SLIDE 1
1
User Input Attacks
CPSC 328 Spring 2009
Review
- Abstract lower level security
- Provide end-to-end security
- User security info to server
- WS Security
- XML Encryption
- XML Signature
- Tokens
- Authentication/Authorization
- SAML
- XACML
- SSO
- Gathering System Information
- Site mapping
- Comments/error codes
- Library/plugin vulnerabilities