Ravindra BagaleCourses & study guides

29. OWASP Top 10 Web Vulnerabilities

29.1 What OWASP and the Top 10 Are

OWASP (Open Worldwide Application Security Project) is a non-profit that publishes free security guidance. Its most famous document is the OWASP Top 10 – the ten most critical web application security risks, updated every few years (the current list is from 2021; verify the latest at owasp.org).

The 2021 Top 10:

# Category
A01 Broken Access Control
A02 Cryptographic Failures
A03 Injection (SQLi, command injection, XSS)
A04 Insecure Design
A05 Security Misconfiguration
A06 Vulnerable and Outdated Components
A07 Identification and Authentication Failures
A08 Software and Data Integrity Failures
A09 Security Logging and Monitoring Failures
A10 Server-Side Request Forgery (SSRF)

Ravindra Bagale's Tip

OWASP Top 10 pathantar karaycha nahi – samjun ghyaycha. Interview madhe "OWASP Top 10 sanga" vichartat, pan khara prashna asto "SQL injection kasa thambavshil?". Concept ani fix mahiti asel tar naav आपोआप lakshat rahtat. Ha document harek web developer ne vachla pahije.

Practice task

Open owasp.org and confirm the current Top 10 list. In your notes, write the ten categories and, beside each, one line in your own words about what it means.