OWASP Top 10: #1 Broken Access Control and #2 Cryptographic Failures
29mIntermediate2022-07-01
Authors

Caroline Wong
Vice President of Cobalt.io
Course details
No one is immune to security vulnerabilities when it comes to web applications. We all live with the looming possibility that something could go wrong in any instant. That’s why the Open Web Application Security Project (OWASP) was formed to provide key resources that educate the public about how to navigate risk on the web. One such resource is the OWASP Top 10, a list of the ten biggest application security vulnerabilities, which was last published in 2021.
Join application security expert Caroline Wong as she walks you through the first two vulnerabilities on the list: broken access control and cryptographic failures. Learn how each vulnerability poses a threat to you with real-life examples along the way. Discover the latest, most effective prevention techniques to keep your web applications safe and secure.
Join application security expert Caroline Wong as she walks you through the first two vulnerabilities on the list: broken access control and cryptographic failures. Learn how each vulnerability poses a threat to you with real-life examples along the way. Discover the latest, most effective prevention techniques to keep your web applications safe and secure.
Skills covered
Security AwarenessApplication SecurityCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - OWASP Top 10
1. Broken Access Control
- 02 - What is broken access control
- 03 - Example 1 - 2021 Facebook broken access control vulnerability
- 04 - Example 2 - 2021 personal data travel breach
- 05 - Prevention techniques - Least privilege
- 06 - Prevention techniques - Record ownership and logging
- 07 - Prevention techniques - Functional access control testing
2. Cryptographic Failure
- 08 - What is cryptographic failure
- 09 - Example 1 - 2021 GoDaddy plaintext passwords
- 10 - Example 2 - Using a broken or risky cryptographic algorithm
- 11 - Prevention techniques - Data classification
- 12 - Prevention techniques - Proper key management
- 13 - Prevention techniques - Secure protocols
Conclusion
- 14 - OWASP Top 10 keep learning