Reader small image

You're reading from  CompTIA CASP+ CAS-004 Certification Guide

Product typeBook
Published inMar 2022
PublisherPackt
ISBN-139781801816779
Edition1st Edition
Right arrow
Author (1)
Mark Birch
Mark Birch
author image
Mark Birch

Mark Birch is an experienced courseware developer and teacher in both information systems and cyber-security. Mark has been developing content and teaching CompTIA A+ classes for more than 20 years and understands the subject area in great depth. Mark began his career working within the aerospace industry (for a major defense contractor) and has over 30 years' experience consulting, engineering, and deploying secure information systems. He has spent over 20 years working with the United States Military and United Kingdom Armed Forces, helping many students attain their learning goals. Mark has ensured that soldiers, officers, and civilians have had the best opportunities to gain cyber-security accreditation.
Read more about Mark Birch

Right arrow

Understanding application vulnerabilities

Information systems offer many options to interact with business users and customers. We have public-facing web application servers, business-to-business (B2B) API connectivity requirements, and mobile devices, to name a few. It is important that we eliminate vulnerabilities during the design and development process when rolling out new systems and services. We must also consider the security of legacy applications that may still be required by the business. It is useful to refer to industry best practices when considering application vulnerabilities and the Open Web Application Security Project (OWASP) is a recommended resource:

https://owasp.org/www-project-top-ten/

We will see the various vulnerabilities in the following section.

Race conditions

A race condition, also known as time of check time of use (TOCTOU), is usually associated with a stored value and the use of that stored value. It is a time-related vulnerability that...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
CompTIA CASP+ CAS-004 Certification Guide
Published in: Mar 2022Publisher: PacktISBN-13: 9781801816779

Author (1)

author image
Mark Birch

Mark Birch is an experienced courseware developer and teacher in both information systems and cyber-security. Mark has been developing content and teaching CompTIA A+ classes for more than 20 years and understands the subject area in great depth. Mark began his career working within the aerospace industry (for a major defense contractor) and has over 30 years' experience consulting, engineering, and deploying secure information systems. He has spent over 20 years working with the United States Military and United Kingdom Armed Forces, helping many students attain their learning goals. Mark has ensured that soldiers, officers, and civilians have had the best opportunities to gain cyber-security accreditation.
Read more about Mark Birch