100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Summary

Summary Web-based Vulnerabilities

Rating
-
Sold
-
Pages
2
Uploaded on
16-10-2024
Written in
2022/2023

The Advanced Cybersecurity and Risk Management notes are from the University of Phoenix Advance Cybersecurity Certification course - these notes will assist you in understand different aspects and domains of Information Security. The notes will guide you through the process of understanding each domain to prepare you for future certification exams.

Show more Read less
Institution
Cyber Security Specialist
Course
Cyber Security Specialist








Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Cyber Security Specialist
Course
Cyber Security Specialist

Document information

Uploaded on
October 16, 2024
Number of pages
2
Written in
2022/2023
Type
Summary

Content preview

Vulnerabilities – web-based systems

Assessment and mitigation

OWASP - community focused web project - nonprofit security project focusing
on improving security for online or web-based applications



Injection Attack - exploitation that allows an attacker to submit code to a
target system in order to modify its operation or poison and corrupt the data

SQL Injection - attack on org assets - use unexpected input to alter or
compromise a web application - vulnerability of the script used to handle the
interaction between the front end (web server) and the backend db - if the
script is written defensively and includes code escape, it will reject then it is
not possible to SQL inject or metacharacter escape

XSS attacks are customers or visitors to a website

To protect

Perform input validation - limit the types of data a user provides in a form

Limit account privileges - database account should have the smallest set of
priv

Escaping a metacharacter is the process of marking the metacharacter as
merely normal or common - metacharacters are assigned special
programmatic meanings

LDAP injection - variation or an input injection attack - focus is on the
backend of the LDAP directory service - if a web server front end uses a
script to craft LDAP statements based on input from the user, then the LDAP
injection is a threat potential



XML Injection - variant of SQL where the target backend is XML application -
need input sanitization to stop

Directory traversal attack enables an attack to jump out of the web root
directory and into any part of the filesystem

XML Exploit - programming attack used to falsify information being sent to a
visitor or cause their system to give up info without authorization



1
$5.99
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
jimb6056

Also available in package deal

Thumbnail
Package deal
Cybersecurity and Risk Management
-
30 2024
$ 179.70 More info

Get to know the seller

Seller avatar
jimb6056 (self)
View profile
Follow You need to be logged in order to follow users or courses
Sold
0
Member since
1 year
Number of followers
0
Documents
37
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions