contentintech

OWASP Top 10 Cheatsheet

Quick reference for the OWASP Top 10 — each category with its cause, example, and one-line fix.

OWASPInjectionAccess ControlAppSec
NotesCheatsheet

OWASP Top 10 (2021) — Cause → Fix

Category Typical cause One-line fix
A01 Access ControlClient-trusted IDsDeny by default; scope queries to user
A02 Crypto FailuresWeak/no cryptoTLS 1.3, Argon2id, AES-GCM
A03 InjectionInput as codeParameterized queries
A04 Insecure DesignNo threat modelThreat model + abuse cases
A05 MisconfigurationDefaults/verbose errorsHardened baseline via IaC
A06 Vuln ComponentsOutdated depsSBOM + CI dependency scan
A07 Auth FailuresWeak creds/no limitsMFA + rate limiting
A08 Integrity FailuresUnsigned code/deser.Sign + verify; lock deps
A09 Logging FailuresNo visibilityCentral logs + alerting
A10 SSRFUnvalidated URL fetchAllowlist + block internal IPs

Injection & Access Control Cluster

Detect

Error/timing changes on ', --, quotes
Sequential/guessable IDs in URLs & bodies
Same endpoint returns other users' data by ID swap
Hidden admin routes reachable without role check

Prevent

Parameterized queries / safe ORM everywhere
Server-side authz on every request; deny by default
Allowlist input validation; least privilege DB user
Automated owner/non-owner access tests in CI

Crypto, Auth & Integrity Cluster

Detect

HTTP / mixed content; missing HSTS
No account lockout / rate limit on login
Unsigned updates; deserialization of user data

Prevent

TLS 1.3 + HSTS; Argon2id password hashing
MFA, breach-list checks, rate limiting/backoff
Sign artifacts; pin deps with integrity hashes
Never deserialize untrusted data; use JSON + schema

Parameterized Queries

Node (pg / mysql2)

db.query('SELECT * FROM users WHERE email = $1', [email]);   // pg
conn.execute('SELECT * FROM users WHERE id = ?', [id]);       // mysql2

Python

cur.execute("SELECT * FROM users WHERE email = %s", (email,))
# Django ORM: User.objects.filter(email=email) is safe by default

Java (PreparedStatement)

PreparedStatement ps = conn.prepareStatement(
    "SELECT * FROM users WHERE email = ?");
ps.setString(1, email);

SSRF Guard

const ALLOWED = new Set(['images.example.com']);
const u = new URL(userUrl);
if (u.protocol !== 'https:' || !ALLOWED.has(u.hostname)) reject();
// Resolve DNS, reject 127.0.0.0/8, 10/8, 172.16/12, 192.168/16,
// 169.254.169.254 (metadata). Disable redirects. Require IMDSv2.

Vuln → Lab Tool Mapping

Vulnerability Find it in a lab with
SQL / injectionJuice Shop, sqlmap (own lab), Burp Repeater
Broken access / IDORWebGoat, PortSwigger Academy, Burp (compare users)
Vulnerable componentsnpm audit, osv-scanner, Dependency-Check
Misconfiguration / headersOWASP ZAP, nikto, browser DevTools
SSRFPortSwigger SSRF labs, Burp Collaborator
Auth / sessionDVWA, WebGoat, Burp Sequencer

Authorized use only

Run these tools only against intentionally vulnerable apps you host or targets you are explicitly authorized to test. Never point them at third-party systems.

Section navigation