OWASP Top 10

Understand the most critical web application security risks and how to prevent them, with vulnerable and fixed code side by side for access control, injection, cryptography, configuration, components, authentication and monitoring.

Start course →

What you'll learn

  • Explain what the OWASP Top 10 is and how its categories map to real web application weaknesses.
  • Recognise and fix broken access control, injection and cross-site scripting in application code.
  • Protect data with correct TLS, password hashing and secrets management.
  • Harden configuration, dependencies and build pipelines against misconfiguration and supply-chain attacks.
  • Implement robust authentication, sessions, logging and monitoring.
  • Build security into the development lifecycle with threat modelling, testing and review checklists.

Syllabus

Understanding the OWASP Top 10

  1. What the OWASP Top 10 Is
  2. The Categories
  3. Thinking Like a Defender

Broken Access Control and SSRF

  1. Object-Level Authorisation (IDOR)
  2. Function-Level Access and CORS
  3. Server-Side Request Forgery

Injection and Cross-Site Scripting

  1. SQL Injection
  2. Cross-Site Scripting (XSS)
  3. Command, Template and Other Injection

Cryptographic Failures and Sensitive Data

  1. Encryption in Transit and at Rest
  2. Password Storage
  3. Secrets Management

Insecure Design and Misconfiguration

  1. Insecure Design
  2. Security Misconfiguration
  3. Security Headers and Error Handling

Components, Integrity and the Supply Chain

  1. Vulnerable and Outdated Components
  2. Software and Data Integrity Failures
  3. Securing the Software Supply Chain

Authentication, Sessions and Monitoring

  1. Authentication Failures
  2. Sessions and Tokens
  3. Security Logging and Monitoring

Building Security Into Development

  1. Security Testing
  2. Handling Exceptional Conditions
  3. Secure Code Review
  4. An OWASP Top 10 Checklist