• manicode Profile Picture

    Jim Manico from Manicode Security @manicode

    4 years ago

    Manicode AppSec Top Ten 1) Lack of Security Testing 2) Insecure 3rd Party Libs 3) SSRF 4) SQL & Other Forms of Injection 5) Access Control Issues 6) XSS 7) AuthN Issues 8) Lack of AppSec Dev Champions 9) Lack of Secrets Management 10) Poorly configured HTTPS

    12 32 128 0 16
  • liran_tal Profile Picture

    Liran Tal @liran_tal

    4 years ago

    @manicode I like that list and how it balances tooling with culture. I'd replace (10) with general misconfiguration to also include infrastructure misconfiguration like open S3 buckets, etc.

    0 1 4 0 0
  • ctxt Profile Picture

    Jeremy Long @ctxt

    4 years ago

    @manicode For me this is missing weak/missing inventory management... while this doesn't seem appsec on the surface it is a huge issue that affects appsec... XSS and "other forms of injection" are the same. You can't secure what you don't know you have.

    2 0 9 0 0
  • rvandenbrink Profile Picture

    Rob VandenBrink @rvandenbrink

    4 years ago

    @manicode Good list! I’d add “poor or no application maintenance” and (in the extreme) “forgetting that app was even there” to the list, both somewhere near the top. Too many dev teams treat each app as a one-time project instead of as a continuing obligation.

    1 1 3 0 0
  • laraghavan Profile Picture

    𝐋𝐚𝐤𝐬𝐡 𝐑𝐚𝐠𝐡𝐚𝐯𝐚𝐧 @laraghavan

    4 years ago

    @manicode The list has stuff at different zoom levels. But, I’ll just caution against over reliance on #1 (many AppSec programs are just that):

    0 1 2 0 0
  • thatsjet Profile Picture

    Code Doctor @thatsjet

    4 years ago

    @manicode #1 - lack of developer training

    1 0 3 0 0
  • derekschatz Profile Picture

    Derek @derekschatz

    4 years ago

    @manicode To build on 1), even when there is testing, it’s a lack of support to actually fix the problems that are found.

    1 0 2 0 0
  • foreverof_ns Profile Picture

    Nick Silver @foreverof_ns

    4 years ago

    @manicode Nice Jim! Wrt to 2- any advice on dealing with vulns in indirect dependencies? Feels like this problem is particularly painful in node land

    1 0 1 0 0
  • _jACK_t_Ripper_ Profile Picture

    the_jACK_Ripper @_jACK_t_Ripper_

    4 years ago

    @manicode So with node.js there are plenty of 3rd party dependencies, and supply chain vulnerabilities. For me most node.js use is through my app.js and run client side, but i do run a socket.io server for which I use a middleware for validation on the WS. Any suggestions.

    1 0 1 0 0
  • richardcardona Profile Picture

    Richard Cardona @richardcardona

    4 years ago

    @manicode Extra credit: assign a weight to each that adds up to 100. Exercise left to the reader

    0 0 0 0 0
  • deckarts Profile Picture

    /𝔡𝔢𝔱/𝔩𝔢𝔣𝔣 ᛑᛂᛐᛛᛂᚡ @deckarts

    4 years ago

    @manicode

    0 0 0 0 0
    Download Gif
  • Download Image
    • Privacy
    • Term and Conditions
    • About
    • Contact Us
    • TwStalker is not affiliated with X™. All Rights Reserved. 2024 www.instalker.org

    twitter web viewer x profile viewer bayigram.com instagram takipçi satın al instagram takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al sosyalgram takipçi satın al instagram ücretsiz takipçi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al metin2 metin2 wiki metin2 ep metin2 dragon coins metin2 forum metin2 board popigram instagram takipçi satın al takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al buyfans buy instagram followers buy instagram likes buy instagram views buy tiktok followers buy tiktok likes buy tiktok views buy twitter followers buy telegram members Buy Youtube Subscribers Buy Youtube Views Buy Youtube Likes forstalk postegro web postegro x profile viewer