Critical Thinking - Bug Bounty Podcast cover image

Episode 60: Our Take on PortSwigger's Top 10 Web Hacking Techniques of 2023

Critical Thinking - Bug Bounty Podcast

00:00

Exploring Top Web Hacking Techniques of 2023

The chapter delves into the top 10 web hacking techniques of 2023, highlighting the development of race conditioning testing by James Kettle and the exploitation of Nagel's algorithm combined with HTTP2 for optimizing TCP packets. It discusses a significant bug in HTTP request smuggling into Akamai servers, leading to global cache poisoning and NTLM token theft, resulting in full arbitrary redirects. The speakers also explore SMTP smuggling, its connection to HTTP smuggling, and the methodology applied to different protocols with similar functionalities.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app