Both items appear to cover DDL hijacking: - TASVS-CODE-7.1 https://github.com/OWASP/www-project-thick-client-application-security-verification-standard/blob/47b44485bd93cf43409e2a381095097c6e9e5afa/document/1.0/05-TASVS-CODE.md?plain=1#L576-L586 - TASVS-STORAGE-2.2 https://github.com/OWASP/www-project-thick-client-application-security-verification-standard/blob/47b44485bd93cf43409e2a381095097c6e9e5afa/document/1.0/09-TASVS-STORAGE.md?plain=1#L60-L62
Both items appear to cover DDL hijacking:
https://github.com/OWASP/www-project-thick-client-application-security-verification-standard/blob/47b44485bd93cf43409e2a381095097c6e9e5afa/document/1.0/05-TASVS-CODE.md?plain=1#L576-L586
https://github.com/OWASP/www-project-thick-client-application-security-verification-standard/blob/47b44485bd93cf43409e2a381095097c6e9e5afa/document/1.0/09-TASVS-STORAGE.md?plain=1#L60-L62