## Занятие 3. Основные атаки и паттерны ## SQL-injection уязвимости:  ### https://portswigger.net/web-security/sql-injection/lab-login-bypass  ### https://portswigger.net/web-security/sql-injection/lab-retrieve-hidden-data   ### https://portswigger.net/web-security/sql-injection/union-attacks/lab-retrieve-data-from-other-tables   ### https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-mysql-microsoft  ## XSS уязвимости: ### https://portswigger.net/web-security/cross-site-scripting/stored/lab-html-context-nothing-encoded    ### https://portswigger.net/web-security/cross-site-scripting/dom-based/lab-document-write-sink  ### https://portswigger.net/web-security/cross-site-scripting/contexts/lab-javascript-string-angle-brackets-html-encoded  ### https://portswigger.net/web-security/cross-site-scripting/dom-based/lab-dom-xss-reflected  ## CSRF ### https://portswigger.net/web-security/csrf/lab-no-defenses   ### https://portswigger.net/web-security/csrf/lab-token-validation-depends-on-request-method  ## SSRF ### https://portswigger.net/web-security/ssrf/lab-basic-ssrf-against-localhost   ## https://portswigger.net/web-security/ssrf/lab-ssrf-filter-bypass-via-open-redirection  ## RCE: ### https://portswigger.net/web-security/os-command-injection/lab-simple   ## Path traversal: ### https://portswigger.net/web-security/file-path-traversal/lab-simple  ### https://portswigger.net/web-security/file-path-traversal/lab-absolute-path-bypass 
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up