PortSwigger Opens Nominations for Top 10 Web Hacking Techniques of 2023
PortSwigger Research, led by Director James Kettle, has opened nominations for the annual Top 10 Web Hacking Techniques of 2023. This community-driven initiative aims to highlight novel, practical security research that can be reapplied across different systems, distinguishing enduring techniques from transient vulnerabilities. The process involves a timeline where community nominations are collected from January 9 to 21, followed by a community vote to shortlist the top 15 entries between January 23 and 30. An expert panel will then select the final ten, with results announced on February 15. The article emphasizes the importance of identifying underlying methods, such as JNDI Injection or race condition exploits, rather than isolated bugs. Several example nominations are listed, including attacks involving Ruby on Rails, mutual TLS vulnerabilities, web race conditions, CORS misconfigurations, and LDAP truncation. The goal is to create a refined resource for security professionals, ensuring innovative discoveries are not overlooked amidst the high volume of annual security reports. Participants are encouraged to submit URLs to their research, with PortSwigger filtering for web-focused, innovative content to maintain quality in the voting stage.
Wire timeline
PortSwigger Opens Nominations for Top 10 Web Hacking Techniques of 2023
PortSwigger Research, led by Director James Kettle, has opened nominations for the annual Top 10 Web Hacking Techniques of 2023. This community-driven initiative aims to highlight novel, practical security research that can be reapplied across different systems, distinguishing enduring techniques from transient vulnerabilities. The process involves a timeline where community nominations are collected from January 9 to 21, followed by a community vote to shortlist the top 15 entries between January 23 and 30. An expert panel will then select the final ten, with results announced on February 15. The article emphasizes the importance of identifying underlying methods, such as JNDI Injection or race condition exploits, rather than isolated bugs. Several example nominations are listed, including attacks involving Ruby on Rails, mutual TLS vulnerabilities, web race conditions, CORS misconfigurations, and LDAP truncation. The goal is to create a refined resource for security professionals, ensuring innovative discoveries are not overlooked amidst the high volume of annual security reports. Participants are encouraged to submit URLs to their research, with PortSwigger filtering for web-focused, innovative content to maintain quality in the voting stage.
PortSwigger Research