Skip to main content

Book 07 · Cheat sheet

Security

Common attacks on web applications and the defenses against them, from authentication to encryption.

01API Key
An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
  • An API key identifies the calling application or project.
  • It is sent with each request, usually in an HTTP header.
  • Anyone who has the key can use it, so treat it like a password.
02Authentication
Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
  • Authentication verifies identity; it answers the question who are you?
  • Factors are something you know, something you have, and something you are.
  • After login, a session cookie or token keeps the user authenticated.
03Authorization
Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
  • Authorization decides what an authenticated identity may do.
  • It always happens after authentication.
  • RBAC groups permissions into roles; ABAC uses attributes and context.
04Brute-Force Attack
A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
  • Brute-force attacks try many possible passwords or keys until one works.
  • Dictionary attacks, credential stuffing, and password spraying are common shortcuts.
  • Online attacks target sign-in forms; offline attacks target stolen password hashes.
05Certificate Authority
A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
  • A CA issues and signs certificates that bind a public key to a domain or identity.
  • Browsers trust a built-in set of root CAs and verify the chain of trust through intermediates.
  • Domain validation and renewal are commonly automated with the ACME protocol.
06Clickjacking
Clickjacking is an attack that hides a legitimate website inside an invisible frame on a malicious page, tricking users into clicking buttons they cannot see.
  • Clickjacking hides a real site in a transparent frame over a decoy page.
  • The victim's click lands on the hidden site and runs with their session.
  • CSRF tokens don't stop it, because the user really performs the click.
07Content Security Policy
A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
  • CSP is an HTTP header that restricts where a page can load resources from.
  • Its main purpose is to block injected scripts and reduce XSS damage.
  • Strict policies use nonces or hashes instead of long domain allowlists.
08CSRFCross-Site Request Forgery
CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
  • CSRF exploits cookies that browsers send automatically.
  • It targets state-changing actions, not reading data.
  • Anti-CSRF tokens prove a request came from the real site's own pages.
09CVECommon Vulnerabilities and Exposures
A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
  • A CVE ID uniquely identifies one publicly known vulnerability.
  • IDs follow the format CVE-YEAR-NUMBER and are assigned by CVE Numbering Authorities.
  • CVSS scores from 0.0 to 10.0 describe a vulnerability's technical severity.
10DDoSDistributed Denial of Service
A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
  • A DDoS attack floods a target with traffic from many devices to make it unavailable.
  • The traffic usually comes from a botnet of compromised computers and IoT devices.
  • Attacks can target network bandwidth, protocols, or the application itself.
11Digital Signature
A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
  • A digital signature proves who signed data and that it hasn't been altered.
  • It is created with a private key and verified with the matching public key.
  • Signing usually applies the private key to a hash of the data.
12Encryption
Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
  • Encryption turns plaintext into ciphertext that only key holders can read.
  • Symmetric encryption uses one shared key; asymmetric uses a public and private key pair.
  • Protect data both in transit (TLS) and at rest (disks, databases, backups).
13End-to-End EncryptionE2EE
End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
  • E2EE lets only the communicating users decrypt messages.
  • Servers relay ciphertext they cannot read.
  • The Signal Protocol, used by Signal and WhatsApp, is the common standard.
14Hashing
Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
  • A hash function maps any input to a fixed-length output.
  • The same input always produces the same hash.
  • Hashing is one-way, while encryption is reversible with a key.
15HMACHash-based Message Authentication Code
HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
  • HMAC uses a secret key and a hash to make a tamper-proof tag.
  • Only holders of the shared key can create or verify the tag.
  • Webhooks, HS256 JWTs, API request signing and signed cookies use it.
16HSTSHTTP Strict Transport Security
HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
  • HSTS tells browsers to use only HTTPS for a site for a set period.
  • It is sent in the Strict-Transport-Security response header over HTTPS.
  • It blocks SSL stripping and other downgrade attacks after the first visit.
17HTTPSHypertext Transfer Protocol Secure
HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
  • HTTPS is HTTP encrypted with TLS.
  • It provides confidentiality, integrity, and server authentication.
  • Certificates from trusted authorities prove a site's identity.
18Input Validation
Input validation is the practice of checking that data entering a program has the expected type, format and range before it is used, and rejecting the rest.
  • Validate all external input for type, length, format, and range before using it.
  • Prefer allowlists of what is permitted over denylists of what is forbidden.
  • Always validate on the server; client-side checks can be bypassed.
19JWTJSON Web Token
A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
  • A JWT has three parts: header, payload, and signature.
  • The signature proves the token has not been altered.
  • Anyone can read the payload, so it must not contain secrets.
20Malware
Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
  • Malware is software built to harm, spy, steal or take control.
  • Viruses, worms, trojans, spyware, rootkits and ransomware are common types.
  • It usually arrives through phishing, fake downloads or poisoned packages.
21Man-in-the-Middle Attack
A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
  • The attacker secretly relays, and can alter, traffic between two parties.
  • Common entry points include rogue Wi-Fi, ARP spoofing, DNS spoofing, and phishing proxies.
  • TLS with proper certificate validation is the main defense for network traffic.
22OAuth
OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
  • OAuth lets apps access resources without collecting users' passwords.
  • Users approve limited permissions called scopes.
  • Apps receive access tokens, usually short-lived, instead of credentials.
23OpenID ConnectOIDC
OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
  • OpenID Connect adds authentication on top of OAuth 2.0.
  • The provider issues a signed ID token (a JWT) describing the user.
  • Apps use the authorization code flow with PKCE.
24OWASP Top 10
The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
  • The OWASP Top 10 ranks the most critical categories of web application security risks.
  • It is published by OWASP, a nonprofit, and updated every few years from real-world data.
  • Broken access control is currently the top risk.
25Passkey
A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
  • A passkey is a key pair: the private key stays with the user, and the site stores the public key.
  • Users unlock passkeys with a biometric or device PIN instead of typing a password.
  • Passkeys are bound to one domain, which makes them resistant to phishing.
26Penetration Testing
Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
  • A penetration test is an authorized, simulated attack with a written scope and rules of engagement.
  • The goal is to find, prove, and help fix vulnerabilities, not to cause damage.
  • Black-box, gray-box, and white-box tests differ in how much the testers know upfront.
27Phishing
Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
  • Phishing tricks people into revealing credentials, codes, or money by impersonating someone trusted.
  • It arrives by email, text message, phone call, QR code, and chat apps.
  • Spear phishing targets specific people with personalized messages.
28Principle of Least Privilege
The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
  • Grant each user, service, and process only the permissions its task requires.
  • Prefer narrow, scoped, and temporary access over broad, permanent rights.
  • Run programs as unprivileged users rather than root or administrator.
29Prompt Injection
Prompt injection is an attack on LLM apps where attacker-written text is treated as instructions, so the model ignores its rules, leaks data or misuses tools.
  • Prompt injection makes a model treat attacker text as instructions.
  • Indirect injection hides instructions in pages, emails or documents the model reads.
  • It is most dangerous for AI agents with tools and access to private data.
30Public-Key Cryptography
Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
  • Each party has a key pair: a public key to share and a private key to keep secret.
  • Data encrypted with a public key can only be decrypted with the matching private key.
  • Signatures made with a private key can be verified by anyone with the public key.
31Ransomware
Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
  • Ransomware encrypts systems and demands payment for the key.
  • Double extortion adds the threat of leaking stolen data.
  • Attackers enter through phishing, stolen credentials or unpatched systems.
32RBACRole-Based Access Control
RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
  • Permissions are attached to roles, and users get permissions by being assigned roles.
  • RBAC is a form of authorization, which happens after authentication.
  • Least privilege means giving each role only the permissions it needs.
33Refresh Token
A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
  • Refresh tokens get new access tokens without a new login.
  • Access tokens stay short-lived to limit damage if they leak.
  • Refresh tokens go only to the token endpoint and need strong protection.
34Salting
Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
  • A salt is a unique random value added to each password before hashing.
  • Salts make identical passwords produce different hashes.
  • Salting defeats rainbow tables and forces attackers to crack each hash separately.
35Same-Origin Policy
The same-origin policy is a browser security rule that stops scripts on one website from reading data from another site unless that site explicitly allows it.
  • The same-origin policy stops scripts on one origin from reading data from another.
  • An origin is the scheme, host, and port together.
  • Cross-origin sending and embedding are mostly allowed; reading the results is blocked.
36SAMLSecurity Assertion Markup Language
SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
  • SAML is an XML-based standard for single sign-on.
  • SAML 2.0 dates from 2005 and is widespread in enterprises.
  • The identity provider sends a signed assertion to the service provider.
37Secrets Management
Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
  • Secrets include passwords, API keys, tokens, certificates, and private keys.
  • Never hard-code secrets or commit them to version control.
  • Store secrets in an encrypted secrets manager with access policies and audit logs.
38Session Hijacking
Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
  • Session hijacking steals a user's session ID or token to impersonate them.
  • Common sources are XSS, malware, unencrypted traffic, leaked URLs or logs, and predictable IDs.
  • Use Secure, HttpOnly, and SameSite cookies, HTTPS, and long random IDs.
39Social Engineering
Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
  • Social engineering manipulates people instead of hacking systems.
  • Phishing, vishing, smishing, pretexting, baiting and tailgating are common forms.
  • Attackers exploit urgency, authority, fear and helpfulness.
40SQL Injection
SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
  • SQL injection occurs when user input becomes part of a query's code.
  • It can expose, modify, or delete data and bypass logins.
  • Parameterized queries are the primary defense.
41SSOSingle Sign-On
SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
  • One login at a central identity provider gives access to many applications.
  • Apps receive a signed SAML assertion or OpenID Connect ID token, not the user's password.
  • OpenID Connect is built on OAuth 2.0; SAML is common in enterprise software.
42SSRFServer-Side Request Forgery
SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
  • SSRF makes a server send requests to destinations chosen by an attacker.
  • It can reach internal services, admin panels, and cloud metadata endpoints.
  • Naive blocklists are bypassed with alternative IP formats, DNS tricks, and redirects.
43Supply Chain Attack
A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
  • Supply chain attacks compromise a trusted dependency, tool, or update to reach its users.
  • Typosquatting, dependency confusion, account takeover, and build compromise are common methods.
  • Lockfiles and pinned versions make builds reproducible and harder to tamper with.
44Symmetric Encryption
Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
  • Symmetric encryption uses one shared key to encrypt and decrypt.
  • AES is the standard algorithm; ChaCha20 is a common alternative.
  • Authenticated modes such as AES-GCM also detect tampering.
45TLSTransport Layer Security
TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
  • TLS encrypts network traffic and verifies the server's identity.
  • It replaced SSL, which is obsolete and insecure.
  • The handshake checks the certificate and agrees on session keys.
46Two-Factor Authentication
Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
  • 2FA requires two different types of proof to log in.
  • A stolen password alone is no longer enough to take over an account.
  • Authenticator apps, security keys, and passkeys are stronger than SMS codes.
47Web Application FirewallWAF
A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
  • A WAF filters HTTP requests at the application layer.
  • It blocks patterns such as SQL injection, XSS and abusive bots.
  • It often runs in a CDN or reverse proxy; ModSecurity is a common engine.
48XSSCross-Site Scripting
XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
  • XSS lets attacker-supplied scripts run in other users' browsers.
  • It is caused by inserting untrusted data into pages without encoding.
  • The three main types are stored, reflected, and DOM-based XSS.
49Zero Trust
Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
  • Zero trust assumes no user, device, or network is trusted by default.
  • Every request is authenticated, authorized, and encrypted.
  • Being inside the corporate network grants no automatic access.
50Zero-Day
A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.
  • A zero-day is a vulnerability with no fix available yet.
  • Defenders have had zero days to prepare when it is first exploited.
  • Zero-day exploits are traded and are worth a lot of money.
50 terms from Software Dictionary. Full explanations, examples and FAQs at softwaredictionary.org/categories/security

Back to the bookTip: pick "Save as PDF" in the print dialog to keep a copy.

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings