A beginner with 10+ years of Software Industry experience
Work I've done in my free time!
Dreaming big. Breaking rules. Creating awareness.
https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
File Inclusion
Server-Side Request Forgery (SSRF)
Data Exfiltration
Remote Code Execution (RCE)
JWT Validation Bypass
OAuth 2.0 Security Misconfigurations
Session Fixation via HTTP Header Injection
Cross-Site Request Forgery (CSRF)
Insecure Direct Object Reference (IDOR)
Parameter Tampering
https://jwt.io/
Of Untrusted User Input
Missing/Broken Cryptography
Hardcoded Secrets in JavaScript Files
Verbose Error Messages
Verbose Server Responses
Missing Security Headers
Missing Rate Limiting
Weak Password Policy
Use of Default Credentials
Missing Server Side Validations
Permission Issue