OWASP Security Testing

OWASP stands for Open Web Applications Security Project, and is an open-source collaboration of web based security tools, technologies and methodologies from industry leaders, educational organisations and individuals from around the world. The aim of OWASP is simple; help people with a useful and clear resource of tools and documents to help understand web application security to better protect themselves online. The OWASP Top 10 2014 has currently not been published however it will likely follow the same principle categories as the previous years results.

What is OWASP Top 10?

OWASP collects data from successful web application attacks and uses this data to produce the OWASP Top 10 statistics. The OWASP Top 10 refers to the top 10 web attacks as seen over the year by security experts, and community contributors to the project.

Security Audit Systems can help

We can test your website or web application against the OWASP Top 10 threats. The latest OWASP top 10 2014 threat list includes the following methods of attack:

A1 Injection
A2 Broken Authentication and Session Management (was formerly 2010-A3)
A3 Cross-Site Scripting (XSS) (was formerly 2010-A2)
A4 Insecure Direct Object References
A5 Security Misconfiguration (was formerly 2010-A6)
A6 Sensitive Data Exposure (2010-A7 Insecure Cryptographic Storage and 2010-A9 Insufficient Transport Layer Protection were merged to form 2013-A6)
A7 Missing Function Level Access Control (renamed/broadened from 2010-A8 Failure to Restrict URL Access)
A8 Cross-Site Request Forgery (CSRF) (was formerly 2010-A5)
A9 Using Components with Known Vulnerabilities (new but was part of 2010-A6 – Security Misconfiguration)
A10 Unvalidated Redirects and Forwards

If you are interested in getting a website OWASP security test to check for the above vulnerabilities get in touch with us. We offer a range of website and OWASP web application security testing services to help mitigate threats to your web facing services and applications. You may wish to consider our website security testing service that checks for all of the OWASP top 10 vulnerabilities.

  • Latest Tweets

    • eBay found to be XSS vulnerable, redirecting users seeking iphones to rogue websites. Slow response time for fix prompts questions.

    • Russian gang dubbed CyberVor Amassed over 4.5 billion stolen credentials claims HoldSecurity