From the course: Static Application Security Testing
Unlock the full course today
Join today to access over 24,400 courses taught by industry experts.
A7: Identification and authentication failures - SonarQube Tutorial
From the course: Static Application Security Testing
A7: Identification and authentication failures
- [Presenter] The seventh set of risks in the OWASP top 10 are identification and authentication failures. If an attacker can find a way around the login screen and start interacting with the application or if you can't trust that the person using the app is the person they claim to be then the application is vulnerable to these flaws. With all the data breaches in recent years a lot of valid usernames and passwords have ended up on the dark web. It doesn't take a lot of technical skill for an attacker to download one of these lists and log into your application with a valid user account that belongs to someone else. Default passwords are even worse. Don't believe me? Just Google for the admin guide for some of the older technology in your environment, tech with an administrative web interface, and see if there's a default admin password combo listed in that guide. Even if an attacker doesn't have a valid set of…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
(Locked)
The OWASP Top 103m 26s
-
(Locked)
A1: Broken access controls6m 17s
-
(Locked)
A2: Cryptographic failures7m 29s
-
(Locked)
A3: Injection8m
-
(Locked)
A4: Insecure design5m 21s
-
(Locked)
A5: Security misconfiguration7m 58s
-
(Locked)
A6: Vulnerable and outdated components7m 8s
-
(Locked)
A7: Identification and authentication failures7m 39s
-
(Locked)
A8: Software and data integrity failures5m 49s
-
(Locked)
A9: Security logging and monitoring failures6m 55s
-
(Locked)
A10: Server-Side Request Forgery4m 58s
-
(Locked)
-