Application Attacks

0.0(0)
studied byStudied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/4

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:19 AM on 7/18/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

5 Terms

1
New cards

Privilege Escelation

Gain higher-level access to a system (exploit)

Horizontal Privilege Escalation

  • Attacker goes from user to user access

2
New cards

Mitigating Privilege Escalation

  • Patches

  • Update anti/virus

  • Data Execution Prevention

  • Address space layout randomization

3
New cards

Cross-Site Request

Loading data into a website

  • Data comes from web server

4
New cards

Cross Site Request Forgery

XRSF, CRSF

  • One-click attack, session riding

  • Take advantage of the trust that a web app has for the user

Ex:

  • Attacker sends malicious link

  • User clicks (Logged in to bank on click)

  • User bank sends money to attacker

Resolution: Cryptographic Token

5
New cards

Directory Traversal

Allows attackers to read/write to a web server

  • May lead into finding other directories