Top 10 web hacking techniques of 2020 - nominations open
2021-01-05 23:01:31 Author: portswigger.net(查看原文) 阅读量:284 收藏

James Kettle

  • Published: 05 January 2021 at 14:01 UTC

  • Updated: 05 January 2021 at 14:11 UTC

Nominations are now open for the top 10 new web hacking techniques of 2020!

2020 was not an ideal year for many of us, but that didn't stop the security community from sharing a broad array of novel research ranging from creative iterations on existing work to entire new attack concepts. Keeping up with this flood of posts can be exhausting in the best of times, so every year we collaborate with the community to first identify all the key research releases, then whittle the list down to the top ten must-see new techniques. Take a look at last year's top 10 to see what this looks like. For researchers, the nomination list is also a valuable asset - check out 2019's superb nomination list.

We'll follow the same battle-tested process as usual:

  • Jan 05: Start to collect community nominations
  • Jan 18: Launch community vote to build shortlist of top 15
  • Feb 01: Launch panel vote on shortlist to select and order the 10 finalists
  • Feb 15: Publish top 10 of 2020!

Everyone is welcome to nominate a piece of research, just use the nomination form.

Feel free to nominate your own research if you think it's worthy. We know too well that some quality work gets overlooked just because it isn't social-media optimized.

We love to see all kinds of security knowledge being shared but we're aiming to list only posts that contain a novel technique, idea or concept that can be reapplied elsewhere. As such, just like last year I will enforce a minimum quality bar to prevent the nomination list from being flooded with posts that merely show the application a technique that's already been publicly documented. If you're looking for techniques that have been around a while but won't go away, check out the OWASP Top Ten.

If you're interested in hearing about novel techniques the moment they come out, you can follow @PortSwiggerRes on Twitter, or subscribe to r/websecurityresearch. I've used these sources to make a few nominations to get things started. This list will get updated regularly during the nomination phase.

Finally, here's the complete list of past year's top 10s:

2019, 2018, 2017, 2015, 2014, 2013, 2012, 2011, 2010, 2009, 2008, 20072006.

Nominations so far:

Back to all articles


文章来源: https://portswigger.net/research/top-10-web-hacking-techniques-of-2020-nominations-open
如有侵权请联系:admin#unsafe.sh