White hat Talk Safe Learning Note (ii): client-side scripting security

Source: Internet
Author: User
The second client Script security Chapter 2nd browser Security 1. Homologous policy: Domain Division 2. Browser sandbox: Allow untrusted code to run in the sandbox for isolation; 3. Malicious URL interception: Public organizations to provide blacklists; EV digital certificate authentication secure website; 4. The high-speed development browser Security browser set the XSS attack principle, followed by the security policy, but the browser for the user's humanized use, the set of matching rules will often be exploited by hackers; Chapter 3rd cross-site scripting attacks (XSS)

1. Introduction to XSS

XSS refers to the hacker using HTML injection to tamper with the page, insert malicious script, so that users use,

The first is reflective XSS.

Also known as non-persistent XSS, by enticing users to click on a link,

The first is the storage-type XSS

4th Cross-site request forgery (CSRF) Chapter 5th Click Hijack (ClickJacking) 6th Chapter HTML 5 Security

White hat Talk Safe Learning Note (ii): client-side scripting security

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.