The State of Application Security 2023 • Sebastian Brandes • GOTO 2023
This presentation was recorded at GOTO Copenhagen 2023. #GOTOcon #GOTOcph
Sebastian Brandes - Co-founder of HeyHack
ORIGINAL TALK TITLE
The State of Application Security 2023: Learnings from 4 Million Scanned Services
Unveiling the Power of Proactive Cybersecurity Investments
RESOURCES
ABSTRACT
The digital security environment is always evolving, with fresh vulnerabilities surfacing, outdated software being phased out, and shifting security guidelines. Heyhack has conducted extensive global scans, assessing countless vulnerabilities. This discussion presents key vulnerabilities and delves into the actual data Heyhack has gathered worldwide. The aim is to heighten awareness and offer concrete examples of the most prevalent cyber risks today.
The foundation for this discussion is grounded in Heyhack’s comprehensive study on 4 million public-facing web services across the globe. This extensive research not only highlights the scale of their investigation but also underscores the significance of the vulnerabilities they’ve uncovered. This vast dataset offers a detailed snapshot of the current online security landscape, and it serves as a pivotal reference throughout the talk. [...]
TIMECODES
00:00 Intro
02:48 Agenda
05:04 2011 study
06:10 Results from Heyhack’s global AppSec study 2023
11:18 2023 study overview
11:43 File leaks
13:44 Dangling DNS records
15:09 Dangling Records demo
17:13 Dangling DNS records continued
18:42 Vulnerable FTP servers
19:40 ProFTP demo
21:27 Cross-site scripting
22:30 Cross-site scripting demo
31:02 Case study: Fortnite
36:08 WAF: Web Application Firewalls
40:09 Learnings
40:49 Proactive investments
42:01 Takeaways
44:28 Outro
Download slides and read the full abstract here:
RECOMMENDED BOOKS
Liz Rice • Container Security •
Liz Rice • Kubernetes Security •
Aaron Parecki • OAuth 2.0 Simplified •
Aaron Parecki • OAuth 2.0 Servers •
Aaron Parecki • The Little Book of OAuth 2.0 RFCs •
Erdal Ozkaya • Cybersecurity: The Beginner’s Guide •
#ApplicationSecurity #Cybersecurity #Security #OWASP #GlobalAppSecStudy #AppSec #Heyhack #CrosssiteScripting #ProFTP #FileLeaks #CVEExploits #BrowserExploitationFramework #FortniteHacked #WAF #WebApplicationFirewall #SebastianBrandes
Looking for a unique learning experience?
Attend the next GOTO conference near you! Get your ticket at
Sign up for updates and specials at
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
1 view
0
0
1 month ago 00:03:53 354
US Agency For International Development EXPOSED | Prophet Uebert Angel
1 month ago 00:54:00 74
Прохождение испытаний на время: JUNK ENERGY и RC BANDITO в GTA Online
2 months ago 00:03:41 2
MIND-BLOWING Oompa Loompa Trump Remix You Need to See!
2 months ago 00:01:32 2
President Elon Musk’s Inauguration
2 months ago 00:03:39 2
Should Billionaires Be Fed To The Sharks?
2 months ago 00:55:35 4
Вагинокоммунизм (фильм, 2025) | рус, eng
2 months ago 00:01:38 1
Ohio State In My Veins Jesus In My Heart T Shirt
2 months ago 00:00:00 1
Самые яркие из нас 13 серия (русская озвучка) дорама The Brightest of Us, 最灿烂的我们
2 months ago 00:38:06 1
French & Brits Is No Alternative To U.S. Nuclear Umbrella | Nato Chief Deciphers New World Order
2 months ago 00:01:01 1
Turkish Protests Erupt Following Detention of Istanbul Mayor Ekrem İmamoğlu
2 months ago 00:03:52 1
Why is a Child Called Bhagwan Ka Roop? Science & Spirituality Explained!
2 months ago 00:03:20 2
DBL x - Love Is Gonna Save Us | Electro House Anthem
2 months ago 00:04:41 1
President Trump talks with reporters at The White House before boarding Marine One (March 21, 2025)
2 months ago 00:02:24 4
Электрический штат — Русский трейлер (Дубляж, 2025)
2 months ago 00:01:38 1
Nine Times National Champions 2024 Ohio State Buckeyes NCAA mascot T-Shirt
2 months ago 00:08:04 1
‘Nail in the coffin for rural America’: Tester breaks down the devastating impact of Trump cuts
2 months ago 01:12:55 9
THANK YOU SHRI MATAJI | GRATITUDE WEEK |GLOBAL MORNING MEDITATION
2 months ago 00:00:40 1
fosoto New Design Half Moon Lamp for Beauty Salon,barbershop,nail artist #lashextensions #beauty
2 months ago 00:12:13 1
Marco Rubio’s irrelevance in Trump world
2 months ago 00:05:34 1
US Keeps Up Attacks On Houthis; Yemen’s Houthi Fighters Target American Warships | Dawn News English
2 months ago 02:11:35 1
New Atlas LIVE: US Bombs Yemen as NATO Prepares Ukraine Bufferzone/Freeze
2 months ago 01:19:01 1
Dr. Anna Lembke: Understanding Addiction and the Role of Faith in Recovery (FULL INTERVIEW)
2 months ago 00:03:54 4
Putin responds to US-Ukraine ceasefire proposal, says he’s ’for it’ but has concerns
2 months ago 00:00:00 1
American Manhunt: Osama Bin Laden | Netflix Docu Series Review (2025)