PortSwigger Opens Nominations for Top 10 Web Hacking Techniques of 2024
PortSwigger Research has officially opened nominations for the annual list of the top ten new web hacking techniques of 2024. This initiative, running since 2006, invites security researchers worldwide to submit innovative findings that demonstrate novel, practical, and reusable approaches to web security challenges. Unlike specific vulnerabilities that may age poorly, the focus is on underlying techniques adaptable across different systems, such as cache poisoning or parser exploitation. The selection process follows a structured timeline: community nominations are collected from January 8 to 14, followed by community voting to create a shortlist of fifteen candidates from January 15 to 21. A panel will then finalize the top ten rankings, with the official list scheduled for publication on February 4, 2025. James Kettle, Director of Research at PortSwigger, emphasized the importance of recognizing research that pushes the boundaries of web security. Examples of current nominations include techniques exploiting HTTP/2 timing attacks, web cache deception, and vulnerabilities in Apache HTTP Server. Participants can submit URLs to their research via the dedicated portal, helping the community identify the most influential security breakthroughs of the past year.
Wire timeline
PortSwigger Opens Nominations for Top 10 Web Hacking Techniques of 2024
PortSwigger Research has officially opened nominations for the annual list of the top ten new web hacking techniques of 2024. This initiative, running since 2006, invites security researchers worldwide to submit innovative findings that demonstrate novel, practical, and reusable approaches to web security challenges. Unlike specific vulnerabilities that may age poorly, the focus is on underlying techniques adaptable across different systems, such as cache poisoning or parser exploitation. The selection process follows a structured timeline: community nominations are collected from January 8 to 14, followed by community voting to create a shortlist of fifteen candidates from January 15 to 21. A panel will then finalize the top ten rankings, with the official list scheduled for publication on February 4, 2025. James Kettle, Director of Research at PortSwigger, emphasized the importance of recognizing research that pushes the boundaries of web security. Examples of current nominations include techniques exploiting HTTP/2 timing attacks, web cache deception, and vulnerabilities in Apache HTTP Server. Participants can submit URLs to their research via the dedicated portal, helping the community identify the most influential security breakthroughs of the past year.
PortSwigger Research