Book 07
Security
Common attacks on web applications and the defenses against them, from authentication to encryption.
Contents
- 01ABACAttribute-Based Access Control1ABAC is an authorization model that allows or denies each request by checking attributes of the user, the resource, the action and the context against policies.
- 02API Key2An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
- 03Authentication3Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- 04Authorization4Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- 05bcrypt5bcrypt is a password-hashing function that adds a random salt and is deliberately slow, so stolen password hashes are very expensive to crack by guessing.
- 06Brute-Force Attack6A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
- 07Bug Bounty7A bug bounty is a program in which an organization rewards outside security researchers for finding and responsibly reporting vulnerabilities in its systems.
- 08Certificate Authority8A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
- 09Clickjacking9Clickjacking is an attack that hides a legitimate website inside an invisible frame on a malicious page, tricking users into clicking buttons they cannot see.
- 10Content Security Policy10A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
- 11CSRFCross-Site Request Forgery11CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
- 12CVECommon Vulnerabilities and Exposures12A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
- 13DDoSDistributed Denial of Service13A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
- 14Digital Signature14A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
- 15Encryption15Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- 16Encryption at Rest16Encryption at rest keeps stored data, such as disks, databases and backups, encrypted, so a stolen drive or copied file is unreadable without the key.
- 17End-to-End EncryptionE2EE17End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
- 18Hashing18Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- 19HMACHash-based Message Authentication Code19HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
- 20HSTSHTTP Strict Transport Security20HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
- 21HTTPSHypertext Transfer Protocol Secure21HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- 22Input Validation22Input validation is the practice of checking that data entering a program has the expected type, format and range before it is used, and rejecting the rest.
- 23JWTJSON Web Token23A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- 24Kerberos24Kerberos is a network authentication protocol in which a trusted server issues time-limited tickets, so users prove who they are without sending passwords.
- 25LDAPLightweight Directory Access Protocol25LDAP is an open protocol for searching and updating a directory service, the central database of an organization's users, groups and devices.
- 26Malware26Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
- 27Man-in-the-Middle Attack27A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
- 28OAuth28OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- 29OpenID ConnectOIDC29OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
- 30OWASP Top 1030The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
- 31Passkey31A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
- 32Penetration Testing32Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
- 33Phishing33Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
- 34Principle of Least Privilege34The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
- 35Prompt Injection35Prompt injection is an attack on LLM apps where attacker-written text is treated as instructions, so the model ignores its rules, leaks data or misuses tools.
- 36Public-Key Cryptography36Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- 37Ransomware37Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
- 38RBACRole-Based Access Control38RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
- 39Refresh Token39A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
- 40Salting40Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
- 41Same-Origin Policy41The same-origin policy is a browser security rule that stops scripts on one website from reading data from another site unless that site explicitly allows it.
- 42SAMLSecurity Assertion Markup Language42SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- 43Secrets Management43Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
- 44Session Hijacking44Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
- 45Social Engineering45Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
- 46SQL Injection46SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- 47SSLSecure Sockets Layer47SSL is the deprecated predecessor of TLS for encrypting connections; every version is insecure and prohibited, and today's "SSL" connections actually use TLS.
- 48SSOSingle Sign-On48SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- 49SSRFServer-Side Request Forgery49SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
- 50Supply Chain Attack50A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
- 51Symmetric Encryption51Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- 52TLSTransport Layer Security52TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- 53Two-Factor Authentication53Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- 54Web Application FirewallWAF54A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
- 55XSSCross-Site Scripting55XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- 56Zero Trust56Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- 57Zero-Day57A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.