OWASP Top 10: #1 Injection and #2 Broken Authentication
37mBeginner2018-06-04
Authors

Caroline Wong
Vice President of Cobalt.io
Course details
The Open Web Application Security Project (OWASP) was formed to provide the public with the resources to understand and improve software security. The OWASP Top 10 list describes the ten biggest software vulnerabilities. In this course, application security expert Caroline Wong provides an overview of the top two: injection and broken authentication attacks. Find out how injection and broken authentication work and see real-life examples of the attacks and their impact on companies and consumers. Plus, get prevention techniques to avoid putting your applications and users at risk.
Skills covered
Application SecurityCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Welcome
1. Injection Attacks - How Do They Work
- 02 - General concept
2. Impact of Injection Attacks
- 03 - Example scenario one
- 04 - Example scenario two
3. Preventing Injection Attacks
- 05 - Input validation
- 06 - Prepared statements and stored procedures
- 07 - Least privilege
4. Broken Authentication Attacks - How Do They Work
- 08 - General concept
- 09 - Variations on the general concept
5. Impact of Broken Authentication Attacks
- 10 - Example scenario one
- 11 - Example scenario two
6. Preventing Broken Authentication Attacks
- 12 - Use complex passwords
- 13 - Store passwords with proper encryption
- 14 - Use multi-factor authentication
Conclusion
- 15 - Next steps