# Web Sec + JWT Attacks + Not verifying signatures + Accepting without signatures + Weak secret + Self signed JWK parameters + File Uploads + Extension bypass + User uploadable folder + Configuration file upload + Information Disclosure + SQL Injection + In band + Error based + Union based + Boolean based + Time-based + Out-of-band + Cross-Site Scripting + Types: Stored, DOM-based, Reflected + Prevention: + CSP +
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up