Open Issues Need Help
View All on GitHubThe Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Summary: The issue proposes adding a new section to the documentation, specifically under '4.12 API Testing,' to guide users on how to check for sensitive information in API responses. This is crucial because developers sometimes inadvertently expose data like passwords or API keys by serializing entire objects directly into API output. The goal is to prevent security vulnerabilities arising from such exposures.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Summary: This GitHub issue discusses the various browser storage methods (e.g., LocalStorage, SessionStorage, IndexedDB) and their security implications, building on previous discussions and CLNT-12. The core question is whether the OWASP WSTG should provide detailed guidance on these techniques and their security aspects, and if so, how best to integrate this information into the guide.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Summary: This GitHub issue proposes adding a complete Hindi translation for the Web Security Testing Guide (WSTG) to make this critical resource accessible to over 600 million Hindi speakers globally, particularly India's large developer and cybersecurity community. The proposal outlines creating a new branch, translating all chapters, adding a Hindi glossary, and a maintenance plan, highlighting the current absence of any Indian language translations.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Summary: This GitHub issue identifies a minor terminology error in the "Fingerprint Web Server > Sending Malformed Requests" documentation. It incorrectly labels the "HTTP version" part of an HTTP request line (e.g., `HTTP/1.1`) as the "method." The proposed solutions are to either modify the example to clarify the method or correct the text to accurately refer to it as the "HTTP version."
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Summary: The issue proposes enhancing the OWASP Web Security Testing Guide (WSTG) by integrating references to practical labs from OWASP SKF (Security Knowledge Framework). The goal is to link specific SKF lab write-ups, which demonstrate "how to test" for various vulnerabilities, directly within the relevant sections of the WSTG. This would provide WSTG users with hands-on examples and practical exercises to complement the testing methodologies described.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Summary: This GitHub issue points out a misclassification in the WSTG guide, where "Direct Page Request (Forced Browsing)" is currently listed under "Testing for Bypassing Authentication Schema." The author argues that forced browsing isn't always an authentication bypass, as it could simply be accessing an unauthenticated page, which is more akin to information disclosure or access control. The suggestion is to clarify or reclassify this section to improve structural consistency and conceptual accuracy.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
AI Summary: Expand the OWASP Web Security Testing Guide's section on testing payment functionality by adding new test cases focusing on real-world business logic flaws such as race conditions, multi-step confirmation vulnerabilities, cart manipulation, and improper source/destination validation in transfers. This involves researching common payment system vulnerabilities, crafting detailed test cases, and contributing the changes via a pull request to the OWASP WSTG GitHub repository.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.