Files
org_web/posts/career/owasp.org
2025-12-28 21:19:27 +00:00

3.1 KiB

OWASP Top Ten

Competency notes:

../../assets/images/owasp/Screenshot 2025-10-16 134403.png ../../assets/images/owasp/Screenshot 2025-10-16 134438.png ../../assets/images/owasp/Screenshot 2025-10-16 134457.png ../../assets/images/owasp/Screenshot 2025-10-16 134403.png ../../assets/images/owasp/Screenshot 2025-10-16 134512.png

OWASP Top 10 (2021)

A01: Broken Access Control

  • Users can act outside their permissions (e.g., IDOR, privilege escalation).
  • Mitigations:

    • Enforce server-side authorization on every request.
    • Deny by default; allow only explicit permissions.
    • Test with role and privilege matrices.

A02: Cryptographic Failures

  • Sensitive data is exposed due to weak or misused cryptography.
  • Mitigations:

    • Use modern TLS everywhere.
    • Encrypt sensitive data in transit and at rest.
    • Manage keys securely and avoid homegrown crypto.

A03: Injection

  • Untrusted input alters queries or commands (SQLi, XSS, command injection).
  • Mitigations:

    • Use parameterized queries and prepared statements.
    • Sanitize and validate input.
    • Escape output appropriately for each context.

A04: Insecure Design

  • Security flaws in system design or architecture.
  • Mitigations:

    • Perform threat modeling early.
    • Use secure design patterns and reference architectures.
    • Enforce defense-in-depth and least privilege.

A05: Security Misconfiguration

  • Insecure defaults, unnecessary features, verbose errors, misconfigured services.
  • Mitigations:

    • Harden configurations and use secure defaults.
    • Automate configuration management.
    • Disable unused features and accounts.

A06: Vulnerable and Outdated Components

  • Using outdated software or libraries with known vulnerabilities.
  • Mitigations:

    • Maintain an inventory (SBOM) of components.
    • Monitor CVEs and patch frequently.
    • Use trusted package sources.

A07: Identification and Authentication Failures

  • Broken login, session management, or weak authentication.
  • Mitigations:

    • Use strong authentication (MFA recommended).
    • Protect session tokens; implement logout and timeouts.
    • Avoid exposing sensitive session IDs in URLs.

A08: Software and Data Integrity Failures

  • Relying on untrusted software or pipelines without integrity verification.
  • Mitigations:

    • Sign and verify code and dependencies.
    • Secure CI/CD pipelines.
    • Use integrity checks for data and updates.

A09: Security Logging and Monitoring Failures

  • Inadequate logging or monitoring prevents detection of attacks.
  • Mitigations:

    • Log critical events (auth, access, errors).
    • Centralize and monitor logs.
    • Establish alerting and response procedures.

A10: Server-Side Request Forgery (SSRF)

  • The application fetches URLs from untrusted sources on behalf of users.
  • Mitigations:

    • Deny outbound network access by default.
    • Use allowlists for external requests.
    • Protect metadata and internal services.