Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
OWASP Top 10: #7 Identification and Authentication Failures and #8 Software and Data Integrity Failures

OWASP Top 10: #7 Identification and Authentication Failures and #8 Software and Data Integrity Failures

40mIntermediate2023-10-25

Authors

Caroline Wong

Caroline Wong

Vice President of Cobalt.io

Course details

Failures related to identity, authentication, and software and data integrity loom large in web application development. You need to keep security vulnerabilities top of mind, but how do you prepare for a possible attack? In this course, instructor and application security expert Caroline Wong gives you an overview of the seventh and eighth most common vulnerabilities listed on the 2021 Open Web Application Security Project (OWASP) Top 10 List: identity and authentication failures, and software and data integrity failures.

Explore the basics of these two types of failures to find out what you can do to defend yourself against an attack, drawing from real-life examples along the way. Caroline shares insights on the latest, most effective prevention techniques to keep your web applications safe and secure, including Pwned Passwords, weak password checks, multifactor authentication, password logs and limits, digital signatures, trusted repositories, and code and configuration changes.

Skills covered

Identity and Access ManagementCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • OWASP Top 10
  • OWASP Top 10 series

Identification and Authentication Failures

  • What are identification and authentication failures
  • Example 1 - Pwned Passwords
  • Example 2 - 2021 Verkada data breach
  • Prevention technique - Check for weak passwords
  • Prevention technique - Use multi-factor authentication
  • Prevention technique - Log and limit repeated login attempts

Software and Data Integrity Failures

  • What are software and data integrity failures
  • Example 1 - Solar Winds software supply chain attack
  • Example 2 - 2021 Codecov bash uploader compromise
  • Prevention technique - Use digital signatures
  • Prevention technique - Ensure repositories are trustworthy
  • Prevention technique - Review code and configuration changes

Conclusion

  • OWASP Top 10 keep learning

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal