Security




CS174

Chris Pollett

Apr 26,2017

Outline

Attacking Web-sites

XSS

Mitigations

CSRF

Mitigations

Inclusion Attacks

More on Inclusion Attacks

Mitigations

SQL Injection Attacks and Prevention

Click-Jacking

Mitigations

In-Class Exercise

target="_blank" Attack

Mitigations

HTTPS and the Secure Socket Layer

HTTPS: How it works

Configuring Apache for SSL

Creating a self-signed certificate

Using Openssl as a Client