• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

OWASP Top 10 Update: Long Overdue Or Same-Old, Same-Old?

April 12, 2017 by Mengqi He 1 Comment

This week, OWASP released a working draft of its latest OWASP Top 10 vulnerabilities list. This is the first time that changes were made on this industry benchmark list in four years, even though many of the vulnerabilities remain the same. OWASP Top 10 is designed to help developers, designers, architects and business owners avoid risks associated with the most common vulnerabilities and provide standards for prioritizing vulnerability mitigation. The greatest change of 2017 Top 10 is the addition of application programing interfaces (APIs), and it could potentially help raise more awareness about API security. However, some would think that the Top 10 list is not evolving quickly enough to keep up with the pace of the changes in how software is delivered, and thus unable to cover the changing trends. On the other side, some think that there’s no need to update the list every year because the strong similarities mean that the trend does not change that quickly.

Link: http://www.darkreading.com/application-security/owasp-top-10-update-long-overdue-or-same-old-same-old/d/d-id/1328608

 

 

Filed Under: Week 12 Tagged With:

Reader Interactions

Comments

  1. Mauchel Barthelemy says

    April 14, 2017 at 7:04 pm

    I would rather agree that the list should be updated every year because it would be better to stay ahead of hackers for no major reasons than operating under risk of ethical hackers not evolving enough. There should never be a good reason to be one step behind of cyber criminals.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in