Uploaded by ChRiStIaAn008 on Sep 1, 2010
Clip 1/3
Speaker: Dave Wichers, Aspect Security and OWASP Foundation
This presentation will cover the OWASP Top 10 - 2010 (final version). The OWASP Top 10 was originally released in 2003 to raise awareness of the importance of application security. As the field evolves, the Top 10 needs to be periodically updated to keep with up with the times. The Top 10 was updated in 2004 and the last update was in 2007, where it introduced Cross Site Request Forgery (CSRF) as the big new emerging web application security risk.
This update will be based on more sources of web application vulnerability information than the previous versions were when determining the new Top 10. It will also present this information in a more concise, compelling, and consumable manner, and include strong references to the many new openly available resources that can help address each issue, particularly OWASP's new Enterprise Security API (ESAPI) and Application Security Verification Standard (ASVS) projects.
A significant change for this update will be that the OWASP Top 10 will be focused on the Top 10 Risks to Web Applications, not just the most common vulnerabilities.
For more information click here (http://bit.ly/aeSvg2)
Category:
Tags:
License:
Standard YouTube License
-
0 likes, 0 dislikes
14:58
OWASP AppSec 2010: OWASP Top 10 2010 2/3by ChRiStIaAn008313 views
10:48
OWASP AppSec 2010: OWASP Top 10 2010 3/3by ChRiStIaAn008212 views
2:18
OWASP Top 10 2010: A4 - Insecure Direct Object Referencesby ConvisoITSecurity1,169 views
3:31
OWASP Top 10 2010: A5 - Cross-Site Request Forgery (CSRF)by ConvisoITSecurity971 views
1:18
A4 Insecure Direct Object Referenceby adams775346 views
2:15
OWASP Top 10 2010: A10 - Unvalidated Redirects and Forwardsby ConvisoITSecurity2,072 views
4:25
OWASP Top 10 2010: A3 - Broken Authentication and Session Managementby ConvisoITSecurity1,582 views
1:56
OWASP Top 10 2010: A8 - Failure to Restrict URL Accessby ConvisoITSecurity1,042 views
6:11
OWASP Top 10 2010: A9 - Insufficient Transport Layer Protectionby ConvisoITSecurity1,185 views
14:57
OWASP AppSec 2010: Automated vs. Manual Security: You Can't Filter The Stupid 1/3by ChRiStIaAn008578 views
2:24
owasp top10by pontocom735,928 views
1:50
OWASP Top 10 2010: A6 - Security Misconfigurationby ConvisoITSecurity846 views
1:34
OWASP Top 10 2010: A7 - Insecure Cryptographic Storageby ConvisoITSecurity758 views
5:00
Cross-Site Scripting (XSS) Protection Against XSSby AachenMethodStuff3,957 views
14:58
OWASP AppSec 2010: Automated vs. Manual Security: You Can't Filter The Stupid 2/3by ChRiStIaAn008278 views
6:32
OWASP AppSec 2010: Automated vs. Manual Security: You Can't Filter The Stupid 3/3by ChRiStIaAn008200 views
3:27
OWASP Phishing demoby pontocom73923 views
14:57
OWASP AppSec 2010: Panel Discussion: Is Application Security a Losing Battle? 1/3by ChRiStIaAn00880 views
5:29
OWASP AppSec 2010: Application Security Scoreboard in the Sky 3/3by ChRiStIaAn00837 views
0:37
Faerie's Aire and Death Waltz Quartetby NeoCiabatta233,446 views
- Loading more suggestions...
Link to this comment:
All Comments (0)