A5:2017-BrokenAccessControlA1:2013-InjectionA1:2017-InjectionA6:2013-SensitiveDataExposureC2:2018-LeverageSecurityFrameworksand LibrariesA3:2017-SensitiveDataExposureC9:2018-ImplementSecurityLogging andMonitoringA3:2013-Cross-SiteScripting(XSS)A4:2017-XMLExternalEntities(XXE)C1:2018-DefineSecurityRequirementsA8:2017-InsecureDeserializationA6:2017-SecurityMisconfigurationA9:2013-UsingComponentswith KnownVulnerabilitiesA2:2013-BrokenAuthenticationand SessionManagementC5:2018-ValidateAll InputsA7:2013-MissingFunctionLevel AccessControlA4:2013-InsecureDirect ObjectReferencesA2:2017-BrokenAuthenticationC10:2018-Handle allErrors andExceptionsC4:2018-Encode andEscape DataC6:2018-ImplementDigitalIdentityA5:2013-SecurityMisconfigurationC3:2018-SecureDatabaseAccessA8:2013-Cross-SiteRequestForgery(CSRF)A7:2017-Cross-SiteScripting(XSS)A9:2017-UsingComponentswith KnownVulnerabilitiesC8:2018-ProtectDataEverywhereA10:2013-UnvalidatedRedirectsandForwardsA10:2017-InsufficientLogging &MonitoringC7:2018-EnforceAccessControlsA5:2017-BrokenAccessControlA1:2013-InjectionA1:2017-InjectionA6:2013-SensitiveDataExposureC2:2018-LeverageSecurityFrameworksand LibrariesA3:2017-SensitiveDataExposureC9:2018-ImplementSecurityLogging andMonitoringA3:2013-Cross-SiteScripting(XSS)A4:2017-XMLExternalEntities(XXE)C1:2018-DefineSecurityRequirementsA8:2017-InsecureDeserializationA6:2017-SecurityMisconfigurationA9:2013-UsingComponentswith KnownVulnerabilitiesA2:2013-BrokenAuthenticationand SessionManagementC5:2018-ValidateAll InputsA7:2013-MissingFunctionLevel AccessControlA4:2013-InsecureDirect ObjectReferencesA2:2017-BrokenAuthenticationC10:2018-Handle allErrors andExceptionsC4:2018-Encode andEscape DataC6:2018-ImplementDigitalIdentityA5:2013-SecurityMisconfigurationC3:2018-SecureDatabaseAccessA8:2013-Cross-SiteRequestForgery(CSRF)A7:2017-Cross-SiteScripting(XSS)A9:2017-UsingComponentswith KnownVulnerabilitiesC8:2018-ProtectDataEverywhereA10:2013-UnvalidatedRedirectsandForwardsA10:2017-InsufficientLogging &MonitoringC7:2018-EnforceAccessControls

Stash OWASP Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
  1. A5:2017-Broken Access Control
  2. A1:2013-Injection
  3. A1:2017-Injection
  4. A6:2013-Sensitive Data Exposure
  5. C2:2018-Leverage Security Frameworks and Libraries
  6. A3:2017-Sensitive Data Exposure
  7. C9:2018-Implement Security Logging and Monitoring
  8. A3:2013-Cross-Site Scripting (XSS)
  9. A4:2017-XML External Entities (XXE)
  10. C1:2018-Define Security Requirements
  11. A8:2017-Insecure Deserialization
  12. A6:2017-Security Misconfiguration
  13. A9:2013-Using Components with Known Vulnerabilities
  14. A2:2013-Broken Authentication and Session Management
  15. C5:2018-Validate All Inputs
  16. A7:2013-Missing Function Level Access Control
  17. A4:2013-Insecure Direct Object References
  18. A2:2017-Broken Authentication
  19. C10:2018-Handle all Errors and Exceptions
  20. C4:2018-Encode and Escape Data
  21. C6:2018-Implement Digital Identity
  22. A5:2013-Security Misconfiguration
  23. C3:2018-Secure Database Access
  24. A8:2013-Cross-Site Request Forgery (CSRF)
  25. A7:2017-Cross-Site Scripting (XSS)
  26. A9:2017-Using Components with Known Vulnerabilities
  27. C8:2018-Protect Data Everywhere
  28. A10:2013-Unvalidated Redirects and Forwards
  29. A10:2017-Insufficient Logging & Monitoring
  30. C7:2018-Enforce Access Controls