SGreene > 1-10.3 Attack Vectors - Code > Flashcards
The process of validating the output of a process before it is returned to recipient
Output validation
Attack that uses a dot-dot-slash sequence
Directory traversal
Injection of malicious code into a vulnerable web application that will execute in a victims browser
Persistent Cross Site Scripting
Tricking an application into including unauthorized commands in the data sent to an interpreter
Injection Attack
Injection of malicious code into a web app that initiates at the client side and ultimately executes in the victim’s browser
Reflective Cross Site Scripting