1/11
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
code injection
adding your own info into a data stream
enabled because of bag prgmng
buffer overflow
overwritign a buffer of memory
developrs need ot perform bounds checking
replay attack
useful info is transimitted over the networ
need aaccess to raw network data
privilege escalation
gain higher level access to a system by exploiting a vulnerability
horizontal privelege escalation
user a access to user b
how to mitigate priveliege escalation
patch quickly
update anti virus
data execution prevention l
address space layout randomization
data exectution prevention
imits area whewre memory can run
cross site request
you visit one website and rows loads a pic and video from other sites
corss site request forgery names
xsrf, csrf (sea surfing)
cross site request forgery
takes advantage of the trust a web app has for the user
log into a website and requests are down without your conset and atatcker pstos something form your account
how can you prevent sea surfing
crypographic tokens
directoy trversal/path traversal
reads files froma web server that are outside fo the websites file directory
suers shouldbe e able to browse the windnwos folder