The release candidate for the OWASP Top Ten for 2010 has been officially released at the OWASP AppSec DC Conference today (Nov 13, 2009). This document is now up for open comment until Dec 31, 2009. The document will be updated and released with a final version in early 2010, hopefully January.
The new additions are:
More information on:
http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project
The new additions are:
- Security Misconfiguration
- Unvalidated Redirects and Forwards- This I was expecting that sometimes it may be included in OWASP Top 10 because the last year itself I had detected many Open Re directions on various reputed sites. Even after reporting to them they were not paying much attention to it. I think now they can think about it as it made a place in Top 10.
More information on:
http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project
Comments