<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tal+Mel</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tal+Mel"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Tal_Mel"/>
		<updated>2026-05-26T05:12:50Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=254756</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=254756"/>
				<updated>2019-09-15T21:45:29Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: presentation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
[https://www.owasp.org/images/1/1e/OWASP_DC_SLS_Top10.pdf Download]&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  PureSec joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Translation Efforts = &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Chinese:&amp;lt;/b&amp;gt; &amp;lt;u&amp;gt;[https://www.owasp.org/images/2/23/OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf OWASP Top 10 - Serverless Interpretation 中文版（PDF)]&amp;lt;/u&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
项目牵头人：肖文棣、王颉（wangj@owasp.org.cn）&amp;lt;br/&amp;gt;&lt;br /&gt;
项目组成员：刘晓辉、李宇全、明敏、王斌（排名不分先后，按姓氏拼音排列）&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_DC_SLS_Top10.pdf&amp;diff=254755</id>
		<title>File:OWASP DC SLS Top10.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_DC_SLS_Top10.pdf&amp;diff=254755"/>
				<updated>2019-09-15T21:44:49Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: Tal Mel uploaded a new version of File:OWASP DC SLS Top10.pdf&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP DC SLS Top10&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_DC_SLS_Top10.pdf&amp;diff=254754</id>
		<title>File:OWASP DC SLS Top10.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_DC_SLS_Top10.pdf&amp;diff=254754"/>
				<updated>2019-09-15T21:43:40Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP DC SLS Top10&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251695</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251695"/>
				<updated>2019-05-17T13:57:36Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  PureSec joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Translation Efforts = &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Chinese:&amp;lt;/b&amp;gt; &amp;lt;u&amp;gt;[https://www.owasp.org/images/2/23/OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf OWASP Top 10 - Serverless Interpretation 中文版（PDF)]&amp;lt;/u&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
项目牵头人：肖文棣、王颉（wangj@owasp.org.cn）&amp;lt;br/&amp;gt;&lt;br /&gt;
项目组成员：刘晓辉、李宇全、明敏、王斌（排名不分先后，按姓氏拼音排列）&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251694</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251694"/>
				<updated>2019-05-17T13:56:05Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  PureSec joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Translation Efforts = &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Chinese:&amp;lt;/b&amp;gt; &amp;lt;u&amp;gt;[https://www.owasp.org/images/2/23/OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf|OWASP Top 10 - Serverless Interpretation 中文版（PDF)]&amp;lt;/u&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
项目牵头人：肖文棣、王颉（wangj@owasp.org.cn）&amp;lt;br/&amp;gt;&lt;br /&gt;
项目组成员：刘晓辉、李宇全、明敏、王斌（排名不分先后，按姓氏拼音排列）&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251693</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251693"/>
				<updated>2019-05-17T13:55:34Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf|OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  PureSec joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Translation Efforts = &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Chinese:&amp;lt;/b&amp;gt; &amp;lt;u&amp;gt;[https://www.owasp.org/images/2/23/OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf|OWASP Top 10 - Serverless Interpretation 中文版（PDF)]&amp;lt;/u&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
项目牵头人：肖文棣、王颉（wangj@owasp.org.cn）&amp;lt;br/&amp;gt;&lt;br /&gt;
项目组成员：刘晓辉、李宇全、明敏、王斌（排名不分先后，按姓氏拼音排列）&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251692</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=251692"/>
				<updated>2019-05-17T13:55:08Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: Chinese translation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  PureSec joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Translation Efforts = &lt;br /&gt;
&lt;br /&gt;
* &amp;lt;b&amp;gt;Chinese:&amp;lt;/b&amp;gt; &amp;lt;u&amp;gt;[https://www.owasp.org/images/2/23/OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf|OWASP Top 10 - Serverless Interpretation 中文版（PDF)]&amp;lt;/u&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
项目牵头人：肖文棣、王颉（wangj@owasp.org.cn）&amp;lt;br/&amp;gt;&lt;br /&gt;
项目组成员：刘晓辉、李宇全、明敏、王斌（排名不分先后，按姓氏拼音排列）&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf&amp;diff=251691</id>
		<title>File:OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP-Top-10-Serverless-Interpretation-cn-v1.0.pdf&amp;diff=251691"/>
				<updated>2019-05-17T13:52:14Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Chinese translation for the OWASP Top 10 - Serverless Interpretation&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Log_review_and_management&amp;diff=251517</id>
		<title>Log review and management</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Log_review_and_management&amp;diff=251517"/>
				<updated>2019-05-14T16:18:49Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: /* Log Standard */  fix type&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
&lt;br /&gt;
Purpose:	&lt;br /&gt;
&lt;br /&gt;
* How to detect suspicious activities as soon as possible to reduce the impact of incidence or make prevention if possible.&lt;br /&gt;
* How to unify the log format and elements as well as the functions?&lt;br /&gt;
&lt;br /&gt;
Role:&lt;br /&gt;
&lt;br /&gt;
* Who typically does this?&lt;br /&gt;
&lt;br /&gt;
Security Administrator or independent party who has no access rights/accounts in the reviewed systems. You can't be an user administrator. At the same time, you review your activity everyday. However, if there is a resource limitation, you need another supervisor to authorize your log review.&lt;br /&gt;
&lt;br /&gt;
Frequency:&lt;br /&gt;
&lt;br /&gt;
It depends on the criticality (i.e. payment system, customer information, business secret, etc.) of the system labelled by the organization, logs could be reviewed ranging from minute, every day, weekly, monthly or even 3 months. In fact, log review is a kind of detective control and the preventive control is lacking. Log review will be the Goal Keeper and frequency is critical.&lt;br /&gt;
&lt;br /&gt;
However, user account and authority list should be reviewed at least 3 to 6 months and never take a check ONLY when the audit cycle is coming&lt;br /&gt;
&lt;br /&gt;
== Log Review Tips ==&lt;br /&gt;
&lt;br /&gt;
Critical systems require at least daily log review, however, what types of logs/activities should we pay attention to?&lt;br /&gt;
&lt;br /&gt;
1. Consecutive login failure especially in non-office hour.&lt;br /&gt;
&lt;br /&gt;
2. Login in non-office hour.&lt;br /&gt;
&lt;br /&gt;
3. Authority change, addition and removal. Check them against with authorized application.&lt;br /&gt;
&lt;br /&gt;
4. Any system administrator's activities&lt;br /&gt;
&lt;br /&gt;
5. Any unknown workstation/server are plugged into the network?&lt;br /&gt;
&lt;br /&gt;
6. Logs removal/log overwritten/log size is full&lt;br /&gt;
&lt;br /&gt;
7. Pay more attention to the log reports after week-end and holiday&lt;br /&gt;
&lt;br /&gt;
8. Any account unlocked/password reset by system administrators without authorized forms?&lt;br /&gt;
&lt;br /&gt;
== Log Standard ==&lt;br /&gt;
&lt;br /&gt;
In fact, we are suffering various log format and standard from various systems even we are working in-house or act as a consultant. Why don't we produce a standard/guidelines to developer before they design the user administrative and audit trail functions to fulfill security control.&lt;br /&gt;
&lt;br /&gt;
Functions:-&lt;br /&gt;
* Search - By date and time, by event type, by criticality, by account/user ID, by department&lt;br /&gt;
&lt;br /&gt;
* Sorting - By date and time, by event type, by criticality, by account/user ID, by department&lt;br /&gt;
&lt;br /&gt;
* Paging (Optional)&lt;br /&gt;
&lt;br /&gt;
* Critical event is marked by &amp;quot;*&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* Log archive and export&lt;br /&gt;
&lt;br /&gt;
* Log code and description table&lt;br /&gt;
&lt;br /&gt;
* Highlighting system and user adminisitrator activities&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Mandatory Fields:-&lt;br /&gt;
* User ID and Name (Sometimes, event may involve the action from administrator)&lt;br /&gt;
&lt;br /&gt;
* Activity Date/Timestamp&lt;br /&gt;
&lt;br /&gt;
* Activity Code, Type and Description&lt;br /&gt;
&lt;br /&gt;
* Terminal IP address and Location&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
User Account List:-&lt;br /&gt;
* User Info - Name, Department, Role&lt;br /&gt;
&lt;br /&gt;
* Last Accessed Time&lt;br /&gt;
&lt;br /&gt;
* Account Creation Date/Time&lt;br /&gt;
&lt;br /&gt;
* Current Authority and Role&lt;br /&gt;
&lt;br /&gt;
* Account authority and information change history&lt;br /&gt;
&lt;br /&gt;
* Show expired and inactive accounts (for example: 90 days)&lt;br /&gt;
&lt;br /&gt;
== Logging Tools ==&lt;br /&gt;
&lt;br /&gt;
'''Resources from Syslog.org'''&lt;br /&gt;
 &lt;br /&gt;
* Event Notification&lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/EventNotification&amp;lt;/u&amp;gt; &lt;br /&gt;
* Syslog Clients &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/SyslogClients&amp;lt;/u&amp;gt;&lt;br /&gt;
* Syslogd Replacements &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/SyslogdReplacements&amp;lt;/u&amp;gt;&lt;br /&gt;
* Event Viewers &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/EventViewers&amp;lt;/u&amp;gt;&lt;br /&gt;
* Log Analyzers &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/LogAnalyzers&amp;lt;/u&amp;gt;&lt;br /&gt;
* Event Correlation &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/EventCorrelation&amp;lt;/u&amp;gt;&lt;br /&gt;
* Windows &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/Windows&amp;lt;/u&amp;gt;&lt;br /&gt;
* Misc Log Tools &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/MiscLogTools&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Best Practice and Tips from Syslog'''&lt;br /&gt;
* Syslog Security Tip &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/SyslogSecurityTip&amp;lt;/u&amp;gt;&lt;br /&gt;
* Central Syslog Tip &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/CentralSyslogTip&amp;lt;/u&amp;gt;&lt;br /&gt;
* Logging Windows To Syslog Server &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/LoggingWindowsToSyslogServer&amp;lt;/u&amp;gt;&lt;br /&gt;
*Logging Troubleshoot&lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/TroubleshootingSyslogForwarding&amp;lt;/u&amp;gt;&lt;br /&gt;
* Syslog Best Practices &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.syslog.org/wiki/Main/SyslogBestPractices&amp;lt;/u&amp;gt;&lt;br /&gt;
* Logging, Log File Rotation, and Syslog Tutorial &lt;br /&gt;
&amp;lt;u&amp;gt;http://www.hccfl.edu/pollock/AUnix2/Logging.htm&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Activity]]&lt;br /&gt;
[[Category:Logging]]&lt;br /&gt;
[[Category:OWASP Logging Project]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tal_Mel&amp;diff=250011</id>
		<title>User:Tal Mel</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tal_Mel&amp;diff=250011"/>
				<updated>2019-04-11T04:15:55Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Tal melamed owasp.jpg|thumb]]&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FFFFFF&amp;quot;&amp;gt;Tal Melamed&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''Tal Melamed''' &amp;lt;br&amp;gt;&lt;br /&gt;
== Contact ==&lt;br /&gt;
Tal.Melamed@owasp.org &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Projects ==&lt;br /&gt;
[[OWASP_DVSA|'''OWASP DVSA''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Serverless_Top_10_Project|'''OWASP Serverless Top 10''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Path_Traverser|'''OWASP Path Traverser''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Rainbow_Maker_Project|'''OWASP Rainbow Maker''']]&amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/kingpin/ Kingpin - TCP/SSL Proxy] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/virustotal/ VirusTotal python API] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conferences ==&lt;br /&gt;
(OWASP Conferences)&amp;lt;br&amp;gt;&lt;br /&gt;
[https://telaviv.appsecglobal.org/ OWASP Global AppSec Tel Aviv] - Serverless Top 10 &amp;lt;br&amp;gt;  &lt;br /&gt;
[https://www.owasp.org/index.php/AppSec_Israel_2016_Presentations '''OWASP AppSec Israel 2016'''] - Java Hurdling: Obstacles and Techniques in Java Client Penetration-testing [https://www.owasp.org/index.php/AppSec_Israel_2016_Presentations#Java_Hurdling:_Obstacles_and_Techniques_in_Java_Client_Penetration-testing Download] [https://www.youtube.com/watch?v=oq4phacH9WY YouTube]&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Israel_January_2017 '''OWASP Israel 2017'''] - [https://www.owasp.org/index.php/OWASP_Israel_January_2017#RUaBLE_BLE_Application_Hacking R U aBLE? BLE Application Hacking]&amp;lt;br&amp;gt;&lt;br /&gt;
Full list of speaking engagements: https://appsec.it/talks&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pages ==&lt;br /&gt;
[http://www.linkedin.com/in/talmelamed LinkedIn] &amp;lt;br&amp;gt;&lt;br /&gt;
[http://serverless.fail DVSA] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://appsec.it AppSec.it] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/ GitHub] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://twitter.com/@_nu11p0inter/ Twitter] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Experience ==&lt;br /&gt;
[2019-Present] &amp;amp;nbsp; '''Adjunct Faculty''' @ [https://www.qu.edu/schools/engineering/programs/ms-cyber-security.html Quinnipiac University]&amp;lt;br&amp;gt;&lt;br /&gt;
[2018-Present] &amp;amp;nbsp; '''Head of Security Research''' @ [https://www.protego.io/ Protego Labs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2017-Present] &amp;amp;nbsp;  Security Researcher @ [https://www.synack.com/red-team/ Synack]&amp;lt;br&amp;gt;&lt;br /&gt;
[2017-2018] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Cyber Security Advisor @ [https://fbk.eu FBK]&amp;lt;br&amp;gt;&lt;br /&gt;
[2013-2018] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Tech Leader @ [https://appsec-labs.com AppSec Labs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2011-2013] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Information Security Analyst @ [http://amdocs.com Amdocs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2009-2011] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Security Researcher @ [http://www.checkpoint.com/products/dlp-software-blade/ CheckPoint Software Technologies] &amp;lt;br&amp;gt;&lt;br /&gt;
[2006-2008] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Intelligence Analyst @ [http://www.emc.com/security/rsa-identity-protection-and-verification/rsa-fraudaction.htm RSA, The Security Division of EMC] &amp;lt;br&amp;gt;&lt;br /&gt;
[2004-2005] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Security Team @ [http://www.iai.co.il/ Israel Aerospace Industries (IAI)] &amp;lt;br&amp;gt;&lt;br /&gt;
[2001-2004] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Platoon Sergeant @ [http://www.idf.il/english/ Israel Defense Forces (IDF)] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tal_Mel&amp;diff=250010</id>
		<title>User:Tal Mel</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tal_Mel&amp;diff=250010"/>
				<updated>2019-04-11T04:14:15Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Tal melamed owasp.jpg|thumb]]&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FFFFFF&amp;quot;&amp;gt;Tal Melamed&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''Tal Melamed''' &amp;lt;br&amp;gt;&lt;br /&gt;
== Contact ==&lt;br /&gt;
Tal.Melamed@owasp.org &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Projects ==&lt;br /&gt;
[[OWASP_DVSA|'''OWASP DVSA''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Serverless_Top_10_Project|'''OWASP Serverless Top 10''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Path_Traverser|'''OWASP Path Traverser''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Rainbow_Maker_Project|'''OWASP Rainbow Maker''']]&amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/kingpin/ Kingpin - TCP/SSL Proxy] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/virustotal/ VirusTotal python API] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conferences ==&lt;br /&gt;
(OWASP Conferences)&amp;lt;br&amp;gt;&lt;br /&gt;
[https://telaviv.appsecglobal.org/ OWASP Global AppSec Tel Aviv] - Serverless Top 10 &amp;lt;br&amp;gt;  &lt;br /&gt;
[https://www.owasp.org/index.php/AppSec_Israel_2016_Presentations '''OWASP AppSec Israel 2016'''] - Java Hurdling: Obstacles and Techniques in Java Client Penetration-testing [https://www.owasp.org/index.php/AppSec_Israel_2016_Presentations#Java_Hurdling:_Obstacles_and_Techniques_in_Java_Client_Penetration-testing Download] [https://www.youtube.com/watch?v=oq4phacH9WY YouTube]&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Israel_January_2017 '''OWASP Israel 2017'''] - [https://www.owasp.org/index.php/OWASP_Israel_January_2017#RUaBLE_BLE_Application_Hacking R U aBLE? BLE Application Hacking]&amp;lt;br&amp;gt;&lt;br /&gt;
Full list of speaking engagements: https://appsec.it/talks&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pages ==&lt;br /&gt;
[http://www.linkedin.com/in/talmelamed LinkedIn] &amp;lt;br&amp;gt;&lt;br /&gt;
[http://serverless.fail DVSA] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://appsec.it AppSec.it] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/ GitHub] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://twitter.com/@_nu11p0inter/ Twitter] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Experience ==&lt;br /&gt;
[2018-Present] &amp;amp;nbsp; '''Head of Security Research''' @ [https://www.protego.io/ Protego Labs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2017-Present] &amp;amp;nbsp;  Security Researcher @ [https://www.synack.com/red-team/ Synack]&amp;lt;br&amp;gt;&lt;br /&gt;
[2017-2018] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Cyber Security Advisor @ [https://fbk.eu FBK]&amp;lt;br&amp;gt;&lt;br /&gt;
[2013-2018] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Tech Leader @ [https://appsec-labs.com AppSec Labs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2011-2013] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Information Security Analyst @ [http://amdocs.com Amdocs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2009-2011] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Security Researcher @ [http://www.checkpoint.com/products/dlp-software-blade/ CheckPoint Software Technologies] &amp;lt;br&amp;gt;&lt;br /&gt;
[2006-2008] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Intelligence Analyst @ [http://www.emc.com/security/rsa-identity-protection-and-verification/rsa-fraudaction.htm RSA, The Security Division of EMC] &amp;lt;br&amp;gt;&lt;br /&gt;
[2004-2005] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Security Team @ [http://www.iai.co.il/ Israel Aerospace Industries (IAI)] &amp;lt;br&amp;gt;&lt;br /&gt;
[2001-2004] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Platoon Sergeant @ [http://www.idf.il/english/ Israel Defense Forces (IDF)] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246816</id>
		<title>OWASP DVSA</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246816"/>
				<updated>2019-01-24T20:47:33Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==DVSA==&lt;br /&gt;
=== a Damn Vulnerable Serverless Application ===&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is a deliberately vulnerable application aiming to be an aid for security professionals to test their skills and tools in a legal environment, help developers better understand the processes of securing serverless applications and to aid both students &amp;amp; teachers to learn about serverless application security in a controlled class room environment.&lt;br /&gt;
&lt;br /&gt;
The aim of DVSA is to practice some of the most common serverless vulnerabilities, with a simple straightforward interface.&lt;br /&gt;
&lt;br /&gt;
Please note, there are both documented and undocumented vulnerabilities with this software. This is intentional. You are encouraged to try and discover as many issues as possible.&lt;br /&gt;
&lt;br /&gt;
== Disclaimer ==&lt;br /&gt;
We do not take responsibility for the way in which any one uses this application (DVSA). We have made the purposes of the application clear and it should not be used maliciously. We have given warnings and taken measures to prevent users from installing DVSA on to production accounts.&lt;br /&gt;
&lt;br /&gt;
==License==&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.&lt;br /&gt;
&lt;br /&gt;
You should have received a copy of the GNU General Public License along with Damn Vulnerable Serverless Application (DVSA). If not, see http://www.gnu.org/licenses/.&lt;br /&gt;
&lt;br /&gt;
== Deployment == &lt;br /&gt;
&lt;br /&gt;
=== Application Repository ===&lt;br /&gt;
Deploy DVSA from the AWS [https://serverlessrepo.aws.amazon.com/applications/arn:aws:serverlessrepo:us-east-1:889485553959:applications~DVSAServerless Applicaiton Repository]&lt;br /&gt;
&lt;br /&gt;
After deployment is complete. Click on 'View CloudFormation Stack'&lt;br /&gt;
&lt;br /&gt;
Under 'Outputs' you will find the URL for the application (DVSA Website URL)&lt;br /&gt;
&lt;br /&gt;
=== Serverless Framework === &lt;br /&gt;
 &lt;br /&gt;
clone project from github&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;npm install&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Backend ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Build Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;npm run-script client:build&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls client deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cheat Sheet ==&lt;br /&gt;
Lessons can be found '''[https://github.com/OWASP/DVSA/blob/master/AWS/LESSONS.md here]'''&lt;br /&gt;
&lt;br /&gt;
== Roadmap ==&lt;br /&gt;
* '''25 DEC 2018''': http://serverless.fail (official website) was launched.&lt;br /&gt;
* '''08 JAN 2019''': v1.0 beta release [https://github.com/owasp/dvsa GitHub])&lt;br /&gt;
* '''01 FEB 2019''': v1.0 official version.&lt;br /&gt;
&lt;br /&gt;
== Project Sponsors ==&lt;br /&gt;
The project was initially developed by Protego Labs:&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. &lt;br /&gt;
&lt;br /&gt;
Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://serverlessrepo.aws.amazon.com/applications/arn:aws:serverlessrepo:us-east-1:889485553959:applications~DVSA AWS Application Repository]&lt;br /&gt;
&lt;br /&gt;
[http://serverless.fail Online version]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DVSA GitHub Repo]&lt;br /&gt;
&lt;br /&gt;
[https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal_Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [25 Dec 2018]:  http://serverless.fail - Launched&lt;br /&gt;
* [01 Jan 2019]:  Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [03 Jan 2019]:  [https://www.theregister.co.uk/2019/01/03/damn_vulnerable_serverless_application/ The Register]&lt;br /&gt;
* [04 Jan 2019]:  [https://sdtimes.com/cloud/sd-times-news-digest-protegos-dvsa-quicklogic-acquires-ai-company-and-iot-interoperability/ SDTimes]&lt;br /&gt;
* [07 Jan 2019]:  [http://www.eweek.com/security/protego-labs-boosts-serverless-security-with-open-source-project eWEEK]&lt;br /&gt;
* [08 Jan 2019]:  [https://www.computerweekly.com/news/252455429/Protego-Labs-launches-serverless-app-security-tool Computer Weekly]&lt;br /&gt;
* [08 Jan 2019]:  [https://technical.ly/baltimore/2019/01/08/protego-has-a-new-open-source-tool-to-provide-serverless-security-training/ Technical.ly]&lt;br /&gt;
* [09 Jan 2019]:  [https://github.com/owasp/dvsa Beta release!]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;400&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246815</id>
		<title>OWASP DVSA</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246815"/>
				<updated>2019-01-24T20:45:15Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==DVSA==&lt;br /&gt;
=== a Damn Vulnerable Serverless Application ===&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is a deliberately vulnerable application aiming to be an aid for security professionals to test their skills and tools in a legal environment, help developers better understand the processes of securing serverless applications and to aid both students &amp;amp; teachers to learn about serverless application security in a controlled class room environment.&lt;br /&gt;
&lt;br /&gt;
The aim of DVSA is to practice some of the most common serverless vulnerabilities, with a simple straightforward interface.&lt;br /&gt;
&lt;br /&gt;
Please note, there are both documented and undocumented vulnerabilities with this software. This is intentional. You are encouraged to try and discover as many issues as possible.&lt;br /&gt;
&lt;br /&gt;
== Disclaimer ==&lt;br /&gt;
We do not take responsibility for the way in which any one uses this application (DVSA). We have made the purposes of the application clear and it should not be used maliciously. We have given warnings and taken measures to prevent users from installing DVSA on to production accounts.&lt;br /&gt;
&lt;br /&gt;
==License==&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.&lt;br /&gt;
&lt;br /&gt;
You should have received a copy of the GNU General Public License along with Damn Vulnerable Serverless Application (DVSA). If not, see http://www.gnu.org/licenses/.&lt;br /&gt;
&lt;br /&gt;
== Deployment ==  &lt;br /&gt;
clone project from github&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;npm install&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Backend ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Build Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;npm run-script client:build&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls client deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cheat Sheet ==&lt;br /&gt;
Lessons can be found '''[https://github.com/OWASP/DVSA/blob/master/AWS/LESSONS.md here]'''&lt;br /&gt;
&lt;br /&gt;
== Roadmap ==&lt;br /&gt;
* '''25 DEC 2018''': http://serverless.fail (official website) was launched.&lt;br /&gt;
* '''08 JAN 2019''': v1.0 beta release [https://github.com/owasp/dvsa GitHub])&lt;br /&gt;
* '''01 FEB 2019''': v1.0 official version.&lt;br /&gt;
&lt;br /&gt;
== Project Sponsors ==&lt;br /&gt;
The project was initially developed by Protego Labs:&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. &lt;br /&gt;
&lt;br /&gt;
Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[https://serverlessrepo.aws.amazon.com/applications/arn:aws:serverlessrepo:us-east-1:889485553959:applications~DVSA AWS Application Repository]&lt;br /&gt;
&lt;br /&gt;
[http://serverless.fail Online version]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DVSA GitHub Repo]&lt;br /&gt;
&lt;br /&gt;
[https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal_Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [25 Dec 2018]:  http://serverless.fail - Launched&lt;br /&gt;
* [01 Jan 2019]:  Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [03 Jan 2019]:  [https://www.theregister.co.uk/2019/01/03/damn_vulnerable_serverless_application/ The Register]&lt;br /&gt;
* [04 Jan 2019]:  [https://sdtimes.com/cloud/sd-times-news-digest-protegos-dvsa-quicklogic-acquires-ai-company-and-iot-interoperability/ SDTimes]&lt;br /&gt;
* [07 Jan 2019]:  [http://www.eweek.com/security/protego-labs-boosts-serverless-security-with-open-source-project eWEEK]&lt;br /&gt;
* [08 Jan 2019]:  [https://www.computerweekly.com/news/252455429/Protego-Labs-launches-serverless-app-security-tool Computer Weekly]&lt;br /&gt;
* [08 Jan 2019]:  [https://technical.ly/baltimore/2019/01/08/protego-has-a-new-open-source-tool-to-provide-serverless-security-training/ Technical.ly]&lt;br /&gt;
* [09 Jan 2019]:  [https://github.com/owasp/dvsa Beta release!]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;400&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246469</id>
		<title>OWASP DVSA</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246469"/>
				<updated>2019-01-08T22:24:35Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==DVSA==&lt;br /&gt;
=== a Damn Vulnerable Serverless Application ===&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is a deliberately vulnerable application aiming to be an aid for security professionals to test their skills and tools in a legal environment, help developers better understand the processes of securing serverless applications and to aid both students &amp;amp; teachers to learn about serverless application security in a controlled class room environment.&lt;br /&gt;
&lt;br /&gt;
The aim of DVSA is to practice some of the most common serverless vulnerabilities, with a simple straightforward interface.&lt;br /&gt;
&lt;br /&gt;
Please note, there are both documented and undocumented vulnerabilities with this software. This is intentional. You are encouraged to try and discover as many issues as possible.&lt;br /&gt;
&lt;br /&gt;
== Disclaimer ==&lt;br /&gt;
We do not take responsibility for the way in which any one uses this application (DVSA). We have made the purposes of the application clear and it should not be used maliciously. We have given warnings and taken measures to prevent users from installing DVSA on to production accounts.&lt;br /&gt;
&lt;br /&gt;
==License==&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.&lt;br /&gt;
&lt;br /&gt;
You should have received a copy of the GNU General Public License along with Damn Vulnerable Serverless Application (DVSA). If not, see http://www.gnu.org/licenses/.&lt;br /&gt;
&lt;br /&gt;
== Deployment ==  &lt;br /&gt;
clone project from github&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;npm install&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Backend ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Build Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;npm run-script client:build&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls client deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cheat Sheet ==&lt;br /&gt;
Lessons can be found '''[https://github.com/OWASP/DVSA/blob/master/AWS/LESSONS.md here]'''&lt;br /&gt;
&lt;br /&gt;
== Roadmap ==&lt;br /&gt;
* '''25 DEC 2018''': http://serverless.fail (official website) was launched.&lt;br /&gt;
* '''08 JAN 2019''': v1.0 beta release [https://github.com/owasp/dvsa GitHub])&lt;br /&gt;
* '''01 FEB 2019''': v1.0 official version.&lt;br /&gt;
&lt;br /&gt;
== Project Sponsors ==&lt;br /&gt;
The project was initially developed by Protego Labs:&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. &lt;br /&gt;
&lt;br /&gt;
Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[http://serverless.fail Online version]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DVSA GitHub Repo]&lt;br /&gt;
&lt;br /&gt;
[https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal_Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [25 Dec 2018]:  http://serverless.fail - Launched&lt;br /&gt;
* [01 Jan 2019]:  Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [03 Jan 2019]:  [https://www.theregister.co.uk/2019/01/03/damn_vulnerable_serverless_application/ The Register]&lt;br /&gt;
* [04 Jan 2019]:  [https://sdtimes.com/cloud/sd-times-news-digest-protegos-dvsa-quicklogic-acquires-ai-company-and-iot-interoperability/ SDTimes]&lt;br /&gt;
* [07 Jan 2019]:  [http://www.eweek.com/security/protego-labs-boosts-serverless-security-with-open-source-project eWEEK]&lt;br /&gt;
* [08 Jan 2019]:  [https://www.computerweekly.com/news/252455429/Protego-Labs-launches-serverless-app-security-tool Computer Weekly]&lt;br /&gt;
* [08 Jan 2019]:  [https://technical.ly/baltimore/2019/01/08/protego-has-a-new-open-source-tool-to-provide-serverless-security-training/ Technical.ly]&lt;br /&gt;
* [09 Jan 2019]:  [https://github.com/owasp/dvsa Beta release!]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;400&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246460</id>
		<title>OWASP DVSA</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246460"/>
				<updated>2019-01-08T14:36:46Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==DVSA==&lt;br /&gt;
=== a Damn Vulnerable Serverless Application ===&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is a deliberately vulnerable application aiming to be an aid for security professionals to test their skills and tools in a legal environment, help developers better understand the processes of securing serverless applications and to aid both students &amp;amp; teachers to learn about serverless application security in a controlled class room environment.&lt;br /&gt;
&lt;br /&gt;
The aim of DVSA is to practice some of the most common serverless vulnerabilities, with a simple straightforward interface.&lt;br /&gt;
&lt;br /&gt;
Please note, there are both documented and undocumented vulnerabilities with this software. This is intentional. You are encouraged to try and discover as many issues as possible.&lt;br /&gt;
&lt;br /&gt;
== Disclaimer ==&lt;br /&gt;
We do not take responsibility for the way in which any one uses this application (DVSA). We have made the purposes of the application clear and it should not be used maliciously. We have given warnings and taken measures to prevent users from installing DVSA on to production accounts.&lt;br /&gt;
&lt;br /&gt;
==License==&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.&lt;br /&gt;
&lt;br /&gt;
You should have received a copy of the GNU General Public License along with Damn Vulnerable Serverless Application (DVSA). If not, see http://www.gnu.org/licenses/.&lt;br /&gt;
&lt;br /&gt;
== Deployment ==  &lt;br /&gt;
clone project from github&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;npm install&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Backend ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Build Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;npm run-script client:build&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls client deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cheat Sheet ==&lt;br /&gt;
Lessons can be found '''[https://github.com/OWASP/DVSA/blob/master/AWS/LESSONS.md here]'''&lt;br /&gt;
&lt;br /&gt;
== Roadmap ==&lt;br /&gt;
* '''25 DEC 2018''': http://serverless.fail (official website) was launched.&lt;br /&gt;
* '''08 JAN 2019''': v1.0 beta release [https://github.com/owasp/dvsa GitHub])&lt;br /&gt;
* '''01 FEB 2019''': v1.0 official version.&lt;br /&gt;
&lt;br /&gt;
== Project Sponsors ==&lt;br /&gt;
The project was initially developed by Protego Labs:&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. &lt;br /&gt;
&lt;br /&gt;
Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[http://serverless.fail Online version]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DVSA GitHub Repo]&lt;br /&gt;
&lt;br /&gt;
[https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal_Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [25 Dec 2018]:  http://serverless.fail - Launched&lt;br /&gt;
* [01 Jan 2019]:  Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [03 Jan 2019]:  [https://www.theregister.co.uk/2019/01/03/damn_vulnerable_serverless_application/ The Register]&lt;br /&gt;
* [04 Jan 2019]:  [https://sdtimes.com/cloud/sd-times-news-digest-protegos-dvsa-quicklogic-acquires-ai-company-and-iot-interoperability/ SDTimes]&lt;br /&gt;
* [07 Jan 2019]:  [http://www.eweek.com/security/protego-labs-boosts-serverless-security-with-open-source-project eWEEK]&lt;br /&gt;
* [08 Jan 2019]:  [https://www.computerweekly.com/news/252455429/Protego-Labs-launches-serverless-app-security-tool Computer Weekly]&lt;br /&gt;
* [09 Jan 2019]:  [https://github.com/owasp/dvsa Beta release!]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;400&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246437</id>
		<title>OWASP DVSA</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246437"/>
				<updated>2019-01-07T21:12:06Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==DVSA==&lt;br /&gt;
=== a Damn Vulnerable Serverless Application ===&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is a deliberately vulnerable application aiming to be an aid for security professionals to test their skills and tools in a legal environment, help developers better understand the processes of securing serverless applications and to aid both students &amp;amp; teachers to learn about serverless application security in a controlled class room environment.&lt;br /&gt;
&lt;br /&gt;
The aim of DVSA is to practice some of the most common serverless vulnerabilities, with a simple straightforward interface.&lt;br /&gt;
&lt;br /&gt;
Please note, there are both documented and undocumented vulnerabilities with this software. This is intentional. You are encouraged to try and discover as many issues as possible.&lt;br /&gt;
&lt;br /&gt;
== Disclaimer ==&lt;br /&gt;
We do not take responsibility for the way in which any one uses this application (DVSA). We have made the purposes of the application clear and it should not be used maliciously. We have given warnings and taken measures to prevent users from installing DVSA on to production accounts.&lt;br /&gt;
&lt;br /&gt;
==License==&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.&lt;br /&gt;
&lt;br /&gt;
You should have received a copy of the GNU General Public License along with Damn Vulnerable Serverless Application (DVSA). If not, see http://www.gnu.org/licenses/.&lt;br /&gt;
&lt;br /&gt;
== Deployment ==  &lt;br /&gt;
clone project from github&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;npm install&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Backend ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Build Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;npm run-script client:build&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls client deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cheat Sheet ==&lt;br /&gt;
Lessons can be found '''[https://github.com/OWASP/DVSA/blob/master/AWS/LESSONS.md here]'''&lt;br /&gt;
&lt;br /&gt;
== Roadmap ==&lt;br /&gt;
* '''25 DEC 2018''': http://serverless.fail (official website) was launched.&lt;br /&gt;
* '''08 JAN 2019''': v1.0 beta release [https://github.com/owasp/dvsa GitHub])&lt;br /&gt;
* '''01 FEB 2019''': v1.0 official version.&lt;br /&gt;
&lt;br /&gt;
== Project Sponsors ==&lt;br /&gt;
The project was initially developed by Protego Labs:&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. &lt;br /&gt;
&lt;br /&gt;
Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[http://serverless.fail Online version]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DVSA GitHub Repo]&lt;br /&gt;
&lt;br /&gt;
[https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal_Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [25 Dec 2018]:  http://serverless.fail - Launched&lt;br /&gt;
* [01 Jan 2019]:  Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [03 Jan 2019]:  [https://www.theregister.co.uk/2019/01/03/damn_vulnerable_serverless_application/ The Register]&lt;br /&gt;
* [04 Jan 2019]:  [https://sdtimes.com/cloud/sd-times-news-digest-protegos-dvsa-quicklogic-acquires-ai-company-and-iot-interoperability/ SDTimes]&lt;br /&gt;
* [07 Jan 2019]:  [http://www.eweek.com/security/protego-labs-boosts-serverless-security-with-open-source-project eWEEK]&lt;br /&gt;
* [08 Jan 2019]:  [https://github.com/owasp/dvsa Beta release!]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;400&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Tal_Mel&amp;diff=246436</id>
		<title>User:Tal Mel</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Tal_Mel&amp;diff=246436"/>
				<updated>2019-01-07T21:02:32Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Tal melamed owasp.jpg|thumb]]&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FFFFFF&amp;quot;&amp;gt;Tal Melamed&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''Tal Melamed''' &amp;lt;br&amp;gt;&lt;br /&gt;
== Contact ==&lt;br /&gt;
Tal.Melamed@owasp.org &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Projects ==&lt;br /&gt;
[[OWASP_DVSA|'''OWASP DVSA''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Serverless_Top_10_Project|'''OWASP Serverless Top 10''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Path_Traverser|'''OWASP Path Traverser''']] &amp;lt;br&amp;gt;&lt;br /&gt;
[[OWASP_Rainbow_Maker_Project|'''OWASP Rainbow Maker''']]&amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/kingpin/ Kingpin - TCP/SSL Proxy] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/virustotal/ VirusTotal python API] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conferences ==&lt;br /&gt;
(OWASP Conferences)&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/AppSec_Israel_2016_Presentations '''OWASP AppSec Israel 2016'''] - Java Hurdling: Obstacles and Techniques in Java Client Penetration-testing [https://www.owasp.org/index.php/AppSec_Israel_2016_Presentations#Java_Hurdling:_Obstacles_and_Techniques_in_Java_Client_Penetration-testing Download] [https://www.youtube.com/watch?v=oq4phacH9WY YouTube]&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Israel_January_2017 '''OWASP Israel 2017'''] - [https://www.owasp.org/index.php/OWASP_Israel_January_2017#RUaBLE_BLE_Application_Hacking R U aBLE? BLE Application Hacking]&amp;lt;br&amp;gt;&lt;br /&gt;
Full list of talking engagements: https://appsec.it/talks&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pages ==&lt;br /&gt;
[http://www.linkedin.com/in/talmelamed LinkedIn] &amp;lt;br&amp;gt;&lt;br /&gt;
[http://serverless.fail DVSA] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://appsec.it AppSec.it] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://github.com/nu11p0inter/ GitHub] &amp;lt;br&amp;gt;&lt;br /&gt;
[https://twitter.com/@_nu11p0inter/ Twitter] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Experience ==&lt;br /&gt;
[2018-Present] &amp;amp;nbsp; '''Head of Security Research''' @ [https://www.protego.io/ Protego Labs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2017-Present] &amp;amp;nbsp;  Security Researcher @ [https://www.synack.com/red-team/ Synack]&amp;lt;br&amp;gt;&lt;br /&gt;
[2017-2018] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Cyber Security Advisor @ [https://fbk.eu FBK]&amp;lt;br&amp;gt;&lt;br /&gt;
[2013-2018] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Tech Leader @ [https://appsec-labs.com AppSec Labs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2011-2013] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Information Security Analyst @ [http://amdocs.com Amdocs]&amp;lt;br&amp;gt;&lt;br /&gt;
[2009-2011] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Security Researcher @ [http://www.checkpoint.com/products/dlp-software-blade/ CheckPoint Software Technologies] &amp;lt;br&amp;gt;&lt;br /&gt;
[2006-2008] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Intelligence Analyst @ [http://www.emc.com/security/rsa-identity-protection-and-verification/rsa-fraudaction.htm RSA, The Security Division of EMC] &amp;lt;br&amp;gt;&lt;br /&gt;
[2004-2005] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Security Team @ [http://www.iai.co.il/ Israel Aerospace Industries (IAI)] &amp;lt;br&amp;gt;&lt;br /&gt;
[2001-2004] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;  Platoon Sergeant @ [http://www.idf.il/english/ Israel Defense Forces (IDF)] &amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246280</id>
		<title>OWASP DVSA</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DVSA&amp;diff=246280"/>
				<updated>2018-12-27T19:02:54Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==DVSA==&lt;br /&gt;
=== a Damn Vulnerable Serverless Application ===&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is a deliberately vulnerable application aiming to be an aid for security professionals to test their skills and tools in a legal environment, help developers better understand the processes of securing serverless applications and to aid both students &amp;amp; teachers to learn about serverless application security in a controlled class room environment.&lt;br /&gt;
&lt;br /&gt;
The aim of DVSA is to practice some of the most common serverless vulnerabilities, with a simple straightforward interface.&lt;br /&gt;
&lt;br /&gt;
Please note, there are both documented and undocumented vulnerabilities with this software. This is intentional. You are encouraged to try and discover as many issues as possible.&lt;br /&gt;
&lt;br /&gt;
== Disclaimer ==&lt;br /&gt;
We do not take responsibility for the way in which any one uses this application (DVSA). We have made the purposes of the application clear and it should not be used maliciously. We have given warnings and taken measures to prevent users from installing DVSA on to production accounts.&lt;br /&gt;
&lt;br /&gt;
==License==&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.&lt;br /&gt;
&lt;br /&gt;
Damn Vulnerable Serverless Application (DVSA) is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.&lt;br /&gt;
&lt;br /&gt;
You should have received a copy of the GNU General Public License along with Damn Vulnerable Serverless Application (DVSA). If not, see http://www.gnu.org/licenses/.&lt;br /&gt;
&lt;br /&gt;
== Deployment ==  &lt;br /&gt;
clone project from github&lt;br /&gt;
&lt;br /&gt;
&amp;lt;code&amp;gt;npm install&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Backend ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Build Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;npm run-script client:build&amp;lt;/code&amp;gt;&lt;br /&gt;
==== Deploy Client ====&lt;br /&gt;
&amp;lt;code&amp;gt;sls client deploy&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cheat Sheet ==&lt;br /&gt;
Lessons can be found '''[https://github.com/OWASP/DVSA/blob/master/AWS/LESSONS.md here]'''&lt;br /&gt;
&lt;br /&gt;
== Roadmap ==&lt;br /&gt;
* '''25 DEC 2018''': http://serverless.fail (official website) was launched.&lt;br /&gt;
* '''01 JAN 2019''': Beta version released ([https://github.com/owasp/dvsa GitHub])&lt;br /&gt;
* '''12 JAN 2019''': v1.0 official version.&lt;br /&gt;
&lt;br /&gt;
== Project Sponsors ==&lt;br /&gt;
The project was initially developed by Protego Labs:&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. &lt;br /&gt;
&lt;br /&gt;
Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
[http://serverless.fail Online version]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/DVSA GitHub Repo]&lt;br /&gt;
&lt;br /&gt;
[https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal_Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
== Project Mailing List ==&lt;br /&gt;
TBD&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246248</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246248"/>
				<updated>2018-12-23T04:39:41Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  PureSec joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246048</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246048"/>
				<updated>2018-12-13T17:09:28Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  [https://puresec.io PureSec] joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246047</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246047"/>
				<updated>2018-12-13T17:09:12Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  [https://puresec.io PureSec] joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[User:MarcinHoppe|Marcin Hoppe]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246045</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246045"/>
				<updated>2018-12-13T16:11:43Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [01 Sep 2018]:  Hello World! Project was donated by [https://protego.io Protego Labs]&lt;br /&gt;
* [18 Sep 2018]:  Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]:  Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]:  [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [30 Oct 2018]:  [https://puresec.io PureSec] joined as sponsor&lt;br /&gt;
* [02 Nov 2018]:  OWASP [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
* [13 Dec 2018]:  WhiteSource joined as sponsor&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[mailto:marcin.hoppe@owasp.org Marcin Hoppe]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246044</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246044"/>
				<updated>2018-12-13T16:05:00Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[mailto:marcin.hoppe@owasp.org Marcin Hoppe]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246043</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246043"/>
				<updated>2018-12-13T15:57:04Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Sponsors      &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Protego logo black.png|frameless|link=https://protego.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246042</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246042"/>
				<updated>2018-12-13T15:47:44Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]   &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246041</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246041"/>
				<updated>2018-12-13T15:42:57Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
[[File:Protego logo black.png|frameless|link=https://protego.io/]] {{pad}} [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]] {{pad}} [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246040</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246040"/>
				<updated>2018-12-13T15:33:35Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}             [[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]                          [[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246039</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246039"/>
				<updated>2018-12-13T15:32:40Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246038</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=246038"/>
				<updated>2018-12-13T15:32:19Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: whitesource&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
[[File:Whitesource logo rgb-02.png|frameless|link=https://www.whitesourcesoftware.com/]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Whitesource_logo_rgb-02.png&amp;diff=246037</id>
		<title>File:Whitesource logo rgb-02.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Whitesource_logo_rgb-02.png&amp;diff=246037"/>
				<updated>2018-12-13T15:31:15Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;WhiteSource logo&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245253</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245253"/>
				<updated>2018-11-19T15:25:03Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
=== ===&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible mw-collapsed&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245252</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245252"/>
				<updated>2018-11-19T15:24:08Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
{| role=&amp;quot;presentation&amp;quot; class=&amp;quot;mw-collapsible&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| '''&amp;lt;big&amp;gt;Report Reviewers   &amp;lt;/big&amp;gt;'''&lt;br /&gt;
|-&lt;br /&gt;
|Assaf Hefetz, Snyk&lt;br /&gt;
|- &lt;br /&gt;
|Erez Metula, AppSec Labs&lt;br /&gt;
|-&lt;br /&gt;
|Erez Yalon, Checkmarx&lt;br /&gt;
|-&lt;br /&gt;
|Frank M. Catucci, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Guy Bernhart-Magen, Intel&lt;br /&gt;
|-&lt;br /&gt;
|Hemed Gur Ary, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Jeff Williams, Contrast Security&lt;br /&gt;
|-&lt;br /&gt;
|Jim DelGrosso, Synopsys&lt;br /&gt;
|-&lt;br /&gt;
|Jochanan Sommerfeld, RDuck&lt;br /&gt;
|-&lt;br /&gt;
|Kobi Lechner, INFINIDAT&lt;br /&gt;
|-&lt;br /&gt;
|Limor Sylvie Kessem, IBM&lt;br /&gt;
|-&lt;br /&gt;
|Marcin Hoppe, Auth0&lt;br /&gt;
|-&lt;br /&gt;
|Mark Johnston, Google&lt;br /&gt;
|-&lt;br /&gt;
|Martin Knobloch, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Matthew Henderson, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Matteo Meucci, Minded Security&lt;br /&gt;
|-&lt;br /&gt;
|Owen Pendlebury, OWASP&lt;br /&gt;
|-&lt;br /&gt;
|Paco Hope, AWS&lt;br /&gt;
|-&lt;br /&gt;
|Patrick Laverty, Rapid7&lt;br /&gt;
|-&lt;br /&gt;
|Rupack Ganguly, Serverless Inc.&lt;br /&gt;
|-&lt;br /&gt;
|Tanya Janca, Microsoft&lt;br /&gt;
|-&lt;br /&gt;
|Tash Norris, Capital One&lt;br /&gt;
|-&lt;br /&gt;
|Tom Brennan, IOActive&lt;br /&gt;
|-&lt;br /&gt;
|Yan Cui, DAZN &lt;br /&gt;
|-&lt;br /&gt;
|Youssef Elmalty, AWS&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245251</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245251"/>
				<updated>2018-11-19T15:10:04Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== Report Reviewers ===&lt;br /&gt;
&amp;lt;small&amp;gt;Assaf Hefetz, Snyk &lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245250</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245250"/>
				<updated>2018-11-19T15:09:54Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== Report Reviewers ===&lt;br /&gt;
&amp;lt;details&amp;gt;&lt;br /&gt;
      &amp;lt;summary&amp;gt;Your header here! (Click to expand)&amp;lt;/summary&amp;gt;&lt;br /&gt;
      Your content here...&amp;lt;/br&amp;gt;&lt;br /&gt;
      (markup only where supported)&amp;lt;/br&amp;gt;&lt;br /&gt;
      more content here...&amp;lt;/br&amp;gt;&lt;br /&gt;
    &amp;lt;/details&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;small&amp;gt;Assaf Hefetz, Snyk &lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245249</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245249"/>
				<updated>2018-11-19T15:08:19Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
=== Report Reviewers ===&lt;br /&gt;
&amp;lt;small&amp;gt;Assaf Hefetz, Snyk &lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245248</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245248"/>
				<updated>2018-11-19T15:07:34Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;details&amp;gt;&amp;lt;summary&amp;gt;CLICK ME&amp;lt;/summary&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
#### yes, even hidden code blocks!&lt;br /&gt;
&lt;br /&gt;
```python&lt;br /&gt;
print(&amp;quot;hello world!&amp;quot;)&lt;br /&gt;
```&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/details&amp;gt;&lt;br /&gt;
&amp;lt;small&amp;gt;Assaf Hefetz, Snyk &lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245247</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245247"/>
				<updated>2018-11-19T15:04:37Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
===First Report Reviewers===&lt;br /&gt;
&amp;lt;small&amp;gt;Assaf Hefetz, Snyk &lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&amp;lt;/small&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245246</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245246"/>
				<updated>2018-11-19T15:03:20Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
==First Report Reviewers==&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245245</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245245"/>
				<updated>2018-11-19T15:02:58Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
==First Report Reviewers==&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245244</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245244"/>
				<updated>2018-11-19T15:02:17Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
&lt;br /&gt;
==First Report Reviewers==&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Tal_Melamed.jpg&amp;diff=245243</id>
		<title>File:Tal Melamed.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Tal_Melamed.jpg&amp;diff=245243"/>
				<updated>2018-11-19T14:32:33Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Tal Melamed&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245224</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245224"/>
				<updated>2018-11-18T16:51:34Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
* [2 Nov 2018]: [https://owasp.blogspot.com/2018/11/serverless-top-10-added-to-project.html Official Announcement]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245026</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245026"/>
				<updated>2018-11-09T18:26:14Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY '''#project-sls-top-10''']&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245025</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245025"/>
				<updated>2018-11-09T18:25:21Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY invite] '''#project-sls-top-10'''&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245024</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=245024"/>
				<updated>2018-11-09T18:23:31Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel] '''#project-sls-top-10'''.&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our [https://lists.owasp.org/mailman/listinfo/owasp-serverless-top-10-project mailing list] &lt;br /&gt;
&lt;br /&gt;
Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY invite]&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244758</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244758"/>
				<updated>2018-10-31T14:21:32Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel].&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our [https://lists.owasp.org/mailman/listinfo/owasp-serverless-top-10-project mailing list] &lt;br /&gt;
&lt;br /&gt;
Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY invite]&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244757</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244757"/>
				<updated>2018-10-31T14:21:20Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel].&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our [https://lists.owasp.org/mailman/listinfo/owasp-serverless-top-10-project mailing list] &lt;br /&gt;
&lt;br /&gt;
Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY invite]&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244756</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244756"/>
				<updated>2018-10-31T14:21:10Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel].&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our [https://lists.owasp.org/mailman/listinfo/owasp-serverless-top-10-project mailing list] &lt;br /&gt;
&lt;br /&gt;
Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY invite]&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244754</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244754"/>
				<updated>2018-10-31T14:20:44Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/5/5c/OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel].&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our [https://lists.owasp.org/mailman/listinfo/owasp-serverless-top-10-project mailing list] &lt;br /&gt;
&lt;br /&gt;
Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY invite]&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244753</id>
		<title>OWASP Serverless Top 10 Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Serverless_Top_10_Project&amp;diff=244753"/>
				<updated>2018-10-31T14:20:26Z</updated>
		
		<summary type="html">&lt;p&gt;Tal Mel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Main =&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/index.php/File:OWASP-Top-10-Serverless-Interpretation-en.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
When adopting serverless technology, we eliminate the need to develop a server to manage our application. By doing so, we also pass some of the security threats to the infrastructure provider such as [https://aws.amazon.com/serverless/ AWS], [https://azure.microsoft.com/en-us/services/functions/ Azure] and [https://cloud.google.com/functions/ Google Cloud]. In addition to the many advantages of serverless application development, such as cost and scalability, some security aspects are also handed to our service provider. Serverless services run code without provisioning or managing servers and the code is executed only when needed.&lt;br /&gt;
&lt;br /&gt;
However, even if these applications are running without a managed server, they still execute code. If this code is written in an insecure manner, it can still be vulnerable to application-level attacks. &lt;br /&gt;
&lt;br /&gt;
The first report will examine the differences in attack vectors, security weaknesses, and the business impact of application attacks on in the serverless world, and, most importantly, the report will suggest ways to to prevent them. As we will be able to see in the report, attack and defense techniques are different from what we used to in the traditional application world.&lt;br /&gt;
&lt;br /&gt;
After that, an open-call will be established to collect data in the wild and establishing the official Serverless Top 10 Report.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Purpose==&lt;br /&gt;
&lt;br /&gt;
OWASP Serverless Top 10 aims at educating practitioners and organizations about the consequences of the most common serverless application security vulnerabilities, as well as providing basic techniques to identify and protect against them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Licensing ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Serverless Top 10 is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/4.0/ Creative Commons Attribution-ShareAlike 4.0 license] (CC BY-SA 4.0).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Project Sponsors==&lt;br /&gt;
The OWASP Serverless Top 10 project is sponsored by&lt;br /&gt;
&lt;br /&gt;
{{MemberLinks|link=https://www.protego.io|logo=Protego logo 300x75.png}}&lt;br /&gt;
&lt;br /&gt;
and&lt;br /&gt;
&lt;br /&gt;
[[File:PureSec-Logo.png|frameless|link=https://www.puresec.io/]]&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Downloads ==&lt;br /&gt;
[https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf OWASP Top 10: Serverless Interpretation]&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
Soon!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News &amp;amp; Events ==&lt;br /&gt;
* [1 Sep 2018]: Hello World!&lt;br /&gt;
* [18 Sep 2018]: Join our [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY Slack-channel].&lt;br /&gt;
* [22 Sep 2018]: Follow our [https://github.com/OWASP/Serverless-Top-10-Project/ Git Repo].&lt;br /&gt;
* [25 Oct 2018]: [https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf '''First Release!''']&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
[[User:Tal Mel|Tal Melamed]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
[[Coming soon!]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
[[:Category:OWASP Top Ten Project|OWASP Top 10 Project]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;300&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgments =&lt;br /&gt;
Assaf Hefetz, Snyk&lt;br /&gt;
&lt;br /&gt;
Erez Metula, AppSec Labs&lt;br /&gt;
&lt;br /&gt;
Erez Yalon, Checkmarx&lt;br /&gt;
&lt;br /&gt;
Frank M. Catucci, OWASP&lt;br /&gt;
&lt;br /&gt;
Guy Bernhart-Magen, Intel&lt;br /&gt;
&lt;br /&gt;
Hemed Gur Ary, OWASP&lt;br /&gt;
&lt;br /&gt;
Jeff Williams, Contrast Security&lt;br /&gt;
&lt;br /&gt;
Jim DelGrosso, Synopsys&lt;br /&gt;
&lt;br /&gt;
Jochanan Sommerfeld, RDuck&lt;br /&gt;
&lt;br /&gt;
Kobi Lechner, INFINIDAT&lt;br /&gt;
&lt;br /&gt;
Limor Sylvie Kessem, IBM&lt;br /&gt;
&lt;br /&gt;
Marcin Hoppe, Auth0&lt;br /&gt;
&lt;br /&gt;
Mark Johnston, Google&lt;br /&gt;
&lt;br /&gt;
Martin Knobloch, OWASP&lt;br /&gt;
&lt;br /&gt;
Matthew Henderson, Microsoft&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci, Minded Security&lt;br /&gt;
&lt;br /&gt;
Owen Pendlebury, OWASP&lt;br /&gt;
&lt;br /&gt;
Paco Hope, AWS&lt;br /&gt;
&lt;br /&gt;
Patrick Laverty, Rapid7&lt;br /&gt;
&lt;br /&gt;
Rupack Ganguly, Serverless Inc.&lt;br /&gt;
&lt;br /&gt;
Tanya Janca, Microsoft&lt;br /&gt;
&lt;br /&gt;
Tash Norris, Capital One&lt;br /&gt;
&lt;br /&gt;
Tom Brennan, IOActive&lt;br /&gt;
&lt;br /&gt;
Yan Cui, DAZN &lt;br /&gt;
&lt;br /&gt;
Youssef Elmalty, AWS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Project Resources =&lt;br /&gt;
== OWASP Serverless Top 10 - First Released ==&lt;br /&gt;
The [https://www.owasp.org/images/7/79/OWASP-Top-10-Serverless-Interpretation_%28en%29.pdf OWASP Top 10: Serverless Interpretation] is now available.&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/Serverless-Top-10-Project/ GitHub repository]&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
{{:Projects/OWASP_Serverless_Top_10_Project/Roadmap}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Get involved =&lt;br /&gt;
&lt;br /&gt;
Get involved in &amp;lt;strong&amp;gt; OWASP Serverless Top 10&amp;lt;/strong&amp;gt;!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute. Contact the Project Leader(s) to get involved, we welcome any type of suggestions and comments.&lt;br /&gt;
&lt;br /&gt;
Possible ways to get contribute:&lt;br /&gt;
* We are actively looking for organizations and individuals that will provide vulnerability prevalence data. &lt;br /&gt;
* Translation efforts (later stages)&lt;br /&gt;
* Assisting in the development of related tools (e.g. DVSA)&lt;br /&gt;
&lt;br /&gt;
Individuals and organizations that will contribute to the project will listed on the acknowledgments page.&lt;br /&gt;
&lt;br /&gt;
Also, join our [https://lists.owasp.org/mailman/listinfo/owasp-serverless-top-10-project mailing list] &lt;br /&gt;
&lt;br /&gt;
Slack Channel [https://join.slack.com/t/owasp/shared_invite/enQtNDI5MzgxMDQ2MTAwLTEyNzIzYWQ2NDZiMGIwNmJhYzYxZDJiNTM0ZmZiZmJlY2EwZmMwYjAyNmJjNzQxNzMyMWY4OTk3ZTQ0MzFhMDY invite]&lt;br /&gt;
&lt;br /&gt;
GitHub [https://github.com/OWASP/Serverless-Top-10-Project/ project page]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:OWASP_Serverless_Top_10_Project_About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Tal Mel</name></author>	</entry>

	</feed>