凌虚的博客
文章 分类 标签 作者
凌虚的博客
取消
文章分类标签作者

目录

web 安全系列文章【译文】

凌虚 收录于 Web Security
 2021-08-12  约 97 字   预计阅读 1 分钟 
目录
  • Cross-site request forgery (CSRF)
  • Clickjacking (UI redressing)
  • Cross-origin resource sharing (CORS)
  • Server-side request forgery (SSRF)
  • HTTP request smuggling
  • OS command injectionn
  • Server-side template injection
  • Directory traversal
  • DOM-based vulnerabilities
  • HTTP Host header attacks

Cross-site request forgery (CSRF)

  • CSRF
  • XSS vs CSRF
  • CSRF tokens
  • SameSite cookies

Clickjacking (UI redressing)

  • Clickjacking (UI redressing)

Cross-origin resource sharing (CORS)

  • CORS
  • Same-origin policy (SOP)
  • Access-control-allow-origin

Server-side request forgery (SSRF)

  • Server-side request forgery (SSRF)
  • Blind SSRF vulnerabilities

HTTP request smuggling

  • HTTP request smuggling
  • Finding HTTP request smuggling vulnerabilities
  • Exploiting HTTP request smuggling vulnerabilities

OS command injectionn

  • OS command injection

Server-side template injection

  • Server-side template injection
  • Exploiting server-side template injection vulnerabilities

Directory traversal

  • Directory traversal

DOM-based vulnerabilities

  • DOM-based vulnerabilities
  • DOM clobbering

HTTP Host header attacks

  • HTTP Host header attacks
  • Exploiting HTTP Host header vulnerabilities
  • Password reset poisoning
更新于 2023-02-21
返回 | 主页
解读 MySQL Client/Server Protocol: Connection & Replication 加速 Kubernetes 镜像拉取
2017 - 2026 凌虚 | CC BY-NC 4.0