4 ms·
Obligatory link to the 2010 list of the top 10 risks: http://www.owasp.org/index.php/Top_10_2010-Main http://www.owasp.org/index.php/Top_10_2010-Main Interesti
by rdj 16y ago
Obligatory link to the 2010 list of the top 10 risks: http://www.owasp.org/index.php/Top_10_2010-Main http://www.owasp.org/index.php/Top_10_2010-Main
Interesting how many items are still there from 2004 to 2007 to 2010.
- JabavuAdams 16y agoArgh, didn't see that. Thanks.
- Locke1689 16y agoIIRC, I think I analyzed and organized those pages in 2007. Looks like the big ones (XSS, injection) are still pretty much the same. In fact, looks like most of my work is pretty much the same, but some shiny new graphics have been added. :) You'd be surprised at the number of pages I come across that still have these basic insecurities. Thankfully, automatic checking is making really basic CSRF attacks less prevalent. I'm sure tptacek or someone more familiar with the current hotlist would have more to say, though.