[Security] Frontend Security
-
XSS (Cross-Site Scripting): XSS is a type of injection security vulnerability where malicious scripts are injected into trusted websites. These scripts can then be executed by the browser of any user who visits the compromised website. XSS can lead to various threats such as identity theft, data theft, and malicious redirection. There are three types of XSS attacks: stored XSS, reflected XSS, and DOM-based XSS.
-
CSRF (Cross-Site Request Forgery): CSRF is an attack that tricks the victim into submitting a malicious request. It exploits the trust that a website has in a user's browser. In this attack, the victim is forced to execute unwanted actions on a web application in which they're authenticated. These actions could range from changing their email address, password, to even more serious actions like making purchases.
-
UI Redressing: UI Redressing is a technique used by attackers to trick users into performing actions they did not intend to do. This is usually accomplished through the use of transparent layers (or "invisible" layers) that are overlaid on the expected UI elements. The most common type of UI Redressing attack is clickjacking, where the attacker tricks the user into clicking on something different from what the user perceives.
-
MITM (Man-in-the-Middle): A man-in-the-middle attack is a type of eavesdropping attack, where the attacker intercepts and potentially alters the communication between two parties without their knowledge. This can happen in any form of online communication, such as email, social media, web surfing, etc. Attackers could potentially steal login credentials, personal information, or even alter a conversation to achieve their goals.
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 阿里最新开源QwQ-32B,效果媲美deepseek-r1满血版,部署成本又又又降低了!
· Manus重磅发布:全球首款通用AI代理技术深度解析与实战指南
· 开源Multi-agent AI智能体框架aevatar.ai,欢迎大家贡献代码
· 被坑几百块钱后,我竟然真的恢复了删除的微信聊天记录!
· AI技术革命,工作效率10个最佳AI工具
2022-06-23 [Typescript] Awaited Type
2021-06-23 [AWS Lambda] Convert a Express node.js app to serverless
2021-06-23 [Cloud DA] Best Practices for Serverless
2016-06-23 [Webpack 2] Chunking common modules from multiple apps with the Webpack CommonsChunkPlugin
2016-06-23 [Webpack 2] Grouping vendor files with the Webpack CommonsChunkPlugin
2013-06-23 【PHP 】 伪静态 - 3. 伪静态的基本使用
2013-06-23 【PHP 】伪静态 - 4. 实际运用