Showing posts with label owasp. Show all posts
Showing posts with label owasp. Show all posts

How to speed up OWASP ZAP scans

So you’ve used OWASP ZAP to scan your web application, and its taking far too long? Is that it, do you have to lump it or leave it? There are actually many things you can do, but the first thing you have to do is work out whyits taking a long time.

https://blog.mozilla.org/security/2013/07/10/how-to-speed-up-owasp-zap-scans/
Speeding up OWASP


How Scanners work:

It helps to understand how scanners like ZAP work.
Typically they explore the application using a spider (also known as a crawler). This identifies all of the URLs that make up the application, all of the forms and all of the parameters.
They then usually attack every parameter on every page.

How to speed up OWASP ZAP scans | Mozilla Security Blog

OWASP Top Ten for 2013 released

The OWASP Top Ten provides a powerful awareness document for web application security. The OWASP Top Ten represents a broad consensus about what the most critical web application security flaws are. Project members include a variety of security experts from around the world who have shared their expertise to produce this list.

OWASP Top Ten for 2013:
  1. Injection
  2. Broken Authentication and Session Management CHANGED
  3. Cross-Site Scripting (XSS) CHANGED
  4. Insecure Direct Object References
  5. Security Misconfiguration CHANGED
  6. Sensitive Data Exposure CHANGED
  7. Missing Function Level Access Control CHANGED
  8. Cross-Site Request Forgery (CSRF) CHANGED
  9. Using Known Vulnerable Components NEW
  10. Unvalidated Redirects and Forwards