Application and Data Vulnerabilities and Attacks
Introduced
Vocabulary
| English |
|---|
| injection attack/ɪnˈdʒekʃn əˈtæk/ |
| data validation/ˈdeɪtə ˌvælɪˈdeɪʃn/ |
| SQL injection/ˌes kjuː ˈel ɪnˈdʒekʃn/ |
| cross-site scripting/krɒs saɪt ˈskrɪptɪŋ/ |
| buffer overflow/ˈbʌfə ˌəʊvəˈfləʊ/ |
| buffer/ˈbʌfə/ |
| directory traversal/daɪˈrektəri træˈvɜːsl/ |
Bad input is the danger
- When a program does not check input, an adversary slips in commands — an injection attack 注入攻击.
- Data validation 数据验证 (checking input meets rules) is the defense.
- Unencrypted files and over-broad admin rights add more risk.
SQL injection and XSS
- SQL injection SQL注入: SQL commands in an input field read or change a database.
- Cross-site scripting (XSS) 跨站脚本: injected script runs in another user's browser.
- Both come from trusting unchecked user input.
Explore
Identify the application attack from the evidence
SQL injection shows OR 1=1; XSS shows
Your subject
Loading subjects…
Pick one and the site follows you — notes, papers, videos and practice all open on it.