29. OWASP Top 10 Web Vulnerabilities
29.1 What OWASP and the Top 10 Are
In short: OWASP (Open Worldwide Application Security Project) is a non-profit that publishes free security guidance.
OWASP (Open Worldwide Application Security Project) is a non-profit that publishes free security guidance. Its most famous document is the OWASP Top 10 – the ten most critical web application security risks, updated every few years (the current list is from 2021; verify the latest at owasp.org).
The 2021 Top 10:
| # | Category |
|---|---|
| A01 | Broken Access Control |
| A02 | Cryptographic Failures |
| A03 | Injection (SQLi, command injection, XSS) |
| A04 | Insecure Design |
| A05 | Security Misconfiguration |
| A06 | Vulnerable and Outdated Components |
| A07 | Identification and Authentication Failures |
| A08 | Software and Data Integrity Failures |
| A09 | Security Logging and Monitoring Failures |
| A10 | Server-Side Request Forgery (SSRF) |
Ravindra Bagale's Tip
The OWASP Top 10 is not something to memorise – it is something to understand. Interviewers ask "Name the OWASP Top 10", but the real question is "How would you stop SQL injection?". If you know the concept and the fix, the names stick automatically. Every web developer should read this document.
Ravindra Bagale's Tip – मराठी
OWASP Top 10 पाठ करायचे नाही – समजून घ्यायचे. Interview मध्ये "OWASP Top 10 सांगा" विचारतात, पण खरा प्रश्न असतो "SQL injection कसा थांबवशील?". Concept आणि fix माहीत असेल तर नावे आपोआप लक्षात राहतात. हे document प्रत्येक web developer ने वाचले पाहिजे.
Ravindra Bagale's Tip – हिंदी
OWASP Top 10 रटना नहीं है – समझना है. Interview में "OWASP Top 10 बताओ" पूछते हैं, पर असली सवाल होता है "SQL injection कैसे रोकोगे?". Concept और fix पता हो तो नाम अपने-आप याद रहते हैं. यह document हर web developer को पढ़ना चाहिए.
Practice task
Open owasp.org and confirm the current Top 10 list. In your notes, write the ten categories and, beside each, one line in your own words about what it means.