Introduction
Introduction to OWASP Top 10
()
1. OWASP Top 10: Why It Still Matters
OWASP Top 10 "in the wild": Recent news headlines
()
How risks shift
()
Security at every phase of the software development lifecycle
()
2. Broken Access Control
Broken access control "in the wild"
()
Defending against broken access control
()
3. Security Misconfiguration
Security misconfiguration "in the wild"
()
Defending against security misconfiguration
()
4. Software Supply Chain Failures
Software supply chain failures "in the wild"
()
Defending against software supply chain failures
()
5. Cryptographic Failures
Cryptographic failures "in the wild"
()
Defending against cryptographic failures
()
6. Injection Attacks
Injection attacks "in the wild"
()
Defending against injection attacks
()
7. Insecure Design
Insecure design "in the wild"
()
Defending against insecure design
()
8. Authentication Failures
Authentication failures "in the wild"
()
Defending against authentication failures
()
9. Software and Data Integrity Failures
Software and data integrity failures "in the wild"
()
Defending against software and data integrity failures
()
10. Security Logging and Alerting Failures
Security logging and alerting failures "in the wild"
()
Defending against security logging and alerting failures
()
11. Mishandling of Exceptional Conditions
Mishandling of exceptional conditions "in the wild"
()
Defending against mishandling of exceptional conditions
()
Putting It All Together: Secure Application Development Playbook
Beyond the Top 10
()