The State of Application Security 2023 • Sebastian Brandes • GOTO 2023
This presentation was recorded at GOTO Copenhagen 2023. #GOTOcon #GOTOcph
Sebastian Brandes - Co-founder of HeyHack
ORIGINAL TALK TITLE
The State of Application Security 2023: Learnings from 4 Million Scanned Services
Unveiling the Power of Proactive Cybersecurity Investments
RESOURCES
ABSTRACT
The digital security environment is always evolving, with fresh vulnerabilities surfacing, outdated software being phased out, and shifting security guidelines. Heyhack has conducted extensive global scans, assessing countless vulnerabilities. This discussion presents key vulnerabilities and delves into the actual data Heyhack has gathered worldwide. The aim is to heighten awareness and offer concrete examples of the most prevalent cyber risks today.
The foundation for this discussion is grounded in Heyhack’s comprehensive study on 4 million public-facing web services across the globe. This extensive research not only highlights the scale of their investigation but also underscores the significance of the vulnerabilities they’ve uncovered. This vast dataset offers a detailed snapshot of the current online security landscape, and it serves as a pivotal reference throughout the talk. [...]
TIMECODES
00:00 Intro
02:48 Agenda
05:04 2011 study
06:10 Results from Heyhack’s global AppSec study 2023
11:18 2023 study overview
11:43 File leaks
13:44 Dangling DNS records
15:09 Dangling Records demo
17:13 Dangling DNS records continued
18:42 Vulnerable FTP servers
19:40 ProFTP demo
21:27 Cross-site scripting
22:30 Cross-site scripting demo
31:02 Case study: Fortnite
36:08 WAF: Web Application Firewalls
40:09 Learnings
40:49 Proactive investments
42:01 Takeaways
44:28 Outro
Download slides and read the full abstract here:
RECOMMENDED BOOKS
Liz Rice • Container Security •
Liz Rice • Kubernetes Security •
Aaron Parecki • OAuth 2.0 Simplified •
Aaron Parecki • OAuth 2.0 Servers •
Aaron Parecki • The Little Book of OAuth 2.0 RFCs •
Erdal Ozkaya • Cybersecurity: The Beginner’s Guide •
#ApplicationSecurity #Cybersecurity #Security #OWASP #GlobalAppSecStudy #AppSec #Heyhack #CrosssiteScripting #ProFTP #FileLeaks #CVEExploits #BrowserExploitationFramework #FortniteHacked #WAF #WebApplicationFirewall #SebastianBrandes
Looking for a unique learning experience?
Attend the next GOTO conference near you! Get your ticket at
Sign up for updates and specials at
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
1 view
0
0
7 months ago 00:03:49 1
Елизавета Шубина. И.Шварц, Прогулка по городу. Из к/ф “Мелодии белой ночи“
7 months ago 00:01:49 1
Bird flu pandemic could be ‘100 times worse’ than COVID, scientists warn
7 months ago 01:05:41 1
After Life São Paulo 2024 (FULL SET) MIX - OPEN AIR - TALE OF US, ANYMA, MRAK & CASSIAN | PREMIERE
7 months ago 00:46:49 1
Ohio State defense, Georgia receivers & more spring game takeaways 👏 | Always College Football
7 months ago 00:06:13 1
The SHOCKING TRUTH: That’s Why Russia Officially Backed IRAN’s Harsh Actions Against ISRAEL
7 months ago 04:00:45 1
300💙 И ВЫБИВАЮ DUCATI В PUBG ▪ Заказ клипа в описании ▪ пубг пабг стрим
7 months ago 05:37:40 1
🔴 ТУРНИР НА 100К СКОРО В PUBG ▪ Заказ клипа в описании ▪ пубг пабг стрим
7 months ago 00:03:56 1
I take issue with those who think the US presidency only became a clown show for war criminals with Joe Biden
7 months ago 00:03:57 1
Nobody
7 months ago 00:10:52 1
Hellblade 2 Preview Reaction: The New State Of The Art For Unreal Engine 5?
7 months ago 00:05:09 1
METALLICA - ENTER SANDMAN 2021 - DRUM COVER BY MEYTAL COHEN
7 months ago 00:26:53 1
The 2009 US Policy Paper that Laid out Future Israel-Iran War
7 months ago 00:11:14 1
7 Foods I’ll NEVER Eat! (Based on Science)
7 months ago 01:03:00 1
Marina Jacobi - The Solar Eclipse-April 8th 2024 / - Ions - S7 E13
7 months ago 00:10:53 1
Zelensky tells CNN the US needs to send aid to avoid Putin from starting WWIII
7 months ago 02:28:38 1
Driving Southern California San Diego Coast in 8K Dolby Vision HDR - Oceanside to Coronado
7 months ago 08:14:31 1
Palword full walkthrough gameplay from Xbox part 68
7 months ago 00:02:26 1
2004 Chevrolet Corvette 324 TUL Gateway Classic Cars of Tulsa
7 months ago 00:02:16 1
«За день до войны» 21 июня 1941 / “The day before the war“ June 21, 1941
7 months ago 00:01:53 1
US daredevil Wallenda crosses Grand Canyon on tightrope
7 months ago 00:01:28 1
Prosecutors demand JSC Makfa be handed over to the state
7 months ago 00:02:10 1
A 14450 Flute Demo
7 months ago 00:04:23 1
FEUERSCHWANZ - Valhalla Calling (Official Video) - Cover of @miracleofsound | Napalm Records
7 months ago 00:00:31 1
WWS Group Celebrates its 25th Anniversary at the 135th Canton Fair Opening Ceremony