- Practical Web Penetration Testing
- Gus Khawaja
- 143字
- 2021-06-25 20:53:49
OWASP Top 10
The Open Web Application Security Project (OWASP) is a community dedicated to helping people and organizations with application security topics. If you'll be working as an AppSec expert, then OWASP should be your bible; they have plenty of help sections that will make your life much easier. Just follow their guidelines and tutorials at http://www.owasp.org.
The OWASP community defined the Top 10 vulnerabilities related to web applications. As for Mutillidae, it dedicated a menu to these vulnerabilities. On the left menu, you will see the OWASP items organized by year (the latest is the OWASP Top 10 for 2017; see the following screenshot). OWASP always keeps this list updated with the latest web vulnerabilities:
![](https://epubservercos.yuewen.com/97ABE4/19470392301559806/epubprivate/OEBPS/Images/Chapter_74.jpg?sign=1739226800-EE5hZphkM2hwKZn7HImcUxyWxIXMbO87-0-046159fcfee1743471e55e94ab0de157)
I have dedicated a whole chapter to these vulnerabilities, later in this book. For the time being, try to get familiar with the menu items.