What were the OWASP top 6 from 2017?
Injection, Broken Authentication, Sensitive Data Exposure, XML External Entities, Broken Access Control, Security Misconfiguration
What are some possible defenses to SQL injections?
Input Sanitization, Prepared Statements
What types of XSS attacks are there?
Non-persistent / Reflected XSS, Persistent / Stored XSS, DOM-based XSS
What are some difficulties with detecting DOM-based XSS?
What are some defenses against XSS?
Input sanitization, CSP
What are some defenses against XSRF?
XSRF Tokens, Limit Sessions, Multi-factor Auth, Check HTTP Referrer
What are countermeasures against Clickjacking?
Old: X-Frame-Options, Modern: CSP: frame-ancestors