I HATE OWASP
OWASP TOP 10 IS OUTDATED
Im not crazy, maybe a little delusional but tech is my playground so who is gonna stop me. The coming technology moves at a pace that has never been seen before and majority of this new development is web based. As much as OWASP is the standardized industry format for being able to categorize vulnerabilities. I dont think it is able to keep up with new technology coming up. In my opinion it fails woefully.
I NEVER LIKED THE OWASP TOP 10
Yes its the old industry standard but these days it is way harder to classify and categorize vulnerabilities under this. So much is coming up and its not even being reviewed at all. You see a sloptural (pun intended by the way, whos gonna beat me on my blog) issue with a site and one particular issue cant be used to describe what the issue is. Injection attacks, one of the oldest but still most golden means of wrecking havoc. Ask yourself as a pentester, Red Team Operator, how many times do you find this issue in systems. Close to none , and if you still see those often with the egregious amount of libraries out there built to solve this, jail the damn developer mehn. Well this is biased if we are being honest. I can understand it in new technologies being made but something thats new and hasnt exactly been a thing before, JAIL THE DAMN DEVELOPER.
NEXT DIRECTION ?
This said, where are we headed as a society, my honest take is simple, burn the damn OWASP top 10 and teach people, especially researchers in training which i think is where a lot of people derive cold feet in the real world, you wont find all the vulnerabilities at first glance, you might not even see the vulnerability at all. Ive seen Pentesters go into an engagement with the idea of OWASP top 10 on their mind be it web, api or mobile and i think its just dumb. Instead i think syllabuses should be focused on teaching the structure of vulnerabilities and OWASP TOP 10 just comes in as an additional supportive knowledge to help buttress the point of how vulnerabilities occur and how to hack better, well this is sorta coming from someone who has done a little bit of hacking (Im always scared to call myself experienced).
WHY DO WE NEED THIS REFORM
If you dont know why we need this reform even till now they probably gotta jail you, but since we cant do that, i might as well just explain whats at play here. We are coming to meet a world whose technology is emerging faster than our minds can comprehend and rather than teach the structures through which a bulk of these vulnerabilities come to life, rather than understand the engineering behind these bugs or hacks we are developing a society where only flashy bugs whose engineering isnt properly understood, instead people are just slopping their minds off in the name of hunting.
This doesnt just help me, it helps everyone because once everyone understand the mechanics behind their bugs they are able to discern for themselves the right things to do with these bugs hence reducing the amount of triage time needed in this slop era. i HOPE MY POINTS ARE DRIVEN HOME AND IF THEY ARENT, YOU SHOULD BE IN JAIL TOO.