# OWASP Low-Code No-Code Top 10 > OWASP Global AppSec DC 2023, 2023-10-31. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2023-10-31-owasp-globalappsec-dc2023-owasp-low-code-no-code-top-10/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2023-10-31_OWASP-DC-23_OWASP-LCNC-Top-10/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2023-10-31_OWASP-DC-23_OWASP-LCNC-Top-10/slides.pdf) - [Conference agenda](https://owasp2023globalappsecwashin.sched.com/event/1OUyz/owasp-low-code-no-code-top-10) - [Source code](https://github.com/OWASP/www-project-citizen-development-top10-security-risks) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2023-10-31-owasp-globalappsec-dc2023-owasp-low-code-no-code-top-10.md) ## Abstract Low-Code/No-Code development platforms provide a development environment used to create application software through a graphical user interface instead of traditional hand-coded computer programming. Such platforms reduce the amount of traditional hand-coding, enabling accelerated delivery of business applications. As Low-Code/No-Code platforms proliferate and become widely used by organizations, there is a clear and immediate need to create awareness around security and privacy risks related to applications developed on such platforms. The primary goal of the "OWASP Low-Code/No-Code Top 10" document is to provide assistance and education for organizations looking to adopt and develop Low-Code/No-Code applications. The guide provides information about what the most prominent security risks are for such applications, the challenges involved, and how to overcome them. _[Official conference abstract](https://owasp2023globalappsecwashin.sched.com/event/1OUyz/owasp-low-code-no-code-top-10)_ ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2023-10-31_OWASP-DC-23_OWASP-LCNC-Top-10/406b1e38/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 Slide 1: visual from the OWASP Low-Code No-Code Top 10 presentation ### Slide 2 Slide 2: Michael Bargury (Zenity), Ory Segal (Palo Alto Networks), Don Willits (Microsoft), John McTiernan (DT Group), Yianna Paris ( Xebia ), Ziv Daniel Hagbi (Zenity) and many more! @OWASPNoCode OWASP Low-Code / No-Code Top 10 ### Slide 3 Slide 3: OWASP LCNC Top 10 @OWASPNoCode OWASP TOP 10 ### Slide 4 Slide 4: Why LCNC? Why new? @OWASPNoCode ### Slide 5 Slide 5: Source: @RezaDorrani OWASP LCNC Top 10 @OWASPNoCode - Animation: [Embedded animation](https://media.mbgsec.com/decks/2023-10-31_OWASP-DC-23_OWASP-LCNC-Top-10/406b1e38/media/slide-005-animation.gif) ### Slide 6 Slide 6: OWASP LCNC Top 10 @OWASPNoCode COVID health check app by Microsoft https://aka.ms/healthcheck ### Slide 7 Slide 7: OWASP LCNC Top 10 @OWASPNoCode Credential Sharing as a Service: The Dark Side of No Code Michael Bargury RSAC 2023 C# devs today ### Slide 8 Slide 8: OWASP LCNC Top 10 @OWASPNoCode ~8M active Power devs today! Credential Sharing as a Service: The Dark Side of No Code Michael Bargury RSAC 2023 ### Slide 9 Slide 9: OWASP LCNC Top 10 @OWASPNoCode AI implies No Code apps become more complex and more useful ### Slide 10 Slide 10: No Code No SDLC @OWASPNoCode ### Slide 11 Slide 11: OWASP LCNC Top 10 @OWASPNoCode SDLC Business Engineering Engineering Ops Ops Ops QA The SDLC ### Slide 12 Slide 12: OWASP LCNC Top 10 @OWASPNoCode SDLC Business Engineering Engineering Ops Ops Ops QA Threat modeling Shift-left Code scanning (SAST/DAST/IAST) Security gates Security gates Vulnerability scanning Runtime monitoring Runtime protection Security review Security training Secure SDLC ### Slide 13 Slide 13: OWASP LCNC Top 10 @OWASPNoCode SDLC Business Business Business Business Business Business Business No Code No SDLC Hit Save to deploy… ### Slide 14 Slide 14: OWASP LCNC Top 10 @OWASPNoCode Existing security control Low-code / no-code Security training Can we expect business users to be security savvy? Threat modeling Can’t scale to 000s apps/year Security review Can’t scale to 000s apps/year Code scanning No code to scan Artifact scanning Mostly unavailable, overwhelming FPs Secur… ### Slide 15 Slide 15: OWASP LCNC Top 10 @OWASPNoCode Recap – security process and controls are severely lacking Has access to business, health, financial data Runs as SaaS Lacking SDLC Lacking security controls Developers with no security savviness 10-100x the scale of application development ### Slide 16 Slide 16: OWASP LCNC Top 10 @OWASPNoCode ### Slide 17 Slide 17: OWASP LCNC Top 10 @OWASPNoCode Unique about LCNC Devs can be anyone from a pro dev to a citizen dev No SDLC No security controls 10-100x scale of app development Code is generated (platform owns code-gen vulns) Focused on logical vulns ### Slide 18 Slide 18: OWASP LCNC Top 10 @OWASPNoCode OWASP LCNC Top 10 LCNC-SEC-01: Account Impersonation LCNC-SEC-02: Authorization Misuse LCNC-SEC-03: Data Leakage and Unexpected Consequences LCNC-SEC-04: Authentication and Secure Communication Failures LCNC-SEC-05: Security Misconfiguration LCNC-SEC-06: Injection Handling Failures LCNC-SEC-07:… ### Slide 19 Slide 19: OWASP LCNC Top 10 @OWASPNoCode OWASP LCNC Top 10 LCNC-SEC-01: Account Impersonation LCNC-SEC-02: Authorization Misuse LCNC-SEC-03: Data Leakage and Unexpected Consequences LCNC-SEC-04: Authentication and Secure Communication Failures LCNC-SEC-05: Security Misconfiguration LCNC-SEC-06: Injection Handling Failures LCNC-SEC-07:… ### Slide 20 Slide 20: OWASP LCNC Top 10 @OWASPNoCode LCNC-SEC-01: Account Impersonation ### Slide 21 Slide 21: OWASP LCNC Top 10 @OWASPNoCode LCNC-SEC-01: Account Impersonation A short description for security pros A short description for business users contribution by John McTiernan , DT Group and Yianna Paris @punk_fairybread, Xebia A longer description for security pros ### Slide 22 Slide 22: OWASP LCNC Top 10 @OWASPNoCode LCNC-SEC-01: Account Impersonation Attack and misuse scenarios for both security pros and business users ### Slide 23 Slide 23: OWASP LCNC Top 10 @OWASPNoCode LCNC-SEC-01: Account Impersonation What can you do about it? ### Slide 24 Slide 24: OWASP LCNC Top 10 @OWASPNoCode Methodology loop Anonymized statistics Publish >1M apps and automations >8M credentials Draft Community feedback Community contribution Ty to all collaborations and contributors! ### Slide 25 Slide 25: Real-world example – employee onboarding @OWASPNoCode ### Slide 26 Slide 26: OWASP LCNC Top 10 @OWASPNoCode ### Slide 27 Slide 27: OWASP LCNC Top 10 @OWASPNoCode ### Slide 28 Slide 28: OWASP LCNC Top 10 @OWASPNoCode ### Slide 29 Slide 29: OWASP LCNC Top 10 @OWASPNoCode ### Slide 30 Slide 30: OWASP LCNC Top 10 @OWASPNoCode ### Slide 31 Slide 31: OWASP LCNC Top 10 @OWASPNoCode ### Slide 32 Slide 32: OWASP LCNC Top 10 @OWASPNoCode ### Slide 33 Slide 33: OWASP LCNC Top 10 @OWASPNoCode Employee LCNC-SEC-01: Account Impersonation LCNC-SEC-02: Authorization Misuse LCNC-SEC-03: Data Leakage and Unexpected Consequences LCNC-SEC-04: Authentication and Secure Communication Failures LCNC-SEC-05: Security Misconfiguration LCNC-SEC-06: Injection Handling Failures LCNC-SEC-07: Vulnerabl… ### Slide 34 Slide 34: Employee onboarding – findings @ mbrg0 #BHUSA @BlackHatEvents OWASP LCNC Top 10 @OWASPNoCode ### Slide 35 Slide 35: OWASP LCNC Top 10 @OWASPNoCode ### Slide 36 Slide 36: OWASP LCNC Top 10 @OWASPNoCode ### Slide 37 Slide 37: OWASP LCNC Top 10 @OWASPNoCode ### Slide 38 Slide 38: OWASP LCNC Top 10 @OWASPNoCode ### Slide 39 Slide 39: App Store sensitive data Data accessible to all (Authorization Misuse) Employee onboarding – findings Data Everyone has access @ mbrg0 #BHUSA @BlackHatEvents OWASP LCNC Top 10 @OWASPNoCode ### Slide 40 Slide 40: App Store in plaintext Data Submit sensitive data User Employee onboarding – findings Data accessible to all (Authorization Misuse) Sensitive data in plain text (Data and Secret Handling Failures) @ mbrg0 #BHUSA @BlackHatEvents OWASP LCNC Top 10 @OWASPNoCode ### Slide 41 Slide 41: OWASP LCNC Top 10 @OWASPNoCode ### Slide 42 Slide 42: OWASP LCNC Top 10 @OWASPNoCode ### Slide 43 Slide 43: OWASP LCNC Top 10 @OWASPNoCode ### Slide 44 Slide 44: OWASP LCNC Top 10 @OWASPNoCode ### Slide 45 Slide 45: Data accessible to all (Authorization Misuse) Sensitive data in plain text (Data and Secret Handling Failures) Sensitive data written to logs Employee onboarding – findings @ mbrg0 #BHUSA @BlackHatEvents (Data Leakage) OWASP LCNC Top 10 @OWASPNoCode ### Slide 46 Slide 46: Data accessible to all (Authorization Misuse) Sensitive data in plain text (Data and Secret Handling Failures) Sensitive data written to logs (Data Leakage) Employee onboarding – findings @ mbrg0 #BHUSA @BlackHatEvents OWASP LCNC Top 10 @OWASPNoCode ### Slide 47 Slide 47: 2023 recap and 2024 plans @OWASPNoCode ### Slide 48 Slide 48: OWASP LCNC Top 10 @OWASPNoCode 2023 recap Lab project Stable 2023 Top 10 version Better wording, better and more examples, clarity Virtual meetups  youtube.com/@owasplcnc Plain language for business users (contribution by John McTiernan , DT Group and Yianna Paris @punk_fairybread, Xebia )  youtube.com/ watch?v =s3lZ8fsMDDQ ### Slide 49 Slide 49: OWASP LCNC Top 10 @OWASPNoCode 2024 plans Top 10 revamp Another look on categories A different treatment for Low Code / RPA / BPA / .. CALL FOR DATA Translation to different languages Collaterals (deck, infographic, ..) Transparency Virtual meetups ### Slide 50 Slide 50: OWASP LCNC Top 10 @OWASPNoCode GET INVOLED! CALL FOR DATA PLEASE SHARE YOUR STORIES! JOIN THE DISCUSSION Slack bit.ly/ owasp - lcnc -slack Email group bit.ly/ owasp - lcnc -group CONTRIBUTE Share stories, review, translate, create graphics, help on social… michael.bargury@owasp.org ### Slide 51 Slide 51: Get involved! Michael.Bargury@owasp.org @OWASPNoCode CALL FOR DATA PLEASE SHARE YOUR STORIES! JOIN THE DISCUSSION Slack bit.ly/ owasp - lcnc -slack Email group bit.ly/ owasp - lcnc -group CONTRIBUTE Share stories, review, translate, create graphics, help on social…