{"id":13462,"date":"2020-11-05T17:41:03","date_gmt":"2020-11-05T22:41:03","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=13462"},"modified":"2023-04-07T17:22:35","modified_gmt":"2023-04-07T21:22:35","slug":"keep-your-site-safe-with-the-owasp-top-10-list","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/keep-your-site-safe-with-the-owasp-top-10-list\/","title":{"rendered":"Keep Your Site Safe with the OWASP Top 10 List"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-learn-how-the-owasp-top-10-can-help-protect-you-from-the-most-dangerous-security-threats\">Learn How the OWASP Top 10 Can Help Protect You from the Most Dangerous Security Threats<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Web security is an ever-changing field, and the threats never end. If one threat is stopped, it\u2019s only a matter of time until another takes its place. For developers of web applications and sites, the target is always moving as far as what you need to protect against. Whether you\u2019re creating your next big idea or are working to maintain your existing product or business, you\u2019ll certainly want to keep the fruits of your labor protected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But with the sheer number of threats lurking in cyberspace, how do you know which are the most critical and most common? Wouldn\u2019t it be nice if there was a simple list out there that laid them all out for you? Well, today\u2019s your lucky day. That\u2019s because the Open Web Application Security Project (OWASP) has created just that, the OWASP Top 10 list of the biggest threats facing your website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Updated every few years, the list is a widely accepted industry document that is a must-read for anyone running a website. Without it you could be leaving yourself exposed to the most dangerous vulnerabilities, rather than mitigating the risks during development and deployment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What are the top 10 vulnerabilities and how can you properly protect yourself against them? And what is your best course of action if you fall victim to one of them?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-owasp\">What is OWASP?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before we get to the OWASP Top 10, let\u2019s talk about OWASP themselves. The OWASP foundation was founded on December 1, 2001, and they were incorporated as a non-profit organization in the United States on April 21, 2004. In the nearly two decades since their launch, they\u2019ve grown to consist of nearly 32,000 volunteers worldwide. They\u2019re a well-recognized and trusted name in the industry, with over 275 local chapters around the globe.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"223\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/owasplogo.png\" alt=\"OWASP Top 10 List\" class=\"wp-image-13464\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/owasplogo.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/owasplogo-300x107.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">OWASP\u2019s mission since launch has been to improve the security of software. They use an \u201copen community\u201d model, which means that anyone can contribute to their projects, events, webinars, and more. They provide materials and information free of charge, which can be accessed via their website. They produce a wide array of media, including videos, software tools, forums, live and virtual events, and learning resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Basically, OWASP is a repository for anything related to web application security, powered by the diverse knowledge and experience of their open community membership. The group is committed to helping organizations create, develop, deploy, operate, and maintain websites and applications that are safe. In addition to providing an array of articles, methodologies, documentation, and technologies, OWASP\u2019s membership also performs security assessments and research.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What they\u2019re best known for, however, is the OWASP Top 10 list.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-owasp-top-10\">What is the OWASP Top 10?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The OWASP Top 10 list outlines security concerns for websites and web applications. It was first published in 2003 and is usually revised every three to four years as the AppSec market changes and evolves. The list has seen updates in 2004, 2007, 2010, 2013, 2017.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The focus of the OWASP Top 10 list is on the most critical vulnerabilities, examining their risks, impacts, and the best countermeasures to combat them. Compiled by a team of security experts from around the world, the list aims to create awareness of the biggest threats facing organizations. OWASP recommends that all companies incorporate the findings of the report into their security processes and practices so they can minimize the presence of these vulnerabilities in their products.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As for the vulnerabilities themselves, they are judged based on four different criteria:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Prevalence \u2013 how well known is this vulnerability to threat agents (eg. hackers)?<\/li>\n\n\n\n<li>Detectability \u2013 how easy is it for threat agents to discover the vulnerability within an application?<\/li>\n\n\n\n<li>Ease of exploitation \u2013 how easy is it for threat agents to actually exploit the vulnerability once they\u2019ve found it?<\/li>\n\n\n\n<li>Business impact \u2013 how severely will the company operating the application be affected by the exploitation?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When the list was originally created, vulnerabilities were grouped by type so that the authors could cover the most ground. However, that made it more difficult for readers to determine which vulnerabilities were actually the highest priorities since there weren\u2019t any statistics included to quantify them. It thus became a subjective task for the audience since there\u2019s wide variation in application types and threat models depending on the organization. Ultimately, after much debate, OWASP decided to offer a more straightforward top 10 list that they believed was relevant to the widest set of companies (although it\u2019s important to note that the entries are in no particular order).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-importance-of-the-owasp-top-10\">The Importance of the OWASP Top 10<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The most useful aspect of the OWASP Top 10 list lies in the actionable information given within, which helps company focus their security efforts on the most important and effective areas. This has led to the list being adopted as a standard requirement by many of the world\u2019s largest companies (including the PCI-DSS payment processing standards). The failure of an organization to address the items within the OWASP Top 10 is a strong indicator to auditors that they are falling short when it comes to compliance standards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Web application attacks have become the most common cause of confirmed data breaches, per the 2018 Verizon Data Breach Investigations Report. Unfortunately, many organizations still struggle when it comes to creating and maintaining an effective application security program because they just don\u2019t know where to begin. The OWASP Top 10 list can help fill that void, acting as a great starting point since it covers the vulnerabilities that are the most likely to be exploited (and potentially creating data breaches that will be very unpleasant for both your business and customers). By remediating them, you\u2019ll greatly decrease your risk of a costly breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And research shows that sort of action is desperately needed. As you can see below, the passing rate of applications when it comes to OWASP Top 10 policy is still alarmingly low. Perhaps even more worrying is the fact that there is only a slight increase in compliance after an initial OWASP Top 10 vulnerability scan occurs, indicating that most companies aren\u2019t taking the scan results seriously.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"936\" height=\"362\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/scanpercent.png\" alt=\"OWASP Top 10 Pass Rate\" class=\"wp-image-13465\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/scanpercent.png 936w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/scanpercent-300x116.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/scanpercent-768x297.png 768w\" sizes=\"auto, (max-width: 936px) 100vw, 936px\" \/><figcaption class=\"wp-element-caption\">Image Source: Veracode<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Most of the items on the OWASP Top 10 list aren\u2019t super complicated to find and fix, but a disconnect often occurs within organizations because developers are often not well trained in cybersecurity or secure coding practices. Conversely, security teams don\u2019t always have the most accurate idea of what application security actually entails. A one-time scan or pen test of a few critical apps is just not good enough. There must be continuous assessments in place of everything an organization develops or buys, and it must occur in all stages of the lifecycle for it to be effective. Running scans to cover the OWASP Top 10 list is important, but it\u2019s not a magic bullet either. It needs to be an element of a greater company-wide security strategy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now that we\u2019ve covered what the list is and how it should be used, let\u2019s take a closer look at those pesky vulnerabilities!<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-owasp-top-10-vulnerabilities\">The OWASP Top 10 Vulnerabilities<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-injection\">#1 \u2013 Injection<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Injection attacks can happen on things such as databases (SQL, noSQL), operating systems, or servers (via protocols like LDAP). They occur when hostile data is sent to an interpreter as part of a query or command. This data then tricks the interpreter into executing commands that would otherwise be off-limits to an outsider. It can also be used to access private data without proper authentication.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Say you run an ecommerce store, and the way to access a particular item is by entering the following into your browser\u2019s address bar:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>http:\/\/www.yourstore.com\/catalog\/item.asp?itemid=999<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Where \u201c999\u201d generates an SQL query to display whatever item \u201c999\u201d corresponds to. An attacker could manipulate this by entering something like this:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>http:\/\/www.yourstore.com\/items\/item.asp?itemid=999 or 1=1<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The SQL query generated would be:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"146\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/injection1.png\" alt=\"OWASP Top 10 Item 1\" class=\"wp-image-13466\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/injection1.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/injection1-300x70.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><figcaption class=\"wp-element-caption\">Image Source: Imperva<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">But since 1 always equals 1, every product name and description will be returned (even ones that the owner may not want you to see).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You could go a step further by entering:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>http:\/\/www.estore.com\/items\/iteam.asp?itemid=999; DROP TABLE<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The SQL query would now be:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"150\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/injection2.png\" alt=\"OWASP Top 10 Item 1\" class=\"wp-image-13467\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/injection2.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/injection2-300x72.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><figcaption class=\"wp-element-caption\">Image Source: Imperva<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The end result? The deletion of your table!<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Validate and\/or sanitize user-submitted data (validation rejects suspicious entries, and sanitization cleans up the suspicious parts of it)<\/li>\n\n\n\n<li>Set controls to minimize the amount of information that is exposed<\/li>\n\n\n\n<li>Use a safe API that avoids the use of an interpreter<\/li>\n\n\n\n<li>Use SQL controls like LIMIT and others to prevent mass disclosure of records<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-broken-authentication\">#2 \u2013 Broken Authentication<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-1\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Broken authentication refers to instances when authentication and session management functions are implemented incorrectly. Credentials like passwords, keys, or session tokens can be compromised, and flaws can also be used to assume the identities of other users. Attacks can even gain access to an admin account that could compromise the entire system.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-1\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Credential stuffing is an example of a broken authentication attack. This is when attackers use lists of known <a href=\"https:\/\/www.thesslstore.com\/blog\/webauthn-eliminate-passwords\/\">passwords (like those obtained in data breaches) to try and gain access, with the application acting as a validation mechanism for each password attempt<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-1\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use multi-factor authentication<\/li>\n\n\n\n<li>Implement rate limiting to restrict the number of failed login attempts<\/li>\n\n\n\n<li>Don\u2019t use system default credentials<\/li>\n\n\n\n<li>Choose passwords based on the <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-63b.pdf\">NIST 800-63B<\/a> section 5.1.1 standard<\/li>\n\n\n\n<li>Use a built-in server-side session manager<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-sensitive-data-exposure\">#3 \u2013 Sensitive Data Exposure<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-2\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Sensitive data exposure occurs when web applications and APIs fail to properly protect sensitive data like financial or healthcare information. This weakly protected data can be easily stolen by attackers to conduct fraud, identity theft, and other crimes.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-2\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If a website doesn\u2019t use SSL\/TLS for all pages, then an attacker could monitor traffic, change connections from HTTPS to HTTP, and then steal the session cookie to gain access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another example is unsalted hashes. If simple hashes are used to store passwords and an attacker gains access to the database, the hashes can be easily cracked.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-2\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identify sensitive data and apply appropriate controls<\/li>\n\n\n\n<li>Encrypt all sensitive data, both in-transit and at rest<\/li>\n\n\n\n<li>Disable the caching of any sensitive information and do not unnecessarily store any of it<\/li>\n\n\n\n<li>Store passwords using strong, <a href=\"https:\/\/www.thesslstore.com\/blog\/difference-encryption-hashing-salting\/\">salted hashing<\/a> functions such as scrypt, bcrypt, and Argon2<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-4-xml-external-entities-xxe\">#4 \u2013 XML External Entities (XXE)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-3\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This sort of attack targets web applications that parse XML inputs. Older or improperly configured XML processors can end up evaluating external entity references (such as a hard drive) in XML documents. This can fool the XML parser into sending data to an unauthorized external entity, which can then send sensitive data straight to a hacker.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-3\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The following XML code can be used to pull data from a server:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"203\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/xml1.png\" alt=\"OWASP Top 10 XEE\" class=\"wp-image-13468\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/xml1.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/xml1-300x98.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><figcaption class=\"wp-element-caption\">Image Source: Imperva<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">But an attacker could get information about a private network by changing the ENTITY line to the following:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"78\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/xml2.png\" alt=\"OWASP Top 10 XEE\" class=\"wp-image-13469\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/xml2.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/xml2-300x38.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><figcaption class=\"wp-element-caption\">Image Source: Imperva<\/figcaption><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-3\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Patch any old XML parsers<\/li>\n\n\n\n<li>Disable the use of external entities in XML applications<\/li>\n\n\n\n<li>Only allow web applications to accept less complex types of data (like JSON)<\/li>\n\n\n\n<li>Avoid serialization<\/li>\n\n\n\n<li>Validate XML using XSD or other validation tools<\/li>\n\n\n\n<li>Whitelist and sanitize server-side XML inputs<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-5-broken-access-controls\">#5 \u2013 Broken Access Controls<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-4\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This is when restrictions on what authenticated users are permitted\/not permitted to do are improperly enforced. Attacks can then take advantage to gain unauthorized functionality, including accessing and modifying user accounts, sensitive files, user data, access rights, and more.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-4\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Say you have a web application that can accept SQL calls for account information without verification:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"120\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/brokencred1.png\" alt=\"OWASP Top 10 Broken Auth\" class=\"wp-image-13470\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/brokencred1.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/brokencred1-300x58.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><figcaption class=\"wp-element-caption\">Image Source: Imperva<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The \u201cacct\u201d parameter could then be changed to allow access to any account of their choosing:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"84\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/brokencred2.png\" alt=\"OWASP Top 10 Broken Auth\" class=\"wp-image-13471\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/brokencred2.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/brokencred2-300x40.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><figcaption class=\"wp-element-caption\">Image Source: Imperva<\/figcaption><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-4\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Deny access by default for everything but public resources<\/li>\n\n\n\n<li>Create strong access control mechanisms and use them everywhere<\/li>\n\n\n\n<li>Don\u2019t allow users to create, read, or delete any record<\/li>\n\n\n\n<li>Disable server directory listing, and don\u2019t store metadata in the folder root<\/li>\n\n\n\n<li>Log failed access attempts and create alerts<\/li>\n\n\n\n<li>Rate limit API access<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-6-security-misconfiguration\">#6 \u2013 Security Misconfiguration<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-5\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This is the most common vulnerability on the OWASP Top 10 list and is usually the result of using default configurations\/credentials or displaying unnecessarily lengthy error messages. These messages can potentially reveal vulnerabilities within the application.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-5\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">One example would be a database deployed with the vendor-default user credentials. You can\u2019t make it much easier for attackers by having a username of \u201cadmin\u201d and a password of \u201cpassword.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another example would be displaying an error message like the one below:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"416\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/error.png\" alt=\"OWASP Top 10 Security Misconfig\" class=\"wp-image-13472\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/error.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/error-300x200.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">As you can see, details of the application code are revealed, which could be exploited by a nefarious third party. A much simpler error message in plain English would suffice.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-5\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Remove any unused features in the code<\/li>\n\n\n\n<li>Only display general error messages that don\u2019t reveal too much information<\/li>\n\n\n\n<li>Use a Static Application Security Testing (SAST) program to identify information exposure risks from error messages<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-7-cross-site-scripting-xss\">#7 \u2013 Cross-Site Scripting (XSS)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-6\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This type of vulnerability is ultimately a result of weak session management and occurs when web applications let users add custom code to a URL or site that will be displayed to others. A malicious JavaScript code can then be run on their browser.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-6\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A hacker could email someone pretending to be from a trusted bank, including a link to the bank\u2019s website within the email. The link, however, could have malicious code appended to the end of the URL. If the bank\u2019s site isn\u2019t properly secured, then the malicious code will be run in the victim\u2019s browser after they click on it.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-6\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use a web application firewall (WAF), which will employ signature based filtering to identify and block requests from attackers<\/li>\n\n\n\n<li>Use frameworks that escape XSS by design and learn the limitations of their XSS protection so you can handle the cases that aren\u2019t covered<\/li>\n\n\n\n<li>Apply context-sensitive encoding when performing client-side browser document modification<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-8-insecure-deserialization\">#8 \u2013 Insecure Deserialization<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-7\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Serialization is when objects from the application code are converted into a format that can be used for another purpose, like streaming it. Deserialization is the reverse, and it allows hackers to execute malicious code on a server. Even if the vulnerability doesn\u2019t result in remote code execution, attackers can still use them to perform actions such as replay attacks, injection attacks, and privilege escalation attacks.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-7\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">An analogy would be when you\u2019re moving. The serialization is when you pack up the boxes with all your possessions. Deserialization would be when you unpack it at your new place. Insecure deserialization would be if the movers added, removed, and re-arranged items before they were unpacked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As for a real-world example, say a PHP forum uses serialization to save a cookie containing the user\u2019s ID, password, and account level:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"479\" height=\"51\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/ser1.png\" alt=\"OWASP Top 10 Item 8\" class=\"wp-image-13473\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/ser1.png 479w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/ser1-300x32.png 300w\" sizes=\"auto, (max-width: 479px) 100vw, 479px\" \/><figcaption class=\"wp-element-caption\">Image Source: OWASP<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">A hacker could change the serialized object to make themselves an admin:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"452\" height=\"51\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/ser2.png\" alt=\"OWASP Top 10 Item 8\" class=\"wp-image-13474\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/ser2.png 452w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/ser2-300x34.png 300w\" sizes=\"auto, (max-width: 452px) 100vw, 452px\" \/><figcaption class=\"wp-element-caption\">Image Source: OWASP<\/figcaption><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-7\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Monitor deserialization<\/li>\n\n\n\n<li>Implement type checks<\/li>\n\n\n\n<li>Prohibit the deserialization of data from untrusted sources<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-9-using-components-with-known-vulnerabilities\">#9 \u2013 Using Components with Known Vulnerabilities<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-8\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Web developers often use existing components in the applications to avoid redundant work while providing needed functionality. Attackers will look for vulnerabilities within these components that they can leverage to perform attacks on the application itself. Popular components can be used on hundreds of thousands of sites, and a single vulnerability could leave all of them at risk.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-8\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The Equifax breach in 2017 is the perfect example of this type of vulnerability. It was caused by using an Apache Struts version that had an existing vulnerability that was discovered six months before the attack. If only they had read the OWASP Top 10 list first, that could\u2019ve saved them $700 million!<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-8\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Always make sure to have the latest security patches and updates for your components<\/li>\n\n\n\n<li>Remove unused components from your project<\/li>\n\n\n\n<li>Only get components from trusted sources<\/li>\n\n\n\n<li>Use software composition analysis (SCA) tools to identify outdated or insecure components<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-10-insufficient-logging-monitoring\">#10 \u2013 Insufficient Logging &amp; Monitoring<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-is-it-9\">What is it?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Logging and monitoring should be performed routinely to help ensure a website is secure. Failure to do so increases the risk that attacks can occur and can hinder your response time when they do. The average discovery time for a breach is roughly 200 days.&nbsp; This in turn gives attackers quite a bit of time to tamper, extract, or destroy data, move on to other systems, and generally run amok.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-example-9\">Example<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">We talked earlier about credential stuffing, where attackers repeatedly attempt to use leaked username and password pairs.&nbsp; Let\u2019s say after 100 attempts, they finally hit the correct combination for a particular account.&nbsp; Since there was no logging or monitoring in place, no one was ever alerted about the alarmingly high number of login attempts on the account.&nbsp; Otherwise, the activity would\u2019ve been noted as suspicious and the breach could\u2019ve been easily prevented.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-to-protect-yourself-9\">How to Protect Yourself<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Implement logging and monitoring for all aspects of your web application<\/li>\n\n\n\n<li>Create an incident response plan that includes alerts so you are immediately aware of any attacks<\/li>\n\n\n\n<li>Make sure your logs are in a format that can be easily used by centralized log management solutions<\/li>\n\n\n\n<li>Set up your logs so that they contain sufficient context to identify the suspicious accounts<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-coding-against-the-owasp-top-10\">Coding Against the OWASP Top 10<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">First off, your team needs to fully understand the vulnerabilities on the OWASP Top 10 list and avoid coding tools and techniques that could leave you exposed. Coding frameworks that enable developers to find and fix vulnerabilities as they code are your best bet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The best coding practices and tools can\u2019t always protect from human error though, so it\u2019s always good to have extra measures in place such as automated website protection with a WAF. It should ideally be part of a mix of technologies and services at the application layer, which should also include dynamic and static analysis. Static analysis is performed in a non-runtime environment, looking at the application from the inside-out via source code. Dynamic analysis is the opposite and involves manipulating the application during run-time in an effort to locate vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After you have the right coding practices, tools, and security software in place, it all comes down to organizational best practices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-organizational-strategy-to-protect-against-the-owasp-top-10\">Organizational Strategy to Protect Against the OWASP Top 10<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many companies still employ aspects of waterfall development methodology, which leads to the pitfall of waiting until the end of the cycle to perform security checks. This often results in a long list of vulnerabilities being presented to the dev team at the last minute. Time is needed to fix them, which delays releases, creates friction between the dev and security teams, and hurts the business\u2019s bottom line.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In response to this, many companies have looked for ways to keep their code secure every step of the way, starting from the very beginning (and not only do they want to prevent cyberattacks, they also want to prevent the security and dev teams from literally attacking each other). A popular and effective method of accomplishing this is by including security staff in the earlier stages of product development. This sort of cross-pollination lets both sides give their input and learn from the other. Issues with the OWASP Top 10, for example, can be brought up in a lower-stress period where the stakes aren\u2019t as high as they are right before release.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-to-do-if-an-owasp-top-10-vulnerability-is-exploited\">What to Do if an OWASP Top 10 Vulnerability is Exploited?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">All the protection measures and strategies we\u2019ve discussed sound great in theory, but they\u2019re not always the easiest thing to achieve in practice. Security incidents can of course still occur no matter how careful you think you\u2019re being. So, what do you do then if a breach does occur? Time is money, and you\u2019ll be losing both for every second your site is down. Not to mention the negative effect any sort of outage can have on customer trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of your best bets to get back up and running as fast as you can, with as little impact as possible, is to be using a website backup service. Having a backup of your website handy allows you to simply undo any hacks, crashes, malware infections, bad updates, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Automatic backups are best, as its easy to forget to perform manual ones.&nbsp; You\u2019ll also want a service that\u2019s not on your side of the fence.&nbsp; If a hacker gets into your system, there\u2019s a good chance they\u2019ll be able to simply delete your local backups as well.&nbsp; Web hosts often offer backup services, but their functionality is often clunky and limited because it\u2019s focused on server-level backups, not website-level backups.&nbsp; You have to submit a ticket, wait for them to respond, and you can\u2019t select from specific dates or files.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sectigo\u2019s <a href=\"https:\/\/www.thesslstore.com\/codeguard\/backup.aspx\">CodeGuard<\/a> is an example of a website backup solution that ticks all of the above boxes. It tracks all of your website changes and automatically backs up your site\u2019s files and databases every day, as seen below:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"468\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg1.png\" alt=\"OWASP Top 10 CodeGuard Backup\" class=\"wp-image-13475\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg1.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg1-300x225.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">&nbsp;Then, if something does happen, it\u2019s literally a one-click restore process. All you have to do is login and select your latest backup (or whichever you want to use), and you\u2019re back up and running instantly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other nice thing about a service like CodeGuard is that it isn\u2019t simply just a backup program. You also get:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>MalwareGone scanning, which automatically detects and removes malware before it becomes a problem<\/li>\n\n\n\n<li>Email backup service<\/li>\n\n\n\n<li>WordPress plugin for creating automatic backups of WordPress sites<\/li>\n\n\n\n<li>Website Migration Tool to quickly and easily move your site<\/li>\n\n\n\n<li>Staging servers to test old backups<\/li>\n\n\n\n<li>Full-Featured API to customize the CodeGuard experience for you or your customers<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">It works with any major website platform and its easy-to-use interface lets you configure it all in less than 5 minutes. First, you set the root directory of your site (or if you\u2019re using the WordPress plugin, you simply install it and enter a one-time key):<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"491\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg2.png\" alt=\"OWASP Top 10 CodeGuard Backup\" class=\"wp-image-13476\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg2.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg2-300x236.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Then, you set your backup preferences:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"518\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg3.png\" alt=\"OWASP Top 10 CodeGuard Backup\" class=\"wp-image-13477\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg3.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg3-300x249.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">And CodeGuard does the rest. Then, if you need to restore later on, it\u2019s a fast and straightforward process:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"626\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg4.png\" alt=\"OWASP Top 10 CodeGuard Backup\" class=\"wp-image-13478\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg4.png 624w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/cg4-300x300.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Within seconds, your website will be back to it\u2019s previous state.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\" style=\"font-size:23px\"><span class=\"color\" style=\"color:#F07725\"><strong>Protect Your Site With CodeGuard Backup<\/strong><\/span><\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<img loading=\"lazy\" decoding=\"async\" src=\"\/content\/images\/cg-vertical-logo.svg\" alt=\"CodeGuard Logo\" width=\"200\" height=\"111\" style=\"display: block;margin-left: auto;margin-right: auto;\">\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p class=\"wp-block-paragraph\">It&#8217;s like an undo button to reverse damage done by a mistake, cyber attack, a bad update, or other issues.<\/p>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-background has-central-palette-7-background-color no-border-radius\" href=\"https:\/\/www.thesslstore.com\/codeguard\/backup.aspx\">Explore CodeGuard Backup<\/a><\/div>\n<\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n<\/div><\/div>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-owasp-top-10-a-valuable-tool-in-your-security-arsenal\">The OWASP Top 10 \u2013 A Valuable Tool in Your Security Arsenal<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As we\u2019ve seen, the OWASP Top 10 acts as an excellent baseline for your security measures. Protecting against the items on the OWASP Top 10 should be the bare minimum really, and ideally the first step to a more comprehensive security framework for your company. By protecting yourself against the most common vulnerabilities, you\u2019re drastically and immediately lowering your risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then, combine that with proper AppSec and organizational best practices to set yourself up for the long term. No matter where you\u2019re at in the process though, breaches are always possibility. You\u2019ll want to have a contingency plan in place, such as CodeGuard, that will get you back online as soon as possible. Like a security system for your house, it\u2019s the sort of thing you hope will never be called in to use. But if it is, you\u2019ll be very glad you had it!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn How the OWASP Top 10 Can Help Protect You from the Most Dangerous Security Threats Web security is an ever-changing field, and the threats never end. If one threat&#8230;<\/p>\n","protected":false},"author":37,"featured_media":13463,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,130,16],"tags":[],"class_list":["post-13462","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-everything-encryption","category-hashing-out-cyber-security","post-without-tags"],"views":30817,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/11\/bigstock-125417255.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=13462"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13462\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/13463"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=13462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=13462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=13462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}