BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Can AI do novel security research? Meet the HTTP Ter
 minator\n   Tags: DEF CON Official Talk | Tool ðŸ›  | Exploit ðŸª²\n   Whe
 n: Friday\, Aug 7\, 12:00 - 12:59 PDT\n   Where: LVCCW Level 1 Hall 3 906 
 (Main Track 3) and DCTV-3 - [1]Map\n\n   Description:\n\n   We all know AI
  can find bugs. After a decade of research\, I asked a\n   harder question
 : can an autonomous system invent new attack\n   techniques\, and use them
  to hack live websites at scale? Building this\n   sounded like a bad idea
 \, so I did it.\n\n   It worked - I'll share an arsenal of new HTTP desync
  triggers\,\n   gadgets\, and exploits that compromised banks\, security s
 olutions\, and\n   government infrastructure. Then I'll trace each discove
 ry chain back\n   through the HTTP Terminator\, showing how to turn your p
 ersonal\n   expertise into an autonomous weapon - and the dark arts requir
 ed to\n   make it lethal.\n\n   I'll also share discoveries from beyond th
 e autonomy horizon - some\n   only reachable with a tight human/AI researc
 h loop\, and others beyond\n   AI's reach entirely. These include a powerf
 ul undisclosed recon\n   technique\, and anomalies that hint at new attack
  classes offering\n   alternative paths to critical impact. I'll analyse t
 he discovery\n   process\, sharing detailed experiments that probe the bou
 ndaries of\n   what AI can and can't discover.\n\n   You'll leave with new
  exploits from desync triggers to undisclosed\n   attack classes\, and a b
 lueprint for turning your instincts into an\n   autonomous research cascad
 e. And yes\, I'll open-source the HTTP\n   Terminator.\n\n   https://ports
 wigger.net/research/http1-must-die\n   https://i.blackhat.com/BH-USA-25/Pr
 esentations/US-25-Dolan-Gavitt-AI-Agents-for-Offsec-with-Zero-False-Positi
 ves-Thursday.pdf\n   https://portswigger.net/research/listen-to-the-whispe
 rs-web-timing-attacks-that-actually-work\n   https://www.intruder.io/resea
 rch/practical-http-header-smuggling\n\n   SpeakerBio:  James "albinowax" K
 ettle\, PortSwigger\n\n   James 'albinowax' Kettle is the Director of Rese
 arch at PortSwigger\,\n   the makers of Burp Suite. He's best known for pi
 oneering novel web\n   attack techniques\, and publishing them at major co
 nferences like Black\n   Hat USA\, at which he's presented for nine consec
 utive years.\n\n   He also loves exploring and advising on innovative tool
  concepts for\n   security professionals\, many of which have since become
  industry\n   standard. Examples include introducing OAST via Burp Collabo
 rator\,\n   bulk parameter discovery via Param Miner\, billion-request att
 acks with\n   Turbo Intruder\, and human-style scanning with Backslash Pow
 ered\n   Scanner.\n\n   His best-known research is HTTP Desync Attacks\, w
 hich popularised HTTP\n   Request Smuggling. Other popular attack techniqu
 es that can be traced\n   back to his research include web cache poisoning
 \, the single-packet\n   attack\, server-side template injection\, and pas
 sword reset poisoning.\n   He's also the designer behind many of the topic
 s and labs that make up\n   the Web Security Academy\, and serves on the B
 lack Hat Europe review\n   board.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n
 \n
DTEND:20260807T195900Z
DTSTART:20260807T190000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Can AI do novel security research? Meet the HTTP Terminator
END:VEVENT
END:VCALENDAR
