OWASP Top 10


Majd Sawaf

OWASP Top 10


Open Web Application Security Project (OWASP) Top 10 is an awareness document that focuses on enhancing security. The most recent of OWASP was released in 2021, emphasizing the important security risks that developers need to address on secure coding.
This list outlines the top 10 security vulnerabilities faced by web applications, emphasizing the mitigation of these risks to ensure the security of web applications against cyber threats.

A01:2021 Broken Access Control | A02:2021 Cryptographic Failures | A03:2021 Injection | A04:2021 Insecure Design | A05:2021 Security Misconfiguration | A06:2021 Vulnerable and Outdated Components | A07:2021 Identification and Authentication Failures | A08:2021 Software and Data Integrity Failures | A09:2021 Security Logging and Monitoring Failures | A010:2021 Server-Side Request Forgery

Broken Access Control

Overview

A security flaw that allows unauthorized user access to confidential information.

What It Is

A security vulnerability when a system neglects to enforce access controls based on user privileges, leading to unauthorized users gaining access to information or performing actions they shouldn’t.

Mitigation

Developers should implement strong access controls and least privilege principles. Regular testing, code review are important to remediate access control flaws.


Cryptographic Failures

Overview

Inadequate cryptographic systems can lead to unauthorized access to encrypted data when exploited by malicious actors due to implementation or management weaknesses.

What It Is

Inadequate cryptographic systems or protocols that fail to deliver the security they are designed for. When systems fail malicious actors can exploit vulnerabilities to gain unauthorized access to encrypted data, decrypt it and misuse it. These weaknesses can be from improper implementation, poor management practices or other vulnerabilities within the system, allowing for encryption bypass or unauthorized access.

Mitigation

Use strong cryptography, implement secure management practices, ensure secure storage. Utilize reputable cryptographic libraries and frameworks, regular security testing and stay updated on security patches and developments.


Injection

Overview

An attacker can inject malicious code into an application to compromise another system.

What It Is

Injection is a type of security flaw that is very well known in application security. It occurs when untrusted data through a query is mishandled which can lead to unintended commands being executed allowing attackers to access authorized information.

They are frequently exploited by attackers to establish a foothold in a system, escalate privileges or take private and confidential information.

Mitigation

Implementing secure code practices

Enforce strict input validation

Regularly updating software

Enhancing least privilege principles

Deploying Web Application Firewall (WAF)

Using secure APIs

Monitoring and logging


Insecure Design

Overview

The way developers design programs and integrate security measures. These hidden vulnerabilities can quietly persist in the background making a security risk.

What It Is

A new category for 2021 focusing on design flaw risks. These security vulnerabilities come from inadequate software architecture or design allowing attackers to exploit systems more easily.

Examples of vulnerabilities:

Weak security controls

Insecure APIs

Insufficient monitoring and logging

Unsecured communication

Mitigation

Key Security Practices:

Implementing security measures throughout the software development lifecycle

Implementing strong authentication and access controls

Encrypting sensitive data

Utilizing secure communication protocols

Logging and monitoring system events

Regularly updating and patching software


Security Misconfiguration

Overview

Inadequate security configurations makes vulnerabilities and open pathways to attackers. Such vulnerabilities come from misconfigurations that makes the application susceptible to attacks.

What It Is

Poor security configurations of web application components, servers, frameworks and databases can leave systems vulnerable to attacks. When security measures are not appropriately defined, implemented or maintained they expose vulnerabilities for attackers to exploit.

Common Examples:

Weak passwords

Not changing default configurations/settings

Leaving unused features and services enabled

Weak encryption settings

Neglecting data encryption

Insecure storage methods

Failure to apply software patches

Risks associated with public Wi-Fi usage

Social Engineering

Insecure mobile applications

Risks from USB and removable media

Lack of data backups

Mitigation

Stay vigilant against common security threats by employing strong passwords, remaining alert to phishing attempts, maintaining up-to-date software, utilizing VPNs and other tools on public Wi-Fi, implementing data encryption and regularly backing up data. These techniques enhance the security posture and help mitigate risks effectively.


Vulnerable and Outdated Components

Overview

When code or hardware becomes vulnerable or is no longer maintained.

What It Is

Software that have security flaws because of coding errors, design flaws or outdated libraries or frameworks.

Vulnerable and outdated components pose a threat to web applications.

Attackers can use flaws in vulnerable components to gain unauthorized access.

Operating systems are susceptible to security risks when they lack the latest updates and patches.

Vulnerabilities can come from operating systems, networking equipment, web servers and applications, databases, IoT devices, cloud infrastructure, libraries and frameworks.

Mitigation

Regularly update both software and firmware along with security patches. Security assessments should be made and security practices should be implemented.


Identification and Authentication Failures

Overview

When systems encounter issues in identifying and verifying users, these failures can lead to a variety of security vulnerabilities.

What It Is

Security vulnerabilities in systems responsible for verifying and granting user access.

Common weaknesses:

Easy passwords

Inadequate credentials

Insecure methods of authentication

Deficient MFA

Brute force attacks

Mitigation

Effective password policies

MFA

Restrict number of login attempts

Educate users


Software and Data Integrity Failures

Overview

Inadequately secured code and infrastructure vulnerable to integrity infraction, allowing access to applications and data.

What It Is

A new category for 2021. Ensuring the integrity of software and data is important for maintaining the security of web applications. Data integrity ensures that only authorized users can access information. When software systems or data storage lack accuracy and reliability it is because of software bugs, coding errors or hardware failures which can lead to data corruption and unauthorized access.

Mitigation

Implementing a comprehensive data validation strategy to ensure accuracy, prevent injection attacks and deny authorized access alongside strong encryption for data protection, regular security testing, security coding practices, backup and recovery protocols and effective logging and monitoring.


Security Logging and Monitoring Failures

Overview

Web applications that lack real-time monitoring. Security vulnerabilities that come from systems or applications that neglect logging or monitoring security events.

What It Is

Ensuring the logging of login attempts, access control checks and server-side input validation processes.

Poor logging and monitoring creates undetected vulnerabilities in the system. Audits like successful logins, failed logins, password changes and other important changes must be logged to prevent security breaches. Inadequate logging in web applications increases vulnerabilities and makes it hard to detect and respond to threats. Strong logging is important for proactive security.

Mitigation

Implement strong logging

Enable real-time monitoring

Conduct routine log analysis

Incident response plan

Training and awareness


Server-Side Request Forgery

Overview

Server-Side Request Forgery or SSRF is a type of injection attack, a web security vulnerability.

What It Is

A new entry into the OWASP Top 10. SSRF is a web security vulnerability where an attacker deceives the server into making unauthorized requests to internal or external systems. This vulnerability allows attackers to breach internal systems that are isolated from web access. Exploiting SSRF allows attackers to bypass firewalls, gather information within the internal network and pivot to launch attacks on other systems accessible from the compromised server.

Mitigation

Strong input validation

Network segmentation

Proxy utilization

Access controls

Regular security audits