Book 07 · Cheat sheet
Security
Common attacks on web applications and the defenses against them, from authentication to encryption.
Software Dictionary · softwaredictionary.org/categories/security/cheat-sheet
- 01API Key
- An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
- An API key identifies the calling application or project.
- It is sent with each request, usually in an HTTP header.
- Anyone who has the key can use it, so treat it like a password.
- 02Authentication
- Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- Authentication verifies identity; it answers the question who are you?
- Factors are something you know, something you have, and something you are.
- After login, a session cookie or token keeps the user authenticated.
- 03Authorization
- Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- Authorization decides what an authenticated identity may do.
- It always happens after authentication.
- RBAC groups permissions into roles; ABAC uses attributes and context.
- 04Brute-Force Attack
- A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
- Brute-force attacks try many possible passwords or keys until one works.
- Dictionary attacks, credential stuffing, and password spraying are common shortcuts.
- Online attacks target sign-in forms; offline attacks target stolen password hashes.
- 05Certificate Authority
- A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
- A CA issues and signs certificates that bind a public key to a domain or identity.
- Browsers trust a built-in set of root CAs and verify the chain of trust through intermediates.
- Domain validation and renewal are commonly automated with the ACME protocol.
- 06Clickjacking
- Clickjacking is an attack that hides a legitimate website inside an invisible frame on a malicious page, tricking users into clicking buttons they cannot see.
- Clickjacking hides a real site in a transparent frame over a decoy page.
- The victim's click lands on the hidden site and runs with their session.
- CSRF tokens don't stop it, because the user really performs the click.
- 07Content Security Policy
- A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
- CSP is an HTTP header that restricts where a page can load resources from.
- Its main purpose is to block injected scripts and reduce XSS damage.
- Strict policies use nonces or hashes instead of long domain allowlists.
- 08CSRFCross-Site Request Forgery
- CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
- CSRF exploits cookies that browsers send automatically.
- It targets state-changing actions, not reading data.
- Anti-CSRF tokens prove a request came from the real site's own pages.
- 09CVECommon Vulnerabilities and Exposures
- A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
- A CVE ID uniquely identifies one publicly known vulnerability.
- IDs follow the format CVE-YEAR-NUMBER and are assigned by CVE Numbering Authorities.
- CVSS scores from 0.0 to 10.0 describe a vulnerability's technical severity.
- 10DDoSDistributed Denial of Service
- A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
- A DDoS attack floods a target with traffic from many devices to make it unavailable.
- The traffic usually comes from a botnet of compromised computers and IoT devices.
- Attacks can target network bandwidth, protocols, or the application itself.
- 11Digital Signature
- A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
- A digital signature proves who signed data and that it hasn't been altered.
- It is created with a private key and verified with the matching public key.
- Signing usually applies the private key to a hash of the data.
- 12Encryption
- Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- Encryption turns plaintext into ciphertext that only key holders can read.
- Symmetric encryption uses one shared key; asymmetric uses a public and private key pair.
- Protect data both in transit (TLS) and at rest (disks, databases, backups).
- 13End-to-End EncryptionE2EE
- End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
- E2EE lets only the communicating users decrypt messages.
- Servers relay ciphertext they cannot read.
- The Signal Protocol, used by Signal and WhatsApp, is the common standard.
- 14Hashing
- Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- A hash function maps any input to a fixed-length output.
- The same input always produces the same hash.
- Hashing is one-way, while encryption is reversible with a key.
- 15HMACHash-based Message Authentication Code
- HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
- HMAC uses a secret key and a hash to make a tamper-proof tag.
- Only holders of the shared key can create or verify the tag.
- Webhooks, HS256 JWTs, API request signing and signed cookies use it.
- 16HSTSHTTP Strict Transport Security
- HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
- HSTS tells browsers to use only HTTPS for a site for a set period.
- It is sent in the Strict-Transport-Security response header over HTTPS.
- It blocks SSL stripping and other downgrade attacks after the first visit.
- 17HTTPSHypertext Transfer Protocol Secure
- HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- HTTPS is HTTP encrypted with TLS.
- It provides confidentiality, integrity, and server authentication.
- Certificates from trusted authorities prove a site's identity.
- 18Input Validation
- Input validation is the practice of checking that data entering a program has the expected type, format and range before it is used, and rejecting the rest.
- Validate all external input for type, length, format, and range before using it.
- Prefer allowlists of what is permitted over denylists of what is forbidden.
- Always validate on the server; client-side checks can be bypassed.
- 19JWTJSON Web Token
- A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- A JWT has three parts: header, payload, and signature.
- The signature proves the token has not been altered.
- Anyone can read the payload, so it must not contain secrets.
- 20Malware
- Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
- Malware is software built to harm, spy, steal or take control.
- Viruses, worms, trojans, spyware, rootkits and ransomware are common types.
- It usually arrives through phishing, fake downloads or poisoned packages.
- 21Man-in-the-Middle Attack
- A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
- The attacker secretly relays, and can alter, traffic between two parties.
- Common entry points include rogue Wi-Fi, ARP spoofing, DNS spoofing, and phishing proxies.
- TLS with proper certificate validation is the main defense for network traffic.
- 22OAuth
- OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- OAuth lets apps access resources without collecting users' passwords.
- Users approve limited permissions called scopes.
- Apps receive access tokens, usually short-lived, instead of credentials.
- 23OpenID ConnectOIDC
- OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
- OpenID Connect adds authentication on top of OAuth 2.0.
- The provider issues a signed ID token (a JWT) describing the user.
- Apps use the authorization code flow with PKCE.
- 24OWASP Top 10
- The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
- The OWASP Top 10 ranks the most critical categories of web application security risks.
- It is published by OWASP, a nonprofit, and updated every few years from real-world data.
- Broken access control is currently the top risk.
- 25Passkey
- A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
- A passkey is a key pair: the private key stays with the user, and the site stores the public key.
- Users unlock passkeys with a biometric or device PIN instead of typing a password.
- Passkeys are bound to one domain, which makes them resistant to phishing.
- 26Penetration Testing
- Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
- A penetration test is an authorized, simulated attack with a written scope and rules of engagement.
- The goal is to find, prove, and help fix vulnerabilities, not to cause damage.
- Black-box, gray-box, and white-box tests differ in how much the testers know upfront.
- 27Phishing
- Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
- Phishing tricks people into revealing credentials, codes, or money by impersonating someone trusted.
- It arrives by email, text message, phone call, QR code, and chat apps.
- Spear phishing targets specific people with personalized messages.
- 28Principle of Least Privilege
- The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
- Grant each user, service, and process only the permissions its task requires.
- Prefer narrow, scoped, and temporary access over broad, permanent rights.
- Run programs as unprivileged users rather than root or administrator.
- 29Prompt Injection
- Prompt injection is an attack on LLM apps where attacker-written text is treated as instructions, so the model ignores its rules, leaks data or misuses tools.
- Prompt injection makes a model treat attacker text as instructions.
- Indirect injection hides instructions in pages, emails or documents the model reads.
- It is most dangerous for AI agents with tools and access to private data.
- 30Public-Key Cryptography
- Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- Each party has a key pair: a public key to share and a private key to keep secret.
- Data encrypted with a public key can only be decrypted with the matching private key.
- Signatures made with a private key can be verified by anyone with the public key.
- 31Ransomware
- Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
- Ransomware encrypts systems and demands payment for the key.
- Double extortion adds the threat of leaking stolen data.
- Attackers enter through phishing, stolen credentials or unpatched systems.
- 32RBACRole-Based Access Control
- RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
- Permissions are attached to roles, and users get permissions by being assigned roles.
- RBAC is a form of authorization, which happens after authentication.
- Least privilege means giving each role only the permissions it needs.
- 33Refresh Token
- A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
- Refresh tokens get new access tokens without a new login.
- Access tokens stay short-lived to limit damage if they leak.
- Refresh tokens go only to the token endpoint and need strong protection.
- 34Salting
- Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
- A salt is a unique random value added to each password before hashing.
- Salts make identical passwords produce different hashes.
- Salting defeats rainbow tables and forces attackers to crack each hash separately.
- 35Same-Origin Policy
- The same-origin policy is a browser security rule that stops scripts on one website from reading data from another site unless that site explicitly allows it.
- The same-origin policy stops scripts on one origin from reading data from another.
- An origin is the scheme, host, and port together.
- Cross-origin sending and embedding are mostly allowed; reading the results is blocked.
- 36SAMLSecurity Assertion Markup Language
- SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
- SAML is an XML-based standard for single sign-on.
- SAML 2.0 dates from 2005 and is widespread in enterprises.
- The identity provider sends a signed assertion to the service provider.
- 37Secrets Management
- Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
- Secrets include passwords, API keys, tokens, certificates, and private keys.
- Never hard-code secrets or commit them to version control.
- Store secrets in an encrypted secrets manager with access policies and audit logs.
- 38Session Hijacking
- Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
- Session hijacking steals a user's session ID or token to impersonate them.
- Common sources are XSS, malware, unencrypted traffic, leaked URLs or logs, and predictable IDs.
- Use Secure, HttpOnly, and SameSite cookies, HTTPS, and long random IDs.
- 39Social Engineering
- Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
- Social engineering manipulates people instead of hacking systems.
- Phishing, vishing, smishing, pretexting, baiting and tailgating are common forms.
- Attackers exploit urgency, authority, fear and helpfulness.
- 40SQL Injection
- SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- SQL injection occurs when user input becomes part of a query's code.
- It can expose, modify, or delete data and bypass logins.
- Parameterized queries are the primary defense.
- 41SSOSingle Sign-On
- SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
- One login at a central identity provider gives access to many applications.
- Apps receive a signed SAML assertion or OpenID Connect ID token, not the user's password.
- OpenID Connect is built on OAuth 2.0; SAML is common in enterprise software.
- 42SSRFServer-Side Request Forgery
- SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
- SSRF makes a server send requests to destinations chosen by an attacker.
- It can reach internal services, admin panels, and cloud metadata endpoints.
- Naive blocklists are bypassed with alternative IP formats, DNS tricks, and redirects.
- 43Supply Chain Attack
- A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
- Supply chain attacks compromise a trusted dependency, tool, or update to reach its users.
- Typosquatting, dependency confusion, account takeover, and build compromise are common methods.
- Lockfiles and pinned versions make builds reproducible and harder to tamper with.
- 44Symmetric Encryption
- Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- Symmetric encryption uses one shared key to encrypt and decrypt.
- AES is the standard algorithm; ChaCha20 is a common alternative.
- Authenticated modes such as AES-GCM also detect tampering.
- 45TLSTransport Layer Security
- TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- TLS encrypts network traffic and verifies the server's identity.
- It replaced SSL, which is obsolete and insecure.
- The handshake checks the certificate and agrees on session keys.
- 46Two-Factor Authentication
- Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- 2FA requires two different types of proof to log in.
- A stolen password alone is no longer enough to take over an account.
- Authenticator apps, security keys, and passkeys are stronger than SMS codes.
- 47Web Application FirewallWAF
- A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
- A WAF filters HTTP requests at the application layer.
- It blocks patterns such as SQL injection, XSS and abusive bots.
- It often runs in a CDN or reverse proxy; ModSecurity is a common engine.
- 48XSSCross-Site Scripting
- XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- XSS lets attacker-supplied scripts run in other users' browsers.
- It is caused by inserting untrusted data into pages without encoding.
- The three main types are stored, reflected, and DOM-based XSS.
- 49Zero Trust
- Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- Zero trust assumes no user, device, or network is trusted by default.
- Every request is authenticated, authorized, and encrypted.
- Being inside the corporate network grants no automatic access.
- 50Zero-Day
- A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.
- A zero-day is a vulnerability with no fix available yet.
- Defenders have had zero days to prepare when it is first exploited.
- Zero-day exploits are traded and are worth a lot of money.