Introduction: Misconceptions- Security: The Complete Picture
- Seven Deadly Assumptions
- Anthem, Sony, Target, Heartland, and TJX Debriefs
- Causes of Data Breaches
- Meaning of Being Compliant
- Verizons 2015 Data Breach Report
- 2015 PCI Compliance Report
Lesson: Security Concepts- Motivations: Costs and Standards
- Open Web Application Security Project
- Web Application Security Consortium
- CERT Secure Coding Standards
- Assets are the Targets
- Security Activities Cost Resources
- Threat Modeling
- System/Trust Boundaries
Lesson: Principles of Information Security- Security Is a Lifecycle Issue
- Minimize Attack Surface Area
- Layers of Defense: Tenacious D
- Compartmentalize
- Consider All Application States
- Do NOT Trust the Untrusted
Lesson: Unvalidated Input- Buffer Overflows
- Integer Arithmetic Vulnerabilities
- Unvalidated Input: From the Web
- Defending Trust Boundaries
- Whitelisting vs Blacklisting
Lesson: Overview of Regular Expressions- Regular Expressions
- Working With Regexes in Java
- Applying Regular Expressions
Lesson: Broken Access Control- Access Control Issues
- Excessive Privileges
- Insufficient Flow Control
- Unprotected URL/Resource Access
- Examples of Shabby Access Control
- Session and Session Management
Lesson: Broken Authentication- Broken Quality/DoS
- Authentication Data
- Username/Password Protection
- Exploits Magnify Importance
- Handling Passwords on Server Side
- Single Sign-on (SSO)
Lesson: Cross Site Scripting (XSS)- Persistent XSS
- Reflective XSS
- Best Practices for Untrusted Data
Lesson: Injection- Injection Flaws
- SQL Injection Attacks Evolve
- Drill Down on Stored Procedures
- Other Forms of Injection
- Minimizing Injection Flaws
Lesson: Error Handling and Information Leakage- Fingerprinting a Web Site
- Error-Handling Issues
- Logging In Support of Forensics
- Solving DLP Challenges
Lesson: Insecure Data Handling- Protecting Data Can Mitigate Impact
- In-Memory Data Handling
- Secure Pipes
- Failures in the SSL Framework Are Appearing
Lesson: Insecure Configuration Management- System Hardening: IA Mitigation
- Application Whitelisting
- Least Privileges
- Anti-Exploitation
- Secure Baseline
Lesson: Direct Object Access- Dynamic Loading
- Direct Object References
Lesson: Spoofing and Redirects- Name Resolution Vulnerabilities
- Fake Certs and Mobile Apps
- Targeted Spoofing Attacks
- Cross Site Request Forgeries (CSRF)
- CSRF Defenses are Entirely Server-Side
- Safe Redirects and Forwards
Lesson: Understanding Whats Important- Common Vulnerabilities and Exposures
- OWASP Top Ten for 2013
- CWE/SANS Top 25 Most Dangerous SW Errors
- Monster Mitigations
- Strength Training: Project Teams/Developers
- Strength Training: IT Organizations
Lesson: Defending XML- XML Signature
- XML Encryption
- XML Attacks: Structure
- XML Attacks: Injection
- Safe XML Processing
Lesson: Defending Web Services- Web Service Security Exposures
- When Transport-Level Alone is NOT Enough
- Message-Level Security
- WS-Security Roadmap
- XWSS Provides Many Functions
- Web Service Attacks
- Web Service Appliance/Gateways
Lesson: Defending Rich Interfaces and REST- How Attackers See Rich Interfaces
- Attack Surface Changes When Moving to Rich Interfaces
- Bridging and its Potential Problems
- Three Basic Tenets for Safe Rich Interfaces
- OWASP REST Security Recommendations
Lesson: SDL Process Overview- Software Security Axioms
- Security Lifecycle Phases
Lesson: Applying Processes and Practices- Awareness
- Application Assessments
- Security Requirements
- Secure Development Practices
- Security Architecture/Design Review
- Security Code Review
- Configuration Management and Deployment
- Vulnerability Remediation Procedures
Lesson: Risk Analysis- Threat Modeling Process
- 1. Identify Security Objectives
- 2. Describe the System
- 3. List Assets
- 4. Define System/Trust Boundaries
- 5. List and Rank Threats
- 6. List Defenses and Countermeasures
Lesson: Testing Tools and Processes- Security Testing Principles
- Black Box Analyzers
- Static Code Analyzers
- Criteria for Selecting Static Analyzers
Lesson: Testing Practices- OWASP Web App Penetration Testing
- Authentication Testing
- Session Management Testing
- Data Validation Testing
- Denial of Service Testing
- Web Services Testing
- Ajax Testing
, Lesson: Why Hunt Bugs
The Language of Cybersecurity
The Changing Cybersecurity Landscape
AppSec Dissection of SolarWinds
The Human Perimeter
Interpreting the Verizon Data Breach Investigation Report
First Axiom in Web Application Security Analysis
First Axiom in Addressing ALL Security Concerns
Lab: Case Study in Failure
Lesson: Safe and Appropriate Bug Hunting/Hacking
Working Ethically
Respecting Privacy
Bug/Defect Notification
Bug Bounty Programs
Bug Hunting Mistakes to Avoid
Session: Moving Forward From Hunting Bugs
Lesson: Removing Bugs
Open Web Application Security Project (OWASP
OWASP Top Ten Overview
Web Application Security Consortium (WASC)
CERT Secure Coding Standards
Microsoft Security Response Center
Software-Specific Threat Intelligence
Session: Foundation for Securing Web Applications
Lesson: Principles of Information Security
Security Is a Lifecycle Issue
Minimize Attack Surface Area
Layers of Defense: Tenacious D
Compartmentalize
Consider All Application States
Do NOT Trust the Untrusted
AppSec Dissection of the Verkada Exploit
Session: Bug Stomping 101
Lesson: Unvalidated Data
Buffer Overflows
Integer Arithmetic Vulnerabilities
Defining and Defending Trust Boundaries
Rigorous., Positive Specifications
Whitelisting vs Blacklisting
Challenges: Free-Form Text, Email Addresses, and Uploaded Files
Lesson: A01: Broken Access Control
Elevation of Privileges
Insufficient Flow Control
Unprotected URL/Resource Access/Forceful Browsing
Metadata Manipulation (JWTs)
CORS Misconfiguration Issues
Cross Site Request Forgeries (CSRF)
CSRF Defenses
Lab: Spotlight: Verizon
Lesson: A02: Cryptographic Failures
Identifying Protection Needs
Evolving Privacy Considerations
Options for Protecting Data
Transport/Message Level Security
Weak Cryptographic Processing
Keys and Key Management
NIST Recommendations
Lesson: A03: Injection
Injection Flaws
SQL Injection Attacks Evolve
Drill Down on Stored Procedures
Other Forms of Server-Side Injection
Minimizing Injection Flaws
Client-side Injection: XSS
Persistent, Reflective, and DOM-Based XSS
Best Practices for Untrusted Data
Lesson: A04: Insecure Design
Secure Software Development Processes
Shifting Left
Cost of Continually Reinventing
Leveraging Common AppSec Practices and Control
Paralysis by Analysis
Actionable Application Security
Additional Tools for the Toolbox
Lab: Actionable AppSec
Lesson: A05: Security Misconfiguration
System Hardening
Risks with Internet-Connected Resources (Servers to Cloud)
Minimalist Configurations
Application Whitelisting
Secure Baseline
Segmentation with Containers and Cloud
Lab: Configuration Guidance
Resolution of External References
Safe XML Processing
Session: Bug Stomping 102
Lesson: A06: Vulnerable and Outdated Components
Vulnerable Components
Software Inventory
Managing Updates: Balancing Risk and Timeliness
AppSec Dissection of Ongoing Microsoft Exchange Exploits
Lab: Spotlight: Equifax
Lesson: A07: Identification and Authentication Failures
Quality and Protection of Authentication Data
Proper hashing of passwords
Handling Passwords on Server Side
Session Management
HttpOnly and Security Headers
Lesson: A08: Software and Data Integrity Failures
Serialization/Deserialization
Issues with Consuming Vulnerable Software
Using Trusted Repositories
CI/CD Pipeline Issues
Protecting Software Development Resources
Lesson: A09: Security Logging and Monitoring Failures
Detecting Threats and Active Attacks
Best Practices for Determining What to Log
Safe Logging in Support of Forensics
Lab: Auditing and Logging Guidance
Lesson: A10: Server-Side Request Forgery (SSRF)
Understanding SSRF
Remote Resource Access Scenarios
Complexity of Cloud Services
SSRF Defense in Depth
Positive Allow Lists
Session: Moving Forward
Lesson: Applications: What Next
Common Vulnerabilities and Exposures
CWE/SANS Top 25 Most Dangerous SW Errors
Strength Training: Project Teams/Developers
Strength Training: IT Organizations
Lab: Spotlight: Capital One
Optional / Bonus Content
Bonus Chapter: Leveraging AI in Web Application Security Development
Introduction to AI in Web Application Security
AI-Powered Threat Detection
AI for Secure Coding
AI in Authentication and Access Control
AI in Incident Response
Challenges and Ethical Considerations in AI for Security