This category is for tagging common types of application security attacks.
What is an attack?
Attacks are the techniques that attackers use to exploit the vulnerabilities in applications. Attacks are often confused with vulnerabilities, so please try to be sure that the attack you are describing is something that an attacker would do, rather than a weakness in an application.
How to add a new Attack article
You can follow the instructions to make a new Attack article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the Attack category:
An attack article should include:
- a description of exactly how the attack works
- tools and techniques for performing the attack
- links to related threats, vulnerabilities, and countermeasures
Work to be done here includes
We're in the process of creating, organizing, and completing the attack articles. If you'd like to help, find some stub articles in this category and fill in the details.
Creating articles for the following topics:
- Credential/Session Prediction
- Unauthorized Access Attempts
- Cross-Site Scripting
- Format String Attack
- Directory Indexing
- File Path Abuse
- File location guessing (see Guessed or visible temporary file)
- URL Redirection
- ... make sure the attack is listed for each vulnerability
Note: many of the items marked vulnerabilities from CLASP and other places are really attacks. Some of the more obvious are:
This category has the following 13 subcategories, out of 13 total.
- ► Data Structure Attacks (2 P)
- ► Injection (30 P)
Pages in category "Attack"
The following 73 pages are in this category, out of 73 total.
- Cache Poisoning
- Cash Overflow
- Code Injection
- Command Injection
- Comment Injection Attack
- Content Security Policy
- Content Spoofing
- Cornucopia - Ecommerce Website Edition - Wiki Deck
- CORS OriginHeaderScrutiny
- CORS RequestPreflighScrutiny
- Credential stuffing
- Cross Frame Scripting
- Cross Site History Manipulation (XSHM)
- Cross Site Tracing
- Cross-Site Request Forgery (CSRF)
- Cross-site Scripting (XSS)
- Cross-User Defacement
- CSV Injection
- Custom Special Character Injection