OWASP Top 10: #5 Broken Access Control and #6 Security Misconfiguration (2019)
27mIntermediate2019-05-13
Authors

Caroline Wong
Vice President of Cobalt.io
Course details
Security-related incidents pose major threats to organizations of all sizes, as well as the customers they serve. The Open Web Application Security Project (OWASP) was formed to educate the public about some of the most common security vulnerabilities. OWASP also provides a list—the OWASP top ten—that highlights the most critical security risks out there. In this course, Caroline Wong explores broken access control and security misconfiguration, the fifth and sixth categories of security vulnerabilities in the OWASP Top 10. Caroline explains how these threats work and provides real-life examples of how they can impact companies and consumers. Plus, she provides techniques that can help you prevent broken access control and security misconfiguration from impacting your organization.
Skills covered
Application SecurityCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Prevent common security vulnerabilities
1. Broken Access Control - How Does It Work
- 02 - General concept
2. Impact of Broken Access Control
- 03 - Example scenario 1
- 04 - Example scenario 2
3. Preventing Broken Access Control
- 05 - Properly implement access controls
- 06 - Logging and alerting
- 07 - Manual testing
4. Security Misconfiguration - How Does It Work
- 08 - General concept
5. Impact of Security Misconfiguration
- 09 - Example scenario 1
- 10 - Example scenario 2
6. Preventing Security Misconfiguration
- 11 - Harden all systems
- 12 - Patch and update software
- 13 - Test configurations
Conclusion
- 14 - Next steps