OWASP Top 10: #7 XSS and #8 Insecure Deserialization
26mIntermediate2019-10-01
Authors

Christina Truong
Educator, Front-End Developer
Course details
Recent changes in application architecture and technology have sparked new opportunities and ways of working. But with these new advancements come new risks. The Open Web Application Security Project (OWASP) Top 10 list describes the ten biggest vulnerabilities that today's software developers and organizations face. In this course, Caroline Wong takes a deep dive into the seventh and eighth categories of security vulnerabilities in the OWASP Top 10—cross-site scripting (XSS) and insecure deserialization. Caroline covers how XSS and insecure deserialization work, providing real-world examples that demonstrate how they affect companies and consumers alike. She also shares techniques that can help you prevent these types of attacks.
Skills covered
Application SecurityCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Common software vulnerabilities
1. Cross-Site Scripting - How Does It Work
- 02 - General concept
2. Impact of Cross-Site Scripting
- 03 - Example scenario 1
- 04 - Example scenario 2
3. Preventing Cross-Site Scripting
- 05 - Enable a content security policy
- 06 - Apply context sensitive encoding
- 07 - Escape untrusted HTTP data
4. Insecure Deserialization - How Does It Work
- 08 - General concept
5. Impact of Insecure Deserialization
- 09 - Example scenario 1
- 10 - Example scenario 2
6. Preventing Insecure Deserialization
- 11 - Use integrity checks and encrypt
- 12 - Log to detect insecure deserialization
- 13 - Isolate code that deserializes
Conclusion
- 14 - Next steps