Skip to main content

Book 07

Security

Common attacks on web applications and the defenses against them, from authentication to encryption.

Contents

  1. 01ABAC1ABAC is an authorization model that allows or denies each request by checking attributes of the user, the resource, the action and the context against policies.
  2. 02API Key2An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
  3. 03Authentication3Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
  4. 04Authorization4Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
  5. 05bcrypt5bcrypt is a password-hashing function that adds a random salt and is deliberately slow, so stolen password hashes are very expensive to crack by guessing.
  6. 06Brute-Force Attack6A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
  7. 07Bug Bounty7A bug bounty is a program in which an organization rewards outside security researchers for finding and responsibly reporting vulnerabilities in its systems.
  8. 08Certificate Authority8A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
  9. 09Clickjacking9Clickjacking is an attack that hides a legitimate website inside an invisible frame on a malicious page, tricking users into clicking buttons they cannot see.
  10. 10Content Security Policy10A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
  11. 11CSRF11CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
  12. 12CVE12A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
  13. 13DDoS13A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
  14. 14Digital Signature14A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
  15. 15Encryption15Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
  16. 16Encryption at Rest16Encryption at rest keeps stored data, such as disks, databases and backups, encrypted, so a stolen drive or copied file is unreadable without the key.
  17. 17End-to-End Encryption17End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
  18. 18Hashing18Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
  19. 19HMAC19HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
  20. 20HSTS20HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
  21. 21HTTPS21HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
  22. 22Input Validation22Input validation is the practice of checking that data entering a program has the expected type, format and range before it is used, and rejecting the rest.
  23. 23JWT23A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
  24. 24Kerberos24Kerberos is a network authentication protocol in which a trusted server issues time-limited tickets, so users prove who they are without sending passwords.
  25. 25LDAP25LDAP is an open protocol for searching and updating a directory service, the central database of an organization's users, groups and devices.
  26. 26Malware26Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
  27. 27Man-in-the-Middle Attack27A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
  28. 28OAuth28OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
  29. 29OpenID Connect29OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
  30. 30OWASP Top 1030The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
  31. 31Passkey31A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
  32. 32Penetration Testing32Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
  33. 33Phishing33Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
  34. 34Principle of Least Privilege34The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
  35. 35Prompt Injection35Prompt injection is an attack on LLM apps where attacker-written text is treated as instructions, so the model ignores its rules, leaks data or misuses tools.
  36. 36Public-Key Cryptography36Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
  37. 37Ransomware37Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
  38. 38RBAC38RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
  39. 39Refresh Token39A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
  40. 40Salting40Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
  41. 41Same-Origin Policy41The same-origin policy is a browser security rule that stops scripts on one website from reading data from another site unless that site explicitly allows it.
  42. 42SAML42SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
  43. 43Secrets Management43Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
  44. 44Session Hijacking44Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
  45. 45Social Engineering45Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
  46. 46SQL Injection46SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
  47. 47SSL47SSL is the deprecated predecessor of TLS for encrypting connections; every version is insecure and prohibited, and today's "SSL" connections actually use TLS.
  48. 48SSO48SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
  49. 49SSRF49SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
  50. 50Supply Chain Attack50A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
  51. 51Symmetric Encryption51Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
  52. 52TLS52TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
  53. 53Two-Factor Authentication53Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
  54. 54Web Application Firewall54A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
  55. 55XSS55XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
  56. 56Zero Trust56Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
  57. 57Zero-Day57A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.

Back to the libraryNext book: AI & Machine Learning

More

Settings