This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Category:Attack
From OWASP
Revision as of 10:49, 25 May 2006 by Jeff Williams (talk | contribs)
This article is a stub. You can help OWASP by expanding it or discussing it on its Talk page.
This category is for common types of application security attacks. These are the techniques that attackers use to exploit the vulnerabilities in applications. Attacks are often confused with vulnerabilities, so please try to be sure that the attack you are describing is something that an attacker would do, rather than a weakness in an application.
Some items to add
- Brute Force Attacks
- Account Lockout
- Credential/Session Prediction
- Unauthorized Access Attempts
- Session Fixation
- Session Hijacking
- Cross-Site Scripting
- Buffer Overflow Attack
- Format String Attack
- Command Injection
- Directory Indexing
- File Path Abuse
- Traffic Flood
- Automation of Functionality
Subcategories
This category has the following 13 subcategories, out of 13 total.
A
D
E
I
P
R
S
Pages in category "Attack"
The following 73 pages are in this category, out of 73 total.
B
C
- Cache Poisoning
- Cash Overflow
- Code Injection
- Command Injection
- Comment Injection Attack
- Content Security Policy
- Content Spoofing
- Cornucopia - Ecommerce Website Edition - Wiki Deck
- CORS OriginHeaderScrutiny
- CORS RequestPreflighScrutiny
- Credential stuffing
- Cross Frame Scripting
- Cross Site History Manipulation (XSHM)
- Cross Site Tracing
- Cross-Site Request Forgery (CSRF)
- Cross-site Scripting (XSS)
- Cross-User Defacement
- Cryptanalysis
- CSV Injection
- Custom Special Character Injection