C4:2018-Encode andEscape DataC9:2018-ImplementSecurityLogging andMonitoringC7:2018-EnforceAccessControlsC1:2018-DefineSecurityRequirementsA10:2013-UnvalidatedRedirectsandForwardsA2:2017-BrokenAuthenticationA6:2017-SecurityMisconfigurationA8:2013-Cross-SiteRequestForgery(CSRF)A9:2013-UsingComponentswith KnownVulnerabilitiesA7:2017-Cross-SiteScripting(XSS)A5:2017-BrokenAccessControlA7:2013-MissingFunctionLevel AccessControlC5:2018-ValidateAll InputsA6:2013-SensitiveDataExposureC3:2018-SecureDatabaseAccessA4:2017-XMLExternalEntities(XXE)A1:2013-InjectionA2:2013-BrokenAuthenticationand SessionManagementC6:2018-ImplementDigitalIdentityC10:2018-Handle allErrors andExceptionsA3:2017-SensitiveDataExposureA10:2017-InsufficientLogging &MonitoringA1:2017-InjectionA8:2017-InsecureDeserializationC2:2018-LeverageSecurityFrameworksand LibrariesA3:2013-Cross-SiteScripting(XSS)C8:2018-ProtectDataEverywhereA4:2013-InsecureDirect ObjectReferencesA9:2017-UsingComponentswith KnownVulnerabilitiesA5:2013-SecurityMisconfigurationC4:2018-Encode andEscape DataC9:2018-ImplementSecurityLogging andMonitoringC7:2018-EnforceAccessControlsC1:2018-DefineSecurityRequirementsA10:2013-UnvalidatedRedirectsandForwardsA2:2017-BrokenAuthenticationA6:2017-SecurityMisconfigurationA8:2013-Cross-SiteRequestForgery(CSRF)A9:2013-UsingComponentswith KnownVulnerabilitiesA7:2017-Cross-SiteScripting(XSS)A5:2017-BrokenAccessControlA7:2013-MissingFunctionLevel AccessControlC5:2018-ValidateAll InputsA6:2013-SensitiveDataExposureC3:2018-SecureDatabaseAccessA4:2017-XMLExternalEntities(XXE)A1:2013-InjectionA2:2013-BrokenAuthenticationand SessionManagementC6:2018-ImplementDigitalIdentityC10:2018-Handle allErrors andExceptionsA3:2017-SensitiveDataExposureA10:2017-InsufficientLogging &MonitoringA1:2017-InjectionA8:2017-InsecureDeserializationC2:2018-LeverageSecurityFrameworksand LibrariesA3:2013-Cross-SiteScripting(XSS)C8:2018-ProtectDataEverywhereA4:2013-InsecureDirect ObjectReferencesA9:2017-UsingComponentswith KnownVulnerabilitiesA5:2013-SecurityMisconfiguration

Stash OWASP Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
  1. C4:2018-Encode and Escape Data
  2. C9:2018-Implement Security Logging and Monitoring
  3. C7:2018-Enforce Access Controls
  4. C1:2018-Define Security Requirements
  5. A10:2013-Unvalidated Redirects and Forwards
  6. A2:2017-Broken Authentication
  7. A6:2017-Security Misconfiguration
  8. A8:2013-Cross-Site Request Forgery (CSRF)
  9. A9:2013-Using Components with Known Vulnerabilities
  10. A7:2017-Cross-Site Scripting (XSS)
  11. A5:2017-Broken Access Control
  12. A7:2013-Missing Function Level Access Control
  13. C5:2018-Validate All Inputs
  14. A6:2013-Sensitive Data Exposure
  15. C3:2018-Secure Database Access
  16. A4:2017-XML External Entities (XXE)
  17. A1:2013-Injection
  18. A2:2013-Broken Authentication and Session Management
  19. C6:2018-Implement Digital Identity
  20. C10:2018-Handle all Errors and Exceptions
  21. A3:2017-Sensitive Data Exposure
  22. A10:2017-Insufficient Logging & Monitoring
  23. A1:2017-Injection
  24. A8:2017-Insecure Deserialization
  25. C2:2018-Leverage Security Frameworks and Libraries
  26. A3:2013-Cross-Site Scripting (XSS)
  27. C8:2018-Protect Data Everywhere
  28. A4:2013-Insecure Direct Object References
  29. A9:2017-Using Components with Known Vulnerabilities
  30. A5:2013-Security Misconfiguration