CDATA[Multi-phase scanning]]></title>
      <description><![CDATA[Burp's current Scanner maintains a queue of items that have been sent for auditing, and processes them in turn. Each item is processed in isolation, and its status moves from waiting, to in-progress, ]]></description>
      <link>https://portswigger.net/blog/multi-phase-scanning</link>
      <media:thumbnail url="https://portswigger.net/cms/images/4e/e3/5d835db9c75b-twittercard-audit_items_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">automatically-maintaining-session-during-scans</guid>
      <pubDate>Tue, 07 Aug 2018 16:18:00 GMT</pubDate>
      <title><![CDATA[Automatically maintaining session during scans]]></title>
      <description><![CDATA[Over the last few days, we've described how Burp's new crawler&nbsp;can deal with a wide variety of challenges presented by modern applications. But crawling applications is only part of the story. Th]]></description>
      <link>https://portswigger.net/blog/automatically-maintaining-session-during-scans</link>
      <media:thumbnail url="https://portswigger.net/cms/images/48/47/ceadff748413-twittercard-auditing-13_-_twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">crawling-volatile-content</guid>
      <pubDate>Mon, 06 Aug 2018 16:23:00 GMT</pubDate>
      <title><![CDATA[Crawling volatile content]]></title>
      <description><![CDATA[Modern web applications frequently contain volatile content, where the "same" location or function will return responses that differ substantially on different occasions, not (necessarily) as the resu]]></description>
      <link>https://portswigger.net/blog/crawling-volatile-content</link>
      <media:thumbnail url="https://portswigger.net/cms/images/d6/e0/79c967c148ce-twittercard-crawling-9-twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">crawling-with-multiple-logins</guid>
      <pubDate>Sun, 05 Aug 2018 15:43:00 GMT</pubDate>
      <title><![CDATA[Crawling with multiple logins]]></title>
      <description><![CDATA[Burp's current Spider tool has a primitive login capability, in that you can configure a username and password that will be submitted in any login forms. You can do a bit better with macros and sessio]]></description>
      <link>https://portswigger.net/blog/crawling-with-multiple-logins</link>
      <media:thumbnail url="https://portswigger.net/cms/images/a1/c4/76518f49e53d-twittercard-crawling-7-twitter.png" />
    </item>
    <item>
      <guid isPermaLink="false">detecting-changes-in-application-state</guid>
      <pubDate>Sat, 04 Aug 2018 15:34:00 GMT</pubDate>
      <title><![CDATA[Detecting changes in application state]]></title>
      <description><![CDATA[Modern web applications are heavily stateful, and it is common for the same application function to return different content and have different behavior on different occasions, as a result of actions ]]></description>
      <link>https://portswigger.net/blog/detecting-changes-in-application-state</link>
      <media:thumbnail url="https://portswigger.net/cms/images/63/c7/52f966ccb121-twittercard-crawling-6-twitter.png" />
    </item>
  </channel>
</rss>