Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
OWASP Top 10: #9 Security Logging and Monitoring Failures and #10 Server-Side Request Forgery

OWASP Top 10: #9 Security Logging and Monitoring Failures and #10 Server-Side Request Forgery

39mIntermediate2023-10-25

Authors

Caroline Wong

Caroline Wong

Vice President of Cobalt.io

Course details

It’s important to protect your organization against security vulnerabilities, but how do you prepare for a possible attack? In this course, join instructor and application security expert Caroline Wong as she gives you an overview of the ninth and tenth most common vulnerabilities listed on the 2021 Open Web Application Security Project (OWASP) Top 10 List: security logging and monitoring failures and server-side request forgery.

Discover strategies to defend yourself against these two prominent types of attack, drawing from real-life examples along the way. Caroline offers insights on the latest, most effective prevention techniques to keep your web applications safe and secure, including sufficient user context, consistent monitoring and alerting, an incident response and recovery plan, network layer and application layer prevention, and authentication for internal services.

Skills covered

Application SecurityCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • 2021 OWASP Top 10
  • OWASP Top 10 series

Security Monitoring and Logging Failures

  • What are security monitoring and logging failures
  • Example 1 - 2018 Starwood data breach
  • Example 2 - 2021 South Georgia Medical Center insider threat
  • Prevention technique - Ensure logging includes sufficient user context
  • Prevention technique - Ensure monitoring and alerting are active and consistent
  • Prevention technique - Establish an incident response and recovery plan

Server-Side Request Forgery

  • What is Server-Side Request Forgery (SSRF)
  • Example 1 - 2019 Capital One breach
  • Example 2 - 2017 GitHub Enterprise chained exploits
  • Prevention technique - Network layer prevention techniques
  • Prevention technique - Application layer
  • Prevention technique - Require authentication for internal services

Conclusion

  • Explore more of the OWASP Top 10

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal