DAY 3 · MODULE 5
OWASP Web Security Risks
Learn common categories of web application weaknesses and their defensive controls.
Understand the concept
Broken access control
Cryptographic failures
Injection
Insecure design
Security misconfiguration
Authentication failures
Integrity failures
Logging failures
SSRF concepts
Why this matters
The OWASP categories help students organize security findings around recurring application-security failure patterns.
See what happens internally
Interactive visualization loads here.
Perform the activity
- Match prepared vulnerable scenarios to OWASP categories.
- For each scenario, select a suitable defensive control.
Workshop safety: Activities involving scanning, web vulnerabilities or security testing must be performed only on the assigned training target or intentionally vulnerable lab.
Read and understand the working example
Think in pairs:
Security weakness -> Defensive controlThis example is shown for guided learning. Real host/network execution is reserved for the isolated cyber-range stage.
Prove your understanding
Classify four prepared web incidents into the most appropriate risk category and justify each answer.