Ravindra BagaleCourses & study guides

29. OWASP Top 10 Web Vulnerabilities

Chala mitrano, aata Part 11 – khara ethical hacking course. Suruvat sarvat mahatvachya yaadine: OWASP Top 10. He jagatlya sarvat dhokadayak web application vulnerabilities aahet, OWASP naavachya sansthene tharavlelya. Tumhi Chapter 9 te 16 madhe swatah web app banavla – aata tya app madhe he bugs kase yetat, attacker kase vaparto, ani sarvat mahatvacha, te kase fix karaycha he shiku. Pratyek attack DVWA/Juice Shop var karun, mag fix code madhe. Sagle fakt tumchya lab var. Samjla ka? Chala!

What you will learn in this chapter

  • What OWASP and the Top 10 are
  • Each of the 2021 Top 10 categories: what it is, a lab, and the fix
  • SQL injection, XSS, CSRF, broken access control/IDOR, file upload, command injection, SSRF and misconfiguration in depth
  • How the fixes map to the code you wrote in Chapters 9–16
  • Secure-coding habits you can apply immediately

Lab scope for this whole chapter

Run every attack only against DVWA, OWASP Juice Shop, or your own reels app from Chapter 16, on the host-only lab. Testing these on any site you do not own is a crime under the IT Act.

Concepts in this chapter

  1. 29.1What OWASP and the Top 10 Are
  2. 29.2A03 Injection: SQL Injection
  3. 29.3A03 Injection: Cross-Site Scripting (XSS)
  4. 29.4A03 Injection: Command Injection
  5. 29.5A01 Broken Access Control and IDOR
  6. 29.6A07 Authentication and A02 Cryptographic Failures
  7. 29.7The Rest: Design, Components, Integrity, Logging, SSRF
  8. 29.8Red vs Blue, Project and Real Incidents

The chapter recap is at the end of the last concept page.