CORNUCOPIA (C3)

Andrew can access source code, or decompile, or otherwise access business logic to understand how the application works and any secrets contained

CORNUCOPIA
3

Andrew can access source code, or decompile, or otherwise access business logic to understand how the application works and any secrets contained

OWASP SCP

134

OWASP ASVS

14.1.1

OWASP AppSensor

CAPEC

-

SAFECODE

How to play?

Protect source code repositories and server-side source-code. Consider anti reverse-engineering techniques. Do not include or minimise logic/secrets within code accessible by users.

Mappings

OWASP ASVS (4.0): 14.1.1

Capec: 189 ,207

OWASP SCP: 134

OWASP Appsensor:

Safecode:

ASVS (4.0) Cheatsheetseries Index

ASVS V14.1 - Build

No suitable mappings were found.

Attacks

Weak Authentication Protocols

Insider Threats

Error message exploitation

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.