The OWASP Top 10

beginnerWeb

Read first: HTTP status codes

TL;DR

The OWASP Top 10 is the industry’s list of the most common, most impactful web application risks. It is not a checklist of bugs so much as ten categories of things that go wrong. If you learn to spot these, you cover most of what shows up on a real web test.

What it is

OWASP (the Open Worldwide Application Security Project) publishes a ranked list of the ten broadest web security risks, refreshed every few years from real-world data. It’s the shared vocabulary the whole industry uses, so it’s worth knowing by heart. Below is the 2021 list, with a line on each and a link to a deeper page where there is one.

#CategoryIn one line
A01Broken Access ControlUsers reaching things they shouldn’t. The most common finding by far.
A02Cryptographic FailuresWeak or missing encryption of data in transit or at rest.
A03InjectionUntrusted input changing a command — SQLi, command injection, and (here) XSS.
A04Insecure DesignThe flaw is in the design, not a single line of code.
A05Security MisconfigurationDefault creds, verbose errors, things left switched on.
A06Vulnerable & Outdated ComponentsOld libraries and software with known CVEs.
A07Identification & Authentication FailuresWeak logins, poor session handling, credential attacks.
A08Software & Data Integrity FailuresTrusting updates, pipelines or data you shouldn’t.
A09Security Logging & Monitoring FailuresNot seeing an attack because nothing was logged.
A10Server-Side Request Forgery (SSRF)Making the server fetch things it shouldn’t.

Two more that sit under other categories but come up constantly on tests, so they get their own pages here: Cross-Site Scripting (XSS), CSRF, file upload flaws and command injection.

How to use it

Treat the Top 10 as a map, not a script. On a web test you’re working through these categories: can I reach things I shouldn’t (A01), can I influence a command (A03), is the login weak (A07), can I make the server fetch something (A10), and so on. The individual pages cover how each one works and how it’s tested and fixed.

Reference: the OWASP Top 10 and the Web Security Testing Guide.

← Back to Web