Owasp released 2013 Top ten Web Application security vulnerabilities

Source: Internet
Author: User
The authoritative security organization Owasp has just updated top 10:https://www.owasp.org/index.php/top_10_2013-top_10 ten security vulnerabilities: 1. injection, including SQL, operating system, and LDAP injection. 2. Problematic identification of session management. 3. Cross-site scripting attacks (XSS). 4. Unsafe direct object references. 5. Security Configuration error. 6. Exposing sensitive data. 7. Function-level access control is missing. 8. Cross-site request forgery (CSRF). 9. Use a component that has a known vulnerability.   10. Unauthenticated redirection. According to Securityweek (http://www.securityweek.com/owasp-top-10-2013-released), the report is based on a summary of more than 500,000 vulnerabilities found in hundreds of companies in thousands of applications. The top 3 remained the same compared to last year, but the XSS rankings slipped. CSRF rankings have also declined. The 6th "Exposing sensitive data" is a merger of last year's "Insecure password store" and "Unsecured Transport Layer Protection", covering more general cases related to data breaches. The 9th place, "Using components with known vulnerabilities", is the newly listed vulnerability.   These changes directly reflect the changing trend of Web application security. Is your web App secure? Review your code and train your staff from owasp Top 10 to improve the overall safety awareness of your company's research and development team.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.