|
You are here |
neilmadden.blog | ||
| | | | |
chefsecure.com
|
|
| | | | | Learn hacking with this hands-on tutorial that shows you how YouTube could be exploited if it had an XSS vulnerability. | |
| | | | |
mathieu.fenniak.net
|
|
| | | | | Cross-site request forgery (CSRF) is a type of security exploit where a user's web browser is tricked by a third-party site into performing actions on websites that the user is logged into. It is often a difficult attack to pull off, as it requires a number of factors to line up at once. Protecting against it requires good discipline and good design practices, especially when it comes to protecting Web APIs. Here's a brief example of a fictitious CSRF attack against a bank: | |
| | | | |
attilaolah.eu
|
|
| | | | | This is intended to be a short list of things to check before you go publish awebsite or web app (or really, anything that interacts with a browser). Itstarts with... | |
| | | | |
homakov.blogspot.com
|
|
| | | TL;DR OAuth2 sucks. Please don't think about OAuth2 as about the next generation of OAuth1. They are completely different like colors: O... | ||