FYI…

OWASP Top 10 Web Application Security Risks
- http://www.darkreading.com/shared/printabl…cleID=221700095
Nov. 13, 2009 - "The Open Web Application Security Project (OWASP) today released a new top 10 list… Injection attacks top the 2010 OWASP Top 10 list of Web application security threats, including SQL, OS, and LDAP injection, followed by cross-site scripting (XSS), broken authentication and session management, insecure direct object references, cross-site request forgery (CSRF), security misconfiguration, failure to restrict URL access, unvalidated redirects and forwards, insecure cryptographic storage, and insufficient transport layer protection. The list is considered a "release candidate" that will be published in its final form in 2010. New to the list are security misconfiguration and unvalidated redirects and forwards. Security misconfiguration is prevalent today, as is unvalidated redirects and forwards. "The evidence shows that this relatively unknown issue is widespread and can cause significant damage," says the OWASP report. Web redirects typically steer users to other pages and sites, and when the data for the destination pages isn't properly validated, users can be redirected to phishing or malware sites by attackers…"
* http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf

:ph34r: