The OWASP API 2023 Top 10: An Overview
43mIntermediate2024-01-23
Authors

Davin Jackson
Engineer, Pentester, Host of InfoSec Unplugged and Hacker Valley Blue
Course details
With more applications becoming more API driven, they are also becoming more vulnerable to major attacks. This course teaches tech professionals how to find and remove vulnerabilities to secure their applications. Instructor Davin Jackson explains how APIs work and the security issues they face. Davin covers the OWASP API 2023 Security Top Ten and explains some examples of these vulnerabilities, illustrating how prone to risk APIs are when left unprotected and sharing some tips on securing them. Get tips on dealing with common API vulnerabilities, including broken object-level authorization, broken authentication, server-side request forgery, unsafe consumptions of APIs, and more.
Skills covered
Application SecurityAPIsCybersecurityLearningSoftware Development
Concepts
0. Introduction
- 01 - Don't be the next data breach
- 02 - What you should know
1. Introduction to APIs
- 03 - What are APIs
- 04 - Security concerns
- 05 - OWASP and the OWASP API Security project
- 06 - The old vs. the new list
2. The OWASP API Top Ten
- 07 - API1 - 2023 Broken Object-Level Authorization
- 08 - API2 - 2023 Broken Authentication
- 09 - API3 - 2023 Broken Object-Property-Level Authorization
- 10 - API4 - 2023 Unrestricted Resource Consumption
- 11 - API5 - 2023 Broken Function-Level Authorization
- 12 - API6 - 2023 Unrestricted Access to Sensitive Business Flows
- 13 - API7 - 2023 Server-Side Request Forgery
- 14 - API8 - 2023 Security Misconfigurations
- 15 - API9 - 2023 Improper Inventory Management
- 16 - API10 - 2023 Unsafe Consumption of APIs
Conclusion
- 17 - Keep learning