凌虚的博客
文章 分类 标签 作者
凌虚的博客
Cancel
文章分类标签作者

Contents

web 安全系列文章【译文】

凌虚 included in Web Security
 2021-08-12  97 words   One minute 
Contents
  • Cross-site request forgery (CSRF)
  • Clickjacking (UI redressing)
  • Cross-origin resource sharing (CORS)
  • Server-side request forgery (SSRF)
  • HTTP request smuggling
  • OS command injectionn
  • Server-side template injection
  • Directory traversal
  • DOM-based vulnerabilities
  • HTTP Host header attacks

Cross-site request forgery (CSRF)

  • CSRF
  • XSS vs CSRF
  • CSRF tokens
  • SameSite cookies

Clickjacking (UI redressing)

  • Clickjacking (UI redressing)

Cross-origin resource sharing (CORS)

  • CORS
  • Same-origin policy (SOP)
  • Access-control-allow-origin

Server-side request forgery (SSRF)

  • Server-side request forgery (SSRF)
  • Blind SSRF vulnerabilities

HTTP request smuggling

  • HTTP request smuggling
  • Finding HTTP request smuggling vulnerabilities
  • Exploiting HTTP request smuggling vulnerabilities

OS command injectionn

  • OS command injection

Server-side template injection

  • Server-side template injection
  • Exploiting server-side template injection vulnerabilities

Directory traversal

  • Directory traversal

DOM-based vulnerabilities

  • DOM-based vulnerabilities
  • DOM clobbering

HTTP Host header attacks

  • HTTP Host header attacks
  • Exploiting HTTP Host header vulnerabilities
  • Password reset poisoning
Updated on 2023-02-21
Back | Home
解读 MySQL Client/Server Protocol: Connection & Replication 加速 Kubernetes 镜像拉取
2017 - 2025 凌虚 | CC BY-NC 4.0