RSnake

Robert Hansen, Austin, Texas

Finding what
everyone else
missed.

It started with Fierce, Slowloris, Clickjacking, XSS Cheat Sheet, and Content Security Policy. Thirty one years on, it's become a venture portfolio, a vulnerability platform willing to put millions behind its findings, and a weekly intelligence report for people who need the signal amongst the noise.

Scroll
SlowlorisAuthor
ClickjackingCo-discovered
Content Security PolicyContributor
FierceAuthor
ha.ckers.orgFounder

The record

More than thirty years,
abbreviated.

Techniques, tools, disclosures and companies that make up RSnake's complicated and storied career.

1996
EHAPCo-founded Ethical Hackers Against Pedophilia, which successfully identified online predators.
1996
WebFringe.comA self healing top 100 list, built because webrings broke as soon as enough sites went offline.
2001
Hardening .htaccessFirst Black Hat Briefings talk, on identifying and thwarting automated brute force attacks.
2001
PeekabootyArchitecture work with Bronc Buster on censorship evasion software, a precursor to Tor.
2004
Intranet port hackingResearched with Jeremiah Grossman. The browser's access to the internal network becomes the conduit to attack.
2005
Content Security PolicyInvented at eBay to defeat stored and reflected cross site scripting. Now in every browser.
2005
ha.ckers.org / sla.ckers.orgA web application security lab and the forum that grew around it. 1,000 posts before it closed.
2006
SecTheoryFounded with James Flom. Consultancy, research lab, and the home of many research papers.
2007
XSS cheat sheetThe filter evasion reference, built to show why blacklisting cross site scripting does not work.
2007
Death by 1000 CuttsGoogle Desktop exploit, CVE-2007-3150, and a paper on chaining small issues against one person.
2008
ClickjackingResearched with Jeremiah Grossman. Disclosure delayed at Adobe's request. CVE-2008-4503, CWE-1021.
2008
Xploiting Google GadgetsDEF CON, with Tom Stracener. Malicious gadgets to phish users and leak data.
2009
SlowlorisPartial HTTP requests held in parallel lead to three CVEs. Used during the Iranian Green Revolution protests.
2009
FierceDNS enumeration by brute force, to find the assets a target does not know it has.
2009
DNS rebindingResearch on turning a browser into a route onto the network behind it.
2009
RFC1918 cache poisoningEveryone shares the same private ranges. Poison a cache on one network, wait, collect data on another.
2010
HTTPS Can Byte MeBlack Hat, with Josh Sokol. Two dozen seperate side channel attacks against HTTPS.
2010
Falling Rock NetworksWith James Flom. Productized the ha.ckers.org stack on BSD chroot jails. Patented.
2012
StratforIncident response work after the Anonymous breach.
2015
Magic hashesPHP's == sometimes casts a hash beginning "0e" plus digits to float zero, so unrelated hashes compare equal.
2017
Bit DiscoveryCo-founded the attack surface management platform acquired by Tenable, where he became Deputy CTO.
2019
Detecting MaliceA book on fraud and abuse. How to read a request and know who is behind it.
2024
AI's Best FriendOn what happens to people, work and truth when the machine gets good enough to be believed.
2025
Grossman VenturesManaging Partner. Finding the best early-stage companies focused on loss prevention and bringing them to market.
2025
Root EvidenceCTO. A vulnerability platform willing to put money behind its findings.
2026
The End of GuessingWith Jeremiah Grossman. Against an industry that scores risk without ever proving it.

The RSnake Report

Weekly, high quality OSINT geopolitical newsletter.

Geopolitics, technology, cybersecurity and business, assembled from primary sources, annotated, and sent every week. Highly acclaimed by the people who read it.

Browse past issues
A recent issue of the RSnake Report

Free, weekly

Get the Report.

One email a week. Stay up to date, and learn how RSnake sees the threat landscape.

The RSnake Show (now offline)

Look up old episodes here. Long, unhurried interviews about technology, security, power and where the internet is actually heading.