I tried to apply for a Web security topic last week. The first application was rejected on the grounds that the topic was not clear and the second application was rejected. The real reason was that there was no relevant originality.Article! I thought I had to apply for a special topic and write an article first. It turned out that I understood it wrong. I had to talk about the Web security topic I was about to write.
I want to write data from four aspects: XSS, SQL injection, csrf, and improper web server configuration, in each aspect, we will explain the causes, dangers, verification methods, and suggestions for some modifications. Some of them will be inserted to demonstrate them for your understanding, because you need to demonstrate the effect to the university and cannot expose the real IP address of the problematic website, all the other websites except the local address will be hidden. If the features are not hidden, I also hope that the majority of users will not take advantage of it. My goal is to learn from everyone and build a safer web environment, rather than teach everyone to attack websites. Thank you for your understanding!