The State of Application Security 2023 • Sebastian Brandes • GOTO 2023
This presentation was recorded at GOTO Copenhagen 2023. #GOTOcon #GOTOcph
Sebastian Brandes - Co-founder of HeyHack
ORIGINAL TALK TITLE
The State of Application Security 2023: Learnings from 4 Million Scanned Services
Unveiling the Power of Proactive Cybersecurity Investments
RESOURCES
ABSTRACT
The digital security environment is always evolving, with fresh vulnerabilities surfacing, outdated software being phased out, and shifting security guidelines. Heyhack has conducted extensive global scans, assessing countless vulnerabilities. This discussion presents key vulnerabilities and delves into the actual data Heyhack has gathered worldwide. The aim is to heighten awareness and offer concrete examples of the most prevalent cyber risks today.
The foundation for this discussion is grounded in Heyhack’s comprehensive study on 4 million public-facing web services across the globe. This extensive research not only highlights the scale of their investigation but also underscores the significance of the vulnerabilities they’ve uncovered. This vast dataset offers a detailed snapshot of the current online security landscape, and it serves as a pivotal reference throughout the talk. [...]
TIMECODES
00:00 Intro
02:48 Agenda
05:04 2011 study
06:10 Results from Heyhack’s global AppSec study 2023
11:18 2023 study overview
11:43 File leaks
13:44 Dangling DNS records
15:09 Dangling Records demo
17:13 Dangling DNS records continued
18:42 Vulnerable FTP servers
19:40 ProFTP demo
21:27 Cross-site scripting
22:30 Cross-site scripting demo
31:02 Case study: Fortnite
36:08 WAF: Web Application Firewalls
40:09 Learnings
40:49 Proactive investments
42:01 Takeaways
44:28 Outro
Download slides and read the full abstract here:
RECOMMENDED BOOKS
Liz Rice • Container Security •
Liz Rice • Kubernetes Security •
Aaron Parecki • OAuth 2.0 Simplified •
Aaron Parecki • OAuth 2.0 Servers •
Aaron Parecki • The Little Book of OAuth 2.0 RFCs •
Erdal Ozkaya • Cybersecurity: The Beginner’s Guide •
#ApplicationSecurity #Cybersecurity #Security #OWASP #GlobalAppSecStudy #AppSec #Heyhack #CrosssiteScripting #ProFTP #FileLeaks #CVEExploits #BrowserExploitationFramework #FortniteHacked #WAF #WebApplicationFirewall #SebastianBrandes
Looking for a unique learning experience?
Attend the next GOTO conference near you! Get your ticket at
Sign up for updates and specials at
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
1 view
0
0
5 years ago 00:21:38 14
The State of Overwatch
5 years ago 00:07:40 34
The Current State of Tarkov 2
4 years ago 00:08:22 41
The Husbando State | Genshin
6 years ago 00:03:01 196
THE EMPIRE STATE LOOK | NYXL
3 years ago 00:37:41 319
The State of Unreal 2022 | Unreal Engine
1 year ago 00:35:35 13
Cyrodiil Developer Diary - The State of Cyrodiil
6 years ago 00:10:40 87
The State of the Fortress
5 years ago 00:23:34 114
The Last of Us Part II - State of Play | PS4
5 years ago 00:02:00 139
UnityStation: The Current State
3 years ago 00:09:00 27
What is Next for Gordon Freeman - The State of Half-Life
3 years ago 00:04:34 24
Inside the Enigmatic State of Mind : The Rundown - Enigma State 🙌
13 years ago 00:03:09 313
James “the one armed bandit“ Spurgin - SPF Ohio State Meet 2012
6 years ago 00:05:54 463
Jeff Kaplan: Ashe changes and the state of Blizzard
1 year ago 00:16:10 9
The State of the World
3 years ago 00:02:03 646
The Callisto Protocol - State of Play June 2022 Trailer | PS5 & PS4 Games
9 years ago 00:02:32 182
R5 - The State of R5
13 years ago 00:03:37 544
A$AP Rocky x Jeremy Scott : The State Of The Art
7 years ago 00:03:28 65
The Luminary - Flow State
2 years ago 00:50:11 1
The State Of The Siege Community
4 years ago 00:01:22 19
THE STATE
3 years ago 00:05:34 402
The State of Splinter Cell
10 years ago 00:03:43 32
The Luka State - Rain
3 years ago 00:02:17 156
The DioField Chronicle - State of Play March 2022 Teaser Movie | PS5, PS4