OWASP Top 10 – A05:2021 – Security Misconfiguration
The OWASP Top 10 features the most critical web application security vulnerabilities. In this part, A05: Security Misconfiguration, you’ll identify, exploit, and offer remediation advice for this vulnerability. We also cover XML External Entities. Build your offensive security and penetration testing skills with this one-of-a-kind course!
Course Description
Our newest OWASP courses contain exclusive content updates for the September 2021 version of the OWASP Top 10 list
In the A05-Security Misconfiguration course, you’ll learn more about how to identify misconfigured Jenkins servers using the Shodan search engine. You will also learn about the pervasiveness and severity of XML External Entities. Think like a bug bounty hunter as you exploit and mitigate XXE vulnerabilities.
Our OWASP Top 10 course is designed for an intermediate-level learner, someone who is a seasoned offensive security professional, SOC analyst, or Windows system administrator who wants to know how to exploit and protect against the latest vulnerabilities impacting enterprise systems.
You will gain the most benefit from this course if you have a basic understanding of: web applications, programming languages, web browsers, and web application hacking.
The Open Web Application Security Project (OWASP) is a non-profit organization focused on web security. The OWASP Top 10 features the most critical web application security vulnerabilities. Our course gives you the knowledge needed to identify, exploit, and offer remediation suggestions for these vulnerabilities.
This course is available on the Cybrary platform in a series of installments. Along with an introductory module, each of the subsequent 10 modules are contained separately as installments of the course series. The multimodal design allows for more self-paced, customizable learning. Our on-demand format affords you the flexibility to learn at your own pace.
This course was developed by Clint Kehr, who is a technical manager for a financial services company’s Responsible Disclosure Team, where he interacts with ethical hackers who find vulnerabilities in the company’s infrastructure. Clint is a former Special Agent with the Department of Justice where he specialized in internet investigations and conducted numerous cases on cyber threat actors on the surface, deep, and dark web, resulting in Clint earning the Attorney General’s Distinguished Service Award. Clint has trained over 1,000 law enforcement officers, prosecutors, and civilians on the dark web and dark market websites. Clint has a master’s degree in intelligence studies from American Military University where he graduated with honors and also has a master’s degree in Information Technology from Carnegie Mellon University where he graduated with highest distinction. As a former Navy Reserve Officer, Clint served in many roles, such as a division officer and department head for commands in the information warfare community.
Cybrary is the first cybersecurity platform to release exclusive, updated course content for the new OWASP Top 10 list that was released on September 24th, 2021. The list has been significantly revised since the release of the last 2017 top 10 list, as the new list combines, reorders, and adds new web application vulnerabilities. OWASP has focused on more data-centered research in their creation of the new top 10 list.
Each Cybrary OWASP Top 10 (2021) course includes:
Each Cybrary OWASP Top 10 (2021) course includes:
Engaging video overview lessons that summarize each category and list of CVEs covered, as well as describe how the category in the 2021 list is distinctive from how the category was presented in the 2017 list
Guided demos in platforms such as OWASP Mutillidae
Module 1: Introduction
Module 2: A05-Security Misconfiguration
Module 3: XML External Entities (XXE)