Skip to main content

Book 07

Security

Common attacks on web applications and the defenses against them, from authentication to encryption.

Contents

  1. 01API Key1An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
  2. 02Authentication2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
  3. 03Authorization3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
  4. 04Brute-Force Attack4A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
  5. 05Certificate Authority5A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
  6. 06Clickjacking6Clickjacking is an attack that hides a legitimate website inside an invisible frame on a malicious page, tricking users into clicking buttons they cannot see.
  7. 07Content Security Policy7A Content Security Policy is an HTTP response header that tells the browser which scripts, styles, and other resources a page may load, blocking injected code.
  8. 08CSRF8CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
  9. 09CVE9A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
  10. 10DDoS10A DDoS attack is an attempt to make a website or online service unavailable by flooding it with traffic from many compromised devices at the same time.
  11. 11Digital Signature11A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
  12. 12Encryption12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
  13. 13End-to-End Encryption13End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
  14. 14Hashing14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
  15. 15HMAC15HMAC combines a secret key with a hash function to produce a tag that proves a message came from someone who knows the key and wasn't changed on the way.
  16. 16HSTS16HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
  17. 17HTTPS17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
  18. 18Input Validation18Input validation is the practice of checking that data entering a program has the expected type, format and range before it is used, and rejecting the rest.
  19. 19JWT19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
  20. 20Malware20Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
  21. 21Man-in-the-Middle Attack21A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
  22. 22OAuth22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
  23. 23OpenID Connect23OpenID Connect (OIDC) is an identity layer on OAuth 2.0 that lets an app sign users in via an identity provider and get a signed token saying who they are.
  24. 24OWASP Top 1024The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
  25. 25Passkey25A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
  26. 26Penetration Testing26Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
  27. 27Phishing27Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
  28. 28Principle of Least Privilege28The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
  29. 29Prompt Injection29Prompt injection is an attack on LLM apps where attacker-written text is treated as instructions, so the model ignores its rules, leaks data or misuses tools.
  30. 30Public-Key Cryptography30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
  31. 31Ransomware31Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
  32. 32RBAC32RBAC is an authorization model that grants permissions to roles, such as admin or editor, and then gives users access by assigning them those roles.
  33. 33Refresh Token33A refresh token is a long-lived credential an app uses to get new short-lived access tokens, so the user stays signed in without logging in again.
  34. 34Salting34Salting is the practice of adding a unique random value to each password before hashing it, so identical passwords produce different hashes and resist cracking.
  35. 35Same-Origin Policy35The same-origin policy is a browser security rule that stops scripts on one website from reading data from another site unless that site explicitly allows it.
  36. 36SAML36SAML is an XML-based single sign-on standard: an identity provider authenticates the user and sends the application a signed assertion that logs them in.
  37. 37Secrets Management37Secrets management is the practice of securely storing, distributing, rotating, and auditing sensitive credentials such as passwords, API keys, and tokens.
  38. 38Session Hijacking38Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
  39. 39Social Engineering39Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
  40. 40SQL Injection40SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
  41. 41SSO41SSO lets a user sign in once with a central identity provider and then access many separate applications without entering credentials again.
  42. 42SSRF42SSRF is a vulnerability where an attacker makes a server send requests to a destination of their choice, often reaching internal systems they can't access.
  43. 43Supply Chain Attack43A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
  44. 44Symmetric Encryption44Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
  45. 45TLS45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
  46. 46Two-Factor Authentication46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
  47. 47Web Application Firewall47A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
  48. 48XSS48XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
  49. 49Zero Trust49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
  50. 50Zero-Day50A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.

Back to the libraryNext book: AI & Machine Learning

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings