Chapter 12: Miscellaneous Vulnerabilities
The OWASP Top 10 is the de facto standard for lists used by security professionals to learn about the most common web application vulnerabilities. It is one of the flagship projects by the Open Web Application Security Project (OWASP) organization. As you may have noticed, chapters 2-11 of this book covered each of the 2017 OWASP Top 10 security risks. This report changes every 3 to 4 years, depending on the information collected by security experts in OWASP. New or old risks may be introduced or removed from this collection, but this document is not a complete list, and there are other vulnerabilities that are not covered. This chapter will talk about a few more of the existing risks, some of which are no longer a part of the OWASP Top 10 but are still critical to know.
In this chapter, we're going to cover the following recipes:
- Fixing the disabled anti-Cross-Site Request Forgery protection
- Preventing Server-Side Request...