

Episode 7: PortSwigger Top 10, TruffleSecurity Drama, and More!
Feb 16, 2023
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
Introduction
00:00 • 2min
The Top 10 Web Hacking Techniques of 2022
01:41 • 2min
How to Avoid Using Externally Hosted Tools
03:21 • 3min
Trump Security's Anti-Security Policy
06:36 • 2min
Fuff 2.0: A New Threat Model
08:25 • 3min
Fuff, Fuff V2
11:02 • 2min
Port Twigger Top 10 Web Hacking Techniques
12:51 • 2min
The Worst Feeling When File Descriptor Is Being Quiet
15:18 • 3min
The Importance of Open Redirects
18:33 • 2min
How to Get Arbitrary Universal XSS on Netlify IPX
20:21 • 2min
The Risks of Same Site Strict Adoption
22:39 • 2min
Chaining Bugs Together, Open Redirects, and CSS Injection
24:44 • 2min
How to Save a Bug
26:58 • 2min
ECDSA Signature Verification in Java
28:59 • 2min
The Perfect Storm of Bad Things
30:43 • 3min
The Zero Signature Migration
33:26 • 2min
How to Encrypt JWTs With Default Keys
35:44 • 2min
The Amazing Concept of Hop by Hop Headers
37:14 • 3min
The Role of HCP Headers in HTTP
40:18 • 3min
The Flow of HTTP Requests
43:39 • 2min
How to Exploit an HTTP Request
45:16 • 4min
Franz's Post Message Tracker Extension
49:04 • 2min
Franz Rosenbug's Post Message Tracker Extension
50:46 • 3min
How to Fix an Akamai Ban
53:22 • 3min