OWASP¶
The Open Web Application Security Project: resources and guidelines for testing web application security, and the standard methodology for web app engagements.
Why It Matters¶
For any web application work, the OWASP Web Security Testing Guide is the reference methodology, and the Top 10 is the shared vocabulary clients already know. Framing web findings in OWASP terms makes them easy for a development team to understand and act on.
Reference¶
Key Resources¶
| Resource | Use |
|---|---|
| OWASP Top 10 | The most critical web application risks; a shared language for findings |
| Web Security Testing Guide (WSTG) | The step-by-step methodology for testing a web app |
| Cheat Sheet Series | Focused guidance per topic |
| Juice Shop | Deliberately vulnerable app for practice |
| ZAP | OWASP's web app scanner and proxy |
How I Use It¶
I follow the WSTG as the checklist for web app testing so coverage is consistent, and I report findings against the Top 10 categories so developers can map them to guidance they already use. Juice Shop is where I practice techniques before using them on a live target.