Smashing the state machine: the true potential of web race conditions

For too long, web race-condition attacks have focused on a tiny handful of scenarios. Their true potential has been masked thanks to tricky workflows, missing tooling, and simple network jitter hiding all but the most trivial, obvious examples.

PortSwigger Research's James Kettle will uncover multiple new classes of race condition, that go far beyond limit-overrun exploits. Watch the presentation at Black Hat USA, or DEF CON 31, to uncover the true potential of race conditions. The presentation and whitepaper will be published on PortSwigger Research at 18:00 UTC on August 9.

Web Security Academy

Register for free to access learning materials and interactive challenges designed by our leading researchers.

Documentation and support

Learn about Burp Suite's powerful range of tools with our interactive guides, videos, and documentation.

Join the community

Follow us on Twitter for our latest research, product information, and to learn from other Burp Suite users.