Skip to content
>_ITDITDWeb Security Platform
tag

OWASP

3 articles with this tag

2026-09-05

Password reset design flaws — harden login all you like, this is the way in

A reset flow is a mechanism for letting someone who does not know the password set a new one — which makes it an authentication path in its own right. Harden the login all you like: if reset is weak, reset is your real authentication strength. Five failure shapes: guessable tokens, tokens that never expire, links that live on in a mailbox, links whose destination can be set from outside (Host header), and responses that reveal whether an account exists. The craft is separating what the guidance requires from the numbers it leaves to you.

2026-09-05

Insecure deserialization — the danger is not the data, it is letting the data choose the type

The danger in deserialization is not that bad values arrive; it is that some formats let external data decide which type of object to construct. So the damage does not stop at corrupted data — OWASP lists denial of service, access control bypass and remote code execution. Two defenses: switch to a pure data format so nothing chooses types for you, and sign serialized messages so unsigned ones are never restored. And some mechanisms cannot be made safe by configuration at all; the only fix is not using them.

2026-07-04

What is the OWASP Top 10 — the standard list of the 10 biggest web-app risks

The OWASP Top 10 is a list the non-profit OWASP publishes every few years of the 'most critical web-app risks.' It's a common language for developers and operators. The current edition (2021) is led by Broken Access Control, followed by injection, misconfiguration, vulnerable and outdated components, authentication failures, and more. These are risk CATEGORIES, not individual exploits — use them as a lens to audit your own app.