Lucebra
Lucebra Biashara
TEHAMA na Programu/Mtandao na Usalama/OWASP

OWASP Top 10 Explained: A Practical Guide to AppSec

Quick guide to the OWASP Top Ten and Application Security fundamentals for developers

Ngazi Zote • 17 Mihadhara • Ufikiaji wa Maisha Yote
Derek Fisher

Mwalimu Mkuu Aliyethibitishwa

OWASP Top 10 Explained: A Practical Guide to AppSec
trailer ya gari
Kutana na mwalimu wako: Derek Fisher

19 ms

5.0 / 5.0
Ukadiriaji wa Kimataifa
1 saa 47 dak
Jumla ya Maudhui

Utajifunza nini

Awareness of what Application Security is and how it's used
Some historical context on Application Security
Basic terms used in AppSec
What a Secure SDLC and DevSecOps pipeline look like

Maudhui ya Kozi

4 sehemu • 17 mihadhara • 01:47:53 urefu wa jumla

Introduction

07:35

Welcome to "Quick Guide to AppSec and the OWASP Top Ten"! Join Derek Fisher, a seasoned product security leader, speaker, university instructor, and author of "The Application Security Program Handbook" as he takes you on a journey through the essentials of application security. We cover the foundational concepts like asset types, threats, and the pillars of cybersecurity: confidentiality, integrity, availability, authentication, and authorization (CIAAA). From real-world examples to best practices, this video dives into securing assets and understanding the critical components of application security. Follow along and learn more about protecting your digital assets. Ready to level up your AppSec knowledge? Let’s get started!

Conclusion

01:50

In this wrap-up video, we summarize the key takeaways from the course on cybersecurity principles. We revisit the pillars of cybersecurity: Confidentiality, Integrity, Availability, Authentication, and Authorization (CIAAA), and their role in safeguarding systems and data. Highlights include defense-in-depth strategies, least privilege access, secure input sanitization, effective patch management, and robust logging practices. Learn the importance of secure third-party components, distinguishing between authentication and authorization, using secure defaults to prevent misconfigurations, and designing systems resilient to failure. Thank you for joining us!

Broken Access Controls

04:34

In this video, we dive into the concept of broken access control, what it is, how it occurs, and why it matters for application security. Starting with the basics of authentication (validating identity) and authorization (granting access), we clarify the differences between these terms and illustrate what happens when authorization controls fail. Learn about common vulnerabilities, such as SQL injection and forced browsing, that attackers use to bypass access restrictions and gain unauthorized access to data and admin functions. Discover preventive measures like default-deny access, centralized control mechanisms, session management, and logging practices to protect sensitive areas and ensure users only access what they need.

Demo of Broken Access Controls

08:25

In this video, we explore session hijacking, a critical vulnerability under the umbrella of broken access control. Using a hands-on example, we demonstrate how weak session ID generation—lacking complexity and randomness—can be exploited to predict and hijack session cookies. Follow along as we use developer tools and PowerShell scripting to identify patterns in session IDs and iterate through possible values to gain unauthorized access. Learn how attackers exploit predictable session IDs and the importance of implementing robust session management practices to protect your applications. This practical exercise underscores the risks of insecure session handling and how to mitigate them.

Cryptographic Failures

05:44

In this video, we tackle cryptographic failures and explore how to protect data in its three primary states: in motion, at rest, and in use. Learn how data in motion is safeguarded through protocols like HTTPS and TLS, ensuring secure transfers between devices. For data at rest (stored in databases or file system) encryption is typically managed with symmetric keys, supported by secure key management tools like Hardware Security Modules (HSMs) and Key Management Services (KMS). Lastly, we cover data in use, which involves protecting data actively processed in memory using techniques such as memory segmentation and encryption. Dive in to understand how these layers of protection maintain data confidentiality and prevent cryptographic failures in your applications.

Injection

03:25

In this video, we dive into injection attacks, a critical security vulnerability that occurs when untrusted input changes the behavior of an application. From SQL injection, where malicious SQL commands exploit unfiltered inputs, to script injection like cross-site scripting (XSS) that embeds harmful code into web pages, we cover it all. Learn about OS injection, which can execute system commands, and XML injection, such as XML External Entity (XXE) attacks, that target XML processors. Discover best practices to prevent these vulnerabilities, including input validation, output encoding, and security mechanisms like Content Security Policy. This is your guide to understanding and mitigating injection vulnerabilities in application security.

Demo of Injection Attack

17:05

Here we will show a brief demo of a SQL injection attack utilizing OWASP WebGoat.

Insecure Design

07:59

This video explores the concept of insecure design, introduced in 2021 to highlight the risks of architectural and design flaws in applications. Learn why security must be integrated into the early stages of development through threat modeling, secure design patterns, and pre-code actions that align with secure-by-design principles. Discover how to create functional and security requirements informed by regulations, frameworks, and threat intelligence. We cover key elements like building a secure architecture, leveraging the Secure Software Development Lifecycle (SDLC), and using tools like SAST, DAST, and SCA for validation. Finally, understand how to mitigate common design vulnerabilities such as insecure password recovery, improper file uploads, and lack of bot protections. This video is your guide to embedding security from the start and ensuring resilient, robust application designs.

Security Misconfiguration

02:17

In this video, we unpack security misconfiguration, a common vulnerability resulting from improper or default configurations across systems and applications. From operating systems and web servers to databases and application code, misconfigurations leave critical systems open to attack. Examples include leaving default settings on production environments, exposing debug code or unused third-party libraries, enabling directory listing for attackers to reverse-engineer code, and providing overly permissive cloud configurations, such as public S3 buckets. Learn the risks these missteps pose and discover how following security best practices and proactive configuration management can prevent data breaches and safeguard your applications.

Insecure Dependencies

05:55

This video dives into the risks posed by vulnerable and outdated components in application development. Modern applications rely heavily on dependencies—both direct and indirect—which form the building blocks of your software. While these libraries and frameworks speed up development, they can introduce significant security risks if not properly managed. Learn how vulnerabilities in direct and nested dependencies can expose your application to attacks, and discover how attackers leverage automated tools to identify misconfigured and outdated components. Explore best practices for mitigating these risks, including maintaining an up-to-date inventory of components, removing unnecessary libraries, and using internal or managed repositories for secure package management. Build safer applications by staying ahead of dependency-related vulnerabilities!

Insecure Authentication

09:13

This video explores identification and authentication failures, highlighting common weaknesses in authentication processes and how they can be exploited. Learn about attacks such as weak passwords, credential stuffing, brute-force attacks, and improper password storage practices. We explain the importance of robust password policies, multi-factor authentication (MFA), and secure password storage techniques like hashing with salt and pepper. Discover best practices aligned with NIST guidelines, including limiting failed login attempts, avoiding default passwords, and using advanced authentication methods like biometrics or PKI. Strengthen your application's defenses against authentication vulnerabilities and protect user identities with these actionable insights.

Demo of Authentication Failure

05:59

This video demonstrates how authentication bypasses occur and how attackers exploit flaws in configuration or logic to bypass security measures. Using a lab example, we explore bypassing a two-factor password reset mechanism by tampering with HTTP request parameters. Follow along as we use developer tools and PowerShell to manipulate hidden inputs and parameter counts to bypass verification and reset a password.

Key takeaways include:

Common techniques for bypassing authentication, such as removing or renaming parameters and forced browsing.

Understanding how insecure validation logic can allow bypasses by failing to properly verify input values.

The importance of validating all parameters and ensuring robust security for authentication mechanisms.

This practical walkthrough highlights the risks of poorly implemented authentication and emphasizes the need for secure design and rigorous testing.

Software Integrity Failures

05:38

This video explores software and data integrity failures, focusing on how vulnerabilities can occur throughout the software development lifecycle (SDLC). From coding and building to deployment and runtime, we discuss key risks like unsigned software, tampered packages, and unverified repositories. Learn why signed software and hosting internal repositories are essential for maintaining code integrity, and discover the importance of a robust patch management process to address vulnerabilities. Additionally, we highlight the need for secure data exchanges with third parties, including validation mechanisms like encryption and mutual authentication. Build confidence in your software’s integrity with these critical best practices!

Logging and Monitoring Failures

05:54

This video explores security logging and monitoring failures, a critical issue that underpins many major security incidents. Attackers exploit insufficient logging and delayed responses to achieve their goals undetected, with vulnerability probing often preceding successful exploits. Learn about the importance of capturing detailed, actionable logs for high-value transactions and the risks of logging sensitive information, which can lead to data breaches if exposed. We also discuss the role of Security Incident and Event Monitors (SIEMs) in aggregating and analyzing logs across systems to detect indicators of compromise and ongoing attacks. Enhance your security posture by implementing robust logging and monitoring practices to detect and respond to threats swiftly.

Server-side Request Forgery

04:12

This video delves into Server-Side Request Forgery (SSRF), a vulnerability that allows attackers to manipulate web applications into making unauthorized requests to internal or external resources. Using examples, we demonstrate how malicious inputs can exploit file upload features or bypass input validation to access sensitive files or execute scripts. Learn prevention techniques, including network segmentation, deny-by-default firewall policies, input validation and sanitization, and using allow lists to restrict server requests to trusted domains. By implementing these measures, you can mitigate SSRF risks and protect your applications from unauthorized access and exploitation.

Mpango wa Masomo wa Kila Wiki
Panga safari yako ya kujifunza
AI hutengeneza ratiba ya kibinafsi kulingana na upatikanaji wako

Mahitaji

Some programming experience

Some familiarity with development practices

Some familiarity with cybersecurity

Watazamaji Walengwa

Some prior programming experience or coding practice

Familiarity with common development processes and workflows

Basic understanding of cybersecurity and security concepts

Kuhusu kozi hii

Every company uses software to function. Whether they are a Fortune 500 technology company or a sole proprietor landscaping company, software is integral to businesses large and small. Software provides a means to track employees, customers, inventory, and scheduling. Data moves from a myriad of systems, networks, and software providing insights to businesses looking to stay competitive. Some of that software used is built within the organization or it is purchased and integrated. What this means is that every organization, regardless of size and industry, has a software need. It enables organizations to move quickly and stay ahead of their competition.


This is where organizations need your help to secure their applications!


In this quick guide to application security and the OWASP Top Ten we will cover what is in the Top Ten. We’ll cover what makes them vulnerabilities and how to protect your application from attacks using these vulnerabilities. Well talk about cryptographic failures, insecure configuration, how to maintain software integrity, what injection attacks are and more!You’ll learn about the terms and security goals that are used in an organization. You’ll learn about some of the basic ways that application security can be brought into the development lifecycle both from a traditional pipeline and from a DevSecOps perspective. I hope you enjoy this brief but key course on AppSec.

Fursa za Kazi na Majukumu Lengwa

Jenga ujuzi wa vitendo unaotakiwa kazini na uhitimu kwa nafasi zenye ushawishi mkubwa duniani

Mtaala Uliotayarishwa kwa Ajira
Majukumu ya Kazi Unayoweza Kuomba

Full Stack Software Engineer

Backend Systems Developer

Frontend Application Specialist

Automation & Scripting Engineer

Mshahara Unaokadiriwa kwa Mwaka
$90,000 – $145,000 / yr
Mahitaji ya Soko Ulimwenguni

High Global Tech Demand

Ujuzi Muhimu Utakaobobea
Production Code Architecture
RESTful & Modern API Design
State Management & UI Scaling
Debugging & Automated Testing
* Makadirio yanatokana na vigezo vya kimataifa vya uajiri wa kiteknolojia.
Kutana na mkufunzi wako
Derek Fisher
5.0 Ukadiriaji
0 Wanafunzi
Tazama Wasifu Kamili
Derek Fisher
Mwalimu Mkuu
Cybersecurity Leader, Author, Educator, & Speaker
Derek Fisher has roughly 30 years of cybersecurity and engineering experience. Derek has worked in industries such as financial, healthcare, military, and commercial over his decades in hardware, software, and cybersecurity engineering. Derek is the author of several books including a children's book series on cybersecurity called Alicia Connected, and the Application Security Program Handbook. His SubStack and YouTube channel continue to contribute to the cybersecurity community. Derek serves as an advisor to Temple University's Cyber DIA program as well as an adjunct professor where he teaches software security to both graduate and undergraduate students. Derek is a regular speaker, panelist, and commentator on a wide range of topics, including product security, vulnerability management, threat modeling, DevSecOps, and cybersecurity career development. Derek is passionate about integrating cybersecurity at the grassroots level by finding partnerships, working with peers and lifting up the next generation of cybersecurity professionals....

Wanafunzi pia walinunua

Wanafunzi waliotazama kozi hii pia walijiandikisha katika kozi hizi zilizopewa alama za juu

Program ESP32 without Coding
Inayouzwa Zaidi
BURE
TEHAMA na Programu | Vifaa

Program ESP32 Board without writing a single code in A Professional Environment

5.0
2 saa 30 dak
18 Lecture
Yote
Using Al to Code: Your Step-by-Step Guide
TEHAMA na Programu | Vifaa

Revolutionize Your Coding Skills with Al: A Comprehensive Guide for Beginners

5.0
2 saa
11 Lecture
Yote
$10.99

$19.99

ISO 27001 Certification Process – A Step-by-Step Guide
TEHAMA na Programu | Usalama wa Habari

Master ISO 27001: Achieve Certification, Build Security, and Ensure Compliance for Your Organization

5.0
1 saa 30 dak
10 Lecture
Mwanzilishi
$39.99

$54.99

Implement GRC (Governance, Risk, Compliance) Step by Step
TEHAMA na Programu | Imethibitishwa katika Utawala, Hatari na Uzingatiaji (CGRC)

Master GRC: Step-by-Step Guide to Implementing Governance, Risk, and Compliance for Business Success

5.0
2 saa 30 dak
35 Lecture
Kati
$39.99

$64.99

Mastering Arduino Data Streaming to Excel
TEHAMA na Programu | Arduino

Seamlessly Stream and Visualize Real-Time Data from Arduino into Excel with Ease

5.0
1 saa 30 dak
6 Lecture
Yote
$9.99

$34.99

Blogger: Make A Professional Website For Free With No Coding
TEHAMA na Programu | Nyingine za IT na Programu

Learn how to create and customize a website with no prior coding experience.

5.0
1 saa 30 dak
12 Lecture
Yote
$9.99

$19.99

Maswali Yanayoulizwa Mara Kwa Mara

Pata majibu kwa maswali ya kawaida kuhusu kozi hii.

Ndiyo! Baada ya kukamilisha 100% ya mihadhara na kazi za kozi, unaweza kupakua Cheti chako cha Dijitali cha Kukamilisha papo hapo moja kwa moja kutoka kwa wasifu wako wa Lucebra.

Gundua zaidi katika Technology

Panua safari yako ya kujifunza kwa vyeti vilivyoidhinishwa, vitabu vya kielektroniki na madarasa ya moja kwa moja.