OWASP Top 10

Informational

OWASP Top 10

Definition

The OWASP Top 10 is a reference document published by the Open Web Application Security Project that lists the 10 most critical security-risk categories in web applications. It is updated periodically and is the de facto standard for web security assessment. The 2021 version includes: Broken Access Control, Cryptographic Failures, Injection, Insecure Design, Security Misconfiguration, and more.

Impact

Reference standard for security testing and auditsGuide for prioritizing vulnerabilities in bug bountyRequirement in regulatory compliance (PCI DSS, ISO 27001)Educational baseline for web security trainingFramework for application risk assessment

Examples

OWASP Top 10 - 2021

The 10 categories are: A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable and Outdated Components, A07 Identification and Authentication Failures, A08 Software and Data Integrity Failures, A09 Security Logging and Monitoring Failures, A10 Server-Side Request Forgery (SSRF).

External references

Practice OWASP Top 10 with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime