OWASP Top 10: #3 Injection and #4 Insecure Design
32mIntermediate2022-08-23
Authors

Caroline Wong
Vice President of Cobalt.io
Course details
The Open Web Application Security Project (OWASP) was formed to provide the public with the resources needed to understand and enhance software security. The OWASP Top 10 list describes the ten biggest vulnerabilities. In this course, Caroline Wong takes a deep dive into the third and fourth categories of security vulnerabilities in the 2021 OWASP Top 10: injection and insecure design. They are extremely prevalent in web application development, and Caroline covers how these kinds of attacks work, reviews some real-life examples, and discusses how to prevent these types of attacks.
Skills covered
Application SecurityCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - 2021 OWASP Top 10
- 02 - What you should know
1. Injection
- 03 - What is injection
- 04 - Example #1 - 2008 Heartland data breach
- 05 - Example #2 - 2020 Accellion data breach
- 06 - Prevention technique #1 - Prepared statements
- 07 - Prevention technique #2 - Input validation
- 08 - Prevention technique #3 - Escape special characters
2. Insecure Design
- 09 - What is insecure design
- 10 - Real-world example #1 - G Suite accounts in 2018
- 11 - Real-world example #2 - 2021 manufacturing data risk report
- 12 - Prevention technique #1 - Threat modeling
- 13 - Prevention technique #2 - Secure design patterns and principles
- 14 - Prevention technique #3 - Secure development lifecycle
Conclusion
- 15 - Next steps