TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

PortSwigger Research

A hacking hat-trick: previewing three PortSwigger Research publications coming to DEF CON & Black Hat USA

2024-07-02 · Read original ↗

ATT&CK techniques detected

3 predictions
T1588.006Vulnerabilities
56%
"a hacking hat - trick : previewing three portswigger research publications coming to def con & amp ; black hat usa research academy my account customers about blog careers legal contact resellers attack surface visibility improve security posture, prioritize manual testing, free …"
T1566.002Spearphishing Link
49%
"methodology refined through testing countless concepts on thousands of websites. we ' ve neglected this omnipresent and incredibly powerful side - channel for too long. suggested pre - reading : timeless timing attacks smashing the state machine author : gareth heyes black hat : …"
T1190Exploit Public-Facing Application
37%
"illustrate this with a case study showing how such a breach can be replicated in environments like nginx behind cloudflare and apache behind cloudfront, using just their default configurations. next, i ' ll present cache key confusion, and show how to exploit url parsing inconsis…"

Summary

We're delighted to announce three major research releases from PortSwigger Research will be published at both Black Hat USA and DEF CON 32. In this post, we'll offer a quick teaser of each talk, info