Lesson 05 OWASP Top 10 2017 A1:2017-Injection Conviso Platform Docs

Injection attacks occur when untrusted data is injected through a form input or other types of data submission to web applications. A common type of injection attack is a Structured Query Language injection (SQLi), which occurs when cyber criminals inject SQL database code into an online form used for plaintext. The OWASP Top 10 is a report, or “awareness document,” that outlines security concerns around web application security. It is regularly updated to ensure it constantly features the 10 most critical risks facing organizations.

  • XXE attacks target web applications that parse the Extensible Markup Language (XML).
XML parsers are often vulnerable to an XXE by default, which means developers must remove the vulnerability manually. Sensitive data exposure or data leakage is one of the most common forms of cyberattack. Sensitive data, like credit card information, medical details, Social Security numbers, and user passwords, can be exposed if a web application does not protect it effectively. Attackers who are able to access and steal this information can use it as part of wider attacks or sell it to third parties.

Top 10 Web Application Security Risks

If you only want to read and view the course content, you can audit the course for free. If you cannot afford the fee, you can apply for financial aid. By providing this information, you agree to the processing OWASP Top 10 2017 Update Lessons of your personal data by SANS as described in our Privacy Policy. • A10 – Unvalidated Redirects and Forwards, while found in approximately 8% of applications, it was edged out overall by XXE.

OWASP Top 10 2017 Update Lessons

Please review the episode audio before quoting from this transcript and email with any questions. In data storage and computer science terms, serialization means converting objects, or data structures, into byte strings. Deserialization means converting those byte strings into objects. Insecure deserialization involves attackers tampering with data before it has been deserialized.

Is OWASP only for web applications?

  • Broken access controls result in users having access to resources beyond what they require.
  • Other recommendations include logging and reporting access failures and using rate limiting to minimize the damage caused by automated attacks.
