I love how he is porting every local attack to web applications.
I am also a bit frightening that the number of attack you have to know for the Burp Certification keeps getting longer.