PortSwigger Releases Top 10 Web Hacking Techniques of 2024
PortSwigger Research has published the 18th edition of its annual 'Top 10 Web Hacking Techniques of 2024,' highlighting the most innovative web security research from the past year. The list was curated through a community-powered process involving nominations, public voting, and final selection by an expert panel including Nicolas Grégoire and Soroush Dalili. This year saw a record 121 nominations, nearly double the previous year. The top techniques focus heavily on advanced exploitation methods, with OAuth manipulation and Web Cache Deception featuring prominently. Notable entries include 'Hijacking OAuth flows via Cookie Tossing' at number ten, 'ChatGPT Account Takeover - Wildcard Web Cache Deception' at nine, and 'CVE-2024-4367 - Arbitrary JavaScript execution in PDF.js' at seven. The report emphasizes creative attack chains, such as exploiting inconsistent decoding in cache rules and manipulating Referer headers for account takeovers. PortSwigger excluded its own research from the final ranking to maintain impartiality, though it highlighted three internal findings separately. This publication serves as a critical resource for security professionals to understand emerging threats and innovative vulnerability exploitation strategies in modern web applications.
Wire timeline
PortSwigger Releases Top 10 Web Hacking Techniques of 2024
PortSwigger Research has published the 18th edition of its annual 'Top 10 Web Hacking Techniques of 2024,' highlighting the most innovative web security research from the past year. The list was curated through a community-powered process involving nominations, public voting, and final selection by an expert panel including Nicolas Grégoire and Soroush Dalili. This year saw a record 121 nominations, nearly double the previous year. The top techniques focus heavily on advanced exploitation methods, with OAuth manipulation and Web Cache Deception featuring prominently. Notable entries include 'Hijacking OAuth flows via Cookie Tossing' at number ten, 'ChatGPT Account Takeover - Wildcard Web Cache Deception' at nine, and 'CVE-2024-4367 - Arbitrary JavaScript execution in PDF.js' at seven. The report emphasizes creative attack chains, such as exploiting inconsistent decoding in cache rules and manipulating Referer headers for account takeovers. PortSwigger excluded its own research from the final ranking to maintain impartiality, though it highlighted three internal findings separately. This publication serves as a critical resource for security professionals to understand emerging threats and innovative vulnerability exploitation strategies in modern web applications.
PortSwigger Research