<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rpande</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rpande"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Rpande"/>
		<updated>2026-04-05T19:59:55Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:Attack&amp;diff=9227</id>
		<title>Category:Attack</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:Attack&amp;diff=9227"/>
				<updated>2006-08-23T03:30:08Z</updated>
		
		<summary type="html">&lt;p&gt;Rpande: /* Work to be done here includes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This category is for tagging common types of application security attacks. &lt;br /&gt;
&lt;br /&gt;
==What is an attack?==&lt;br /&gt;
&lt;br /&gt;
Attacks are the techniques that attackers use to exploit the vulnerabilities in applications. Attacks are often confused with vulnerabilities, so please try to be sure that the attack you are describing is something that an attacker would do, rather than a weakness in an application.&lt;br /&gt;
&lt;br /&gt;
{{Template:PutInCategory}}&lt;br /&gt;
&lt;br /&gt;
An attack article should include:&lt;br /&gt;
* a description of exactly how the attack works&lt;br /&gt;
* tools and techniques for performing the attack&lt;br /&gt;
* links to related threats, vulnerabilities, and countermeasures&lt;br /&gt;
&lt;br /&gt;
==Work to be done here includes==&lt;br /&gt;
&lt;br /&gt;
We're in the process of creating, organizing, and completing the attack articles. If you'd like to help, find some stub articles in this category and fill in the details.&lt;br /&gt;
&lt;br /&gt;
Creating articles for the following topics:&lt;br /&gt;
*Credential/Session Prediction&lt;br /&gt;
*Unauthorized Access Attempts&lt;br /&gt;
*Cross-Site Scripting&lt;br /&gt;
*Format String Attack&lt;br /&gt;
*Directory Indexing&lt;br /&gt;
*File Path Abuse&lt;br /&gt;
*Automation of Functionality (CSRF)&lt;br /&gt;
*File location guessing (see [[Guessed or visible temporary file]]&lt;br /&gt;
*URL Redirection&lt;br /&gt;
* ... make sure the attack is listed for each [[:Category:Vulnerability|vulnerability]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Note: many of the items marked vulnerabilities from CLASP and other places are really attacks. Some of the more obvious are:&lt;br /&gt;
* [[Command injection]]&lt;br /&gt;
* [[Log injection]]&lt;br /&gt;
* [[Resource exhaustion]]&lt;br /&gt;
* [[SQL injection]]&lt;br /&gt;
* [[Reflection injection]]&lt;br /&gt;
* [[Reflection attack in an auth protocol]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Article Type]]&lt;br /&gt;
[[Category:OWASP Honeycomb Project]]&lt;/div&gt;</summary>
		<author><name>Rpande</name></author>	</entry>

	</feed>