Web Application Security
Studies in this cluster, in series order. Each one keeps its own URL.
Security
AuthN, AuthZ, OAuth/OIDC, OWASP web attacks (injection, XSS, CSRF, SSRF, CORS), secrets/KMS, tokens, and service identity you can defend in interviews.
Web Application Security
6 studies- 1.Web Application Security - OWASP Top 10, Injection, XSS, CSRF & SSRFAlmost every web bug on the OWASP Top 10 is untrusted data parsed as code or as authority at a sink. Fix that sink with an API that keeps code and data apart, then add a second platform layer for the day the first control is skipped.
- 2.Injection Attacks - SQLi, Command & Template Injection, Parameterized QueriesInjection is string-built commands: SQL, a shell, a template, LDAP, or a NoSQL query. The attacker's bytes close your literal and open theirs. Bind values, pass argv, and allowlist identifiers. Escaping is the fallback you will get wrong.
- 3.Cross-Site Scripting (XSS) - Contextual Encoding, Strict CSP Nonces & Trusted TypesXSS is attacker JavaScript running in your origin. Reflected, stored, and DOM XSS are three delivery routes. Contextual encoding is the fix. A strict nonce CSP and Trusted Types are the layer that still blocks the script when someone uses an escape hatch.
- 4.CSRF - SameSite Cookies, Anti-CSRF Tokens & Fetch MetadataCSRF works because the browser attaches cookies by itself. A page on another site can submit a form to yours, and the session rides along. SameSite, a CSRF token, and Origin or Sec-Fetch-Site each prove the request came from your pages. Bearer headers set by your own script are a different trade.
- 5.SSRF - Cloud Metadata, DNS Rebinding, Redirects & Egress AllowlistsSSRF is your server fetching a URL the attacker chose. The request leaves from inside your network, often with the host's cloud role. Metadata at 169.254.169.254 is the famous target. Pin the resolved IP, re-check every redirect, allowlist egress, require IMDSv2 with hop limit 1, and keep that role small.
- 6.CORS & Security Headers - Same-Origin Policy, Misconfigurations, HSTS & CSPThe same-origin policy stops a script on another site from reading your responses. CORS is the opt-in that relaxes that rule. It never adds protection. Reflecting any Origin together with credentials lets any site read a logged-in user's data. A short header baseline closes clickjacking, MIME sniffing, and SSL stripping beside that.