The OWASP Top 10
Read first: HTTP status codes
TL;DR
The OWASP Top 10 is the industry’s list of the most common, most impactful web application risks. It is not a checklist of bugs so much as ten categories of things that go wrong. If you learn to spot these, you cover most of what shows up on a real web test.
What it is
OWASP (the Open Worldwide Application Security Project) publishes a ranked list of the ten broadest web security risks, refreshed every few years from real-world data. It’s the shared vocabulary the whole industry uses, so it’s worth knowing by heart. Below is the 2021 list, with a line on each and a link to a deeper page where there is one.
| # | Category | In one line |
|---|---|---|
| A01 | Broken Access Control | Users reaching things they shouldn’t. The most common finding by far. |
| A02 | Cryptographic Failures | Weak or missing encryption of data in transit or at rest. |
| A03 | Injection | Untrusted input changing a command — SQLi, command injection, and (here) XSS. |
| A04 | Insecure Design | The flaw is in the design, not a single line of code. |
| A05 | Security Misconfiguration | Default creds, verbose errors, things left switched on. |
| A06 | Vulnerable & Outdated Components | Old libraries and software with known CVEs. |
| A07 | Identification & Authentication Failures | Weak logins, poor session handling, credential attacks. |
| A08 | Software & Data Integrity Failures | Trusting updates, pipelines or data you shouldn’t. |
| A09 | Security Logging & Monitoring Failures | Not seeing an attack because nothing was logged. |
| A10 | Server-Side Request Forgery (SSRF) | Making the server fetch things it shouldn’t. |
Two more that sit under other categories but come up constantly on tests, so they get their own pages here: Cross-Site Scripting (XSS), CSRF, file upload flaws and command injection.
How to use it
Treat the Top 10 as a map, not a script. On a web test you’re working through these categories: can I reach things I shouldn’t (A01), can I influence a command (A03), is the login weak (A07), can I make the server fetch something (A10), and so on. The individual pages cover how each one works and how it’s tested and fixed.
Reference: the OWASP Top 10 and the Web Security Testing Guide.