Below you will find list of top 10 web vulnerabilities classified by OWASP, here is also description of the problem and some examples. I will just give you the list in case you missed it before, i will not comment on any of these as there is already hot discussion about this matter on several sites/forums. So here it starts: 1. Cross site scripting (XSS) The problem: The “most prevalent and pernicious” Web application security vulnerability, XSS flaws happen when an application sends user data to a Web browser without first validating or encoding the content. This lets hackers execute malicious scripts in a browser, letting them hijack user sessions, deface Web sites, insert hostile content and conduct phishing and malware attacks. Attacks are usually executed with JavaScript, letting hackers manipulate any aspect of a page. In a worst-case scenario, a hacker could steal information and impersonate a user on a bank’s Web site, according to Snyder. Real-world example: PayPal was targete...
Comments