|
5 | 5 | * ###### Which architecture is more secure? 2 tier or 3 tier |
6 | 6 | * ###### Explain SSL Handshake |
7 | 7 | ###### https://www.youtube.com/watch?v=ubHZQrECeew |
8 | | -https://www.cloudflare.com/learning/ssl/how-does-ssl-work/ |
9 | | -https://www.cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake/ |
10 | | -* Recommend XXE mitigation for application which requires external entities to be called because of business requirement |
11 | | -* Explain CORS and SOP |
12 | | -https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS |
13 | | -https://portswigger.net/web-security/cors |
14 | | -https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy |
15 | | -https://www.bedefended.com/papers/cors-security-guide |
16 | | -* Does SOP mitigate CSRF attacks? |
17 | | -https://security.stackexchange.com/questions/157061/how-does-csrf-correlate-with-same-origin-policy |
| 8 | +###### https://www.cloudflare.com/learning/ssl/how-does-ssl-work/ |
| 9 | +###### https://www.cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake/ |
| 10 | +* ###### Recommend XXE mitigation for application which requires external entities to be called because of business requirement |
| 11 | +* ###### Explain CORS and SOP |
| 12 | +###### https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS |
| 13 | +###### https://portswigger.net/web-security/cors |
| 14 | +###### https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy |
| 15 | +###### https://www.bedefended.com/papers/cors-security-guide |
| 16 | +* ###### Does SOP mitigate CSRF attacks? |
| 17 | +###### https://security.stackexchange.com/questions/157061/how-does-csrf-correlate-with-same-origin-policy |
18 | 18 |
|
19 | | -* Exploiting SSRF attacks |
20 | | -https://portswigger.net/web-security/ssrf |
21 | | -https://www.hackerone.com/blog-How-To-Server-Side-Request-Forgery-SSRF |
22 | | -https://blog.appsecco.com/an-ssrf-privileged-aws-keys-and-the-capital-one-breach-4c3c2cded3af |
23 | | -* What is web cache deception? |
24 | | -https://blog.cloudflare.com/understanding-our-cache-and-the-web-cache-deception-attack/ |
25 | | -http://omergil.blogspot.com/2017/02/web-cache-deception-attack.html |
26 | | -https://portswigger.net/research/practical-web-cache-poisoning |
| 19 | +* ###### Exploiting SSRF attacks |
| 20 | +###### https://portswigger.net/web-security/ssrf |
| 21 | +###### https://www.hackerone.com/blog-How-To-Server-Side-Request-Forgery-SSRF |
| 22 | +###### https://blog.appsecco.com/an-ssrf-privileged-aws-keys-and-the-capital-one-breach-4c3c2cded3af |
| 23 | +* ###### What is web cache deception? |
| 24 | +###### https://blog.cloudflare.com/understanding-our-cache-and-the-web-cache-deception-attack/ |
| 25 | +###### http://omergil.blogspot.com/2017/02/web-cache-deception-attack.html |
| 26 | +###### https://portswigger.net/research/practical-web-cache-poisoning |
27 | 27 | * What is HTTP request smuggling? |
28 | 28 | http://projects.webappsec.org/w/page/13246928/HTTP%20Request%20Smuggling |
29 | 29 | https://portswigger.net/web-security/request-smuggling |
|
0 commit comments