Book 07
Security
Common attacks on web applications and the defenses against them, from authentication to encryption.
Contents
- 01API Key1An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
- 02Authentication2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- 03Authorization3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- 04Brute-Force Attack4A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
- 05Certificate Authority5A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
- 06Clickjacking6Clickjacking is an attack that hides a legitimate website inside an invisible frame on a malicious page, tricking users into clicking buttons they cannot see.
- 07Content Security Policy7A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
- 08CSRFCross-Site Request Forgery8CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
- 09CVECommon Vulnerabilities and Exposures9A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
- 10DDoSDistributed Denial of Service10A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
- 11Digital Signature11A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
- 12Encryption12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- 13End-to-End EncryptionE2EE13End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
- 14Hashing14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- 15HMACHash-based Message Authentication Code15HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
- 16HSTSHTTP Strict Transport Security16HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
- 17HTTPSHypertext Transfer Protocol Secure17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- 18Input Validation18Input validation is the practice of checking that data entering a program has the expected type, format and range before it is used, and rejecting the rest.
- 19JWTJSON Web Token19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- 20Malware20Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
- 21Man-in-the-Middle Attack21A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
- 22OAuth22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- 23OpenID ConnectOIDC23OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
- 24OWASP Top 1024The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
- 25Passkey25A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
- 26Penetration Testing26Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
- 27Phishing27Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
- 28Principle of Least Privilege28The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
- 29Prompt Injection29Prompt injection is an attack on LLM apps where attacker-written text is treated as instructions, so the model ignores its rules, leaks data or misuses tools.
- 30Public-Key Cryptography30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- 31Ransomware31Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
- 32RBACRole-Based Access Control32RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
- 33Refresh Token33A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
- 34Salting34Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
- 35Same-Origin Policy35The same-origin policy is a browser security rule that stops scripts on one website from reading data from another site unless that site explicitly allows it.
- 36SAMLSecurity Assertion Markup Language36SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- 37Secrets Management37Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
- 38Session Hijacking38Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
- 39Social Engineering39Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
- 40SQL Injection40SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- 41SSOSingle Sign-On41SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- 42SSRFServer-Side Request Forgery42SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
- 43Supply Chain Attack43A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
- 44Symmetric Encryption44Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- 45TLSTransport Layer Security45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- 46Two-Factor Authentication46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- 47Web Application FirewallWAF47A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
- 48XSSCross-Site Scripting48XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- 49Zero Trust49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- 50Zero-Day50A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.