PortSwigger Releases Top 10 Web Hacking Techniques of 2023
PortSwigger Research has published the 17th edition of its annual list identifying the most innovative web security research from 2023. Selected by an expert panel and community votes from a record 68 nominations, the top ten techniques highlight critical vulnerabilities in modern web infrastructure. Key entries include attacks on root EPP servers to control domain zones, methods for breaking web session integrity via CSRF token fixation, and persistent HTTP Desync Attacks affecting major vendors like Akamai and F5. The list also features a detailed breakdown of a $150,000 exploit chain against Microsoft Teams, creative exploitation of HTTP Request Splitting in nginx, and techniques for exploiting HTTP parser inconsistencies to bypass security controls. Additionally, it covers advanced PHP filter chain exploits for file reading. This compilation serves as an essential resource for security researchers and developers, offering deep insights into emerging attack vectors, protection bypasses, and the fragility of critical internet systems. The report emphasizes the importance of understanding these complex techniques to better defend against sophisticated cyber threats in the evolving digital landscape.
Wire timeline
PortSwigger Releases Top 10 Web Hacking Techniques of 2023
PortSwigger Research has published the 17th edition of its annual list identifying the most innovative web security research from 2023. Selected by an expert panel and community votes from a record 68 nominations, the top ten techniques highlight critical vulnerabilities in modern web infrastructure. Key entries include attacks on root EPP servers to control domain zones, methods for breaking web session integrity via CSRF token fixation, and persistent HTTP Desync Attacks affecting major vendors like Akamai and F5. The list also features a detailed breakdown of a $150,000 exploit chain against Microsoft Teams, creative exploitation of HTTP Request Splitting in nginx, and techniques for exploiting HTTP parser inconsistencies to bypass security controls. Additionally, it covers advanced PHP filter chain exploits for file reading. This compilation serves as an essential resource for security researchers and developers, offering deep insights into emerging attack vectors, protection bypasses, and the fragility of critical internet systems. The report emphasizes the importance of understanding these complex techniques to better defend against sophisticated cyber threats in the evolving digital landscape.
PortSwigger Research