
Product Announcements — shinksmon (Veracode, Inc.) asked a question.
This month, we’ve added three new labs:
- OWASP API #4 Lack of Resources & Rate Limiting- Denial of Service (DoS) for .NET
- OWASP #1 Broken Access Control - Loose Lips Sink Servers for JavaScript
- OWASP #4 Insecure Design - Valid Deficit for .NET
If APIs don’t impose any restrictions on the size or number of resources that can be requested, it opens the door for Denial of Service attacks, poor API server performance, and authentication flaws such as brute force. The OWASP API #4 lab covers Denial of Service and how to avoid it.
OWASP #1 Broken Access Control - Loose Lips Sink Servers for JavaScript covers how information leakage can lead to the exposure of sensitive data.
Similar to last month’s release, the new OWASP #4 Insecure Design - Valid Deficit covers insufficient validation of user data, but with a focus on .NET. The Security Labs Course Catalog is updated to reflect these changes.
.png)