OWASP Top 10
Understand the most critical web application security risks and how to prevent them, with vulnerable and fixed code side by side for access control, injection, cryptography, configuration, components, authentication and monitoring.
What you'll learn
- Explain what the OWASP Top 10 is and how its categories map to real web application weaknesses.
- Recognise and fix broken access control, injection and cross-site scripting in application code.
- Protect data with correct TLS, password hashing and secrets management.
- Harden configuration, dependencies and build pipelines against misconfiguration and supply-chain attacks.
- Implement robust authentication, sessions, logging and monitoring.
- Build security into the development lifecycle with threat modelling, testing and review checklists.
Syllabus
Understanding the OWASP Top 10
Broken Access Control and SSRF
Injection and Cross-Site Scripting
Cryptographic Failures and Sensitive Data
Insecure Design and Misconfiguration
Components, Integrity and the Supply Chain
- Vulnerable and Outdated Components
- Software and Data Integrity Failures
- Securing the Software Supply Chain