OWASP Top 10: #7 XSS and #8 Insecure Deserialization

OWASP Top 10: #7 XSS and #8 Insecure Deserialization

26mIntermediate2019-10-01

Authors

Christina Truong

Christina Truong

Educator, Front-End Developer

Course details

Recent changes in application architecture and technology have sparked new opportunities and ways of working. But with these new advancements come new risks. The Open Web Application Security Project (OWASP) Top 10 list describes the ten biggest vulnerabilities that today's software developers and organizations face. In this course, Caroline Wong takes a deep dive into the seventh and eighth categories of security vulnerabilities in the OWASP Top 10—cross-site scripting (XSS) and insecure deserialization. Caroline covers how XSS and insecure deserialization work, providing real-world examples that demonstrate how they affect companies and consumers alike. She also shares techniques that can help you prevent these types of attacks.

Skills covered

Application SecurityCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Common software vulnerabilities

Cross-Site Scripting - How Does It Work

  • General concept

Impact of Cross-Site Scripting

  • Example scenario 1
  • Example scenario 2

Preventing Cross-Site Scripting

  • Enable a content security policy
  • Apply context sensitive encoding
  • Escape untrusted HTTP data

Insecure Deserialization - How Does It Work

  • General concept

Impact of Insecure Deserialization

  • Example scenario 1
  • Example scenario 2

Preventing Insecure Deserialization

  • Use integrity checks and encrypt
  • Log to detect insecure deserialization
  • Isolate code that deserializes

Conclusion

  • Next steps