Ayo Secu

  • 홈
  • 태그
  • 방명록

XSS 3

Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)Cross-Site Scripting (XSS) is a web application vulnerability where attackers inject malicious scripts into web pages viewed by other users. These scripts execute in the victim’s browser, enabling attackers to steal sensitive data, hijack sessions, or perform other malicious actions.1. Types of XSS Attacksa. Reflected XSSDefinition: Malicious scripts are injected into a..

Security Terms/Web Application 2025.01.22

Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) is a web security vulnerability that allows an attacker to trick a user into performing unwanted actions on a trusted website where the user is authenticated. CSRF exploits the trust that a website has in a user’s browser, primarily through the misuse of cookies for authentication.1. How CSRF WorksVictim AuthenticationThe victim ..

Security Terms/Web Application 2025.01.22

Cookies

CookiesCookies are small pieces of data stored by a web browser on behalf of a website, typically used for session management, user preferences, and tracking. To enhance security, cookies come with attributes that control their behavior and access.1. Key Cookie AttributesAttributePurposeHttpOnlyPrevents client-side JavaScript from accessing the cookie.SecureEnsures the cookie is sent only over H..

Security Terms/Web Application 2025.01.22
이전
1
다음
더보기
  • 분류 전체보기 (144)
    • Security Terms (144)
      • Threat Modeling (5)
      • Attack Structure (14)
      • Exploits (5)
      • Detection (11)
      • Incident Management (6)
      • Digital Forensics (7)
      • Network Security (35)
      • Web Application (22)
      • Cryptography, Authenticatio.. (8)
      • Infrastructure Virtualizati.. (9)
      • OS Implementation and Syste.. (8)
      • Mitigations (10)
      • Malware Reversing (4)

Tag

Cryptography, Exploit, identity, security, Detection, mitigations, network, os implementation, infrastructure virtualization, cybersecurity, systems, web application, NETWORK SECURITY, threat modeling, security terms, attack structure, Digital Forensics, forensic, incident management, Authentication,

Copyright © Kakao Corp. All rights reserved.

티스토리툴바