The OWASP API 2023 Top 10: An Overview

The OWASP API 2023 Top 10: An Overview

43mIntermediate2024-01-23

Authors

Davin Jackson

Davin Jackson

Engineer, Pentester, Host of InfoSec Unplugged and Hacker Valley Blue

Course details

With more applications becoming more API driven, they are also becoming more vulnerable to major attacks. This course teaches tech professionals how to find and remove vulnerabilities to secure their applications. Instructor Davin Jackson explains how APIs work and the security issues they face. Davin covers the OWASP API 2023 Security Top Ten and explains some examples of these vulnerabilities, illustrating how prone to risk APIs are when left unprotected and sharing some tips on securing them. Get tips on dealing with common API vulnerabilities, including broken object-level authorization, broken authentication, server-side request forgery, unsafe consumptions of APIs, and more.

Skills covered

Application SecurityAPIsCybersecurityLearningSoftware Development

Concepts

Introduction

  • Don't be the next data breach
  • What you should know

Introduction to APIs

  • What are APIs
  • Security concerns
  • OWASP and the OWASP API Security project
  • The old vs. the new list

The OWASP API Top Ten

  • API1 - 2023 Broken Object-Level Authorization
  • API2 - 2023 Broken Authentication
  • API3 - 2023 Broken Object-Property-Level Authorization
  • API4 - 2023 Unrestricted Resource Consumption
  • API5 - 2023 Broken Function-Level Authorization
  • API6 - 2023 Unrestricted Access to Sensitive Business Flows
  • API7 - 2023 Server-Side Request Forgery
  • API8 - 2023 Security Misconfigurations
  • API9 - 2023 Improper Inventory Management
  • API10 - 2023 Unsafe Consumption of APIs

Conclusion

  • Keep learning
40,000 Toman