SLIDE 1
Last Few Lectures
- XSS - Cross-site scripting
- XSRF/CSRF - Cross-site request forgery
SQL Injection Last Few Lectures XSS - Cross-site scripting - - PowerPoint PPT Presentation
SQL Injection Last Few Lectures XSS - Cross-site scripting XSRF/CSRF - Cross-site request forgery Code Injection Attacks Attacker executes arbitrary code on server Programming the program Not sanitizing user
server
function
SQL query
data to attacker
https://xkcd.com/327/
what input you expect.