Lecture 6
Lecture 6
NTU CNS Final Project Proposal
NTU CNS Final Project Proposal
Lab: Modifying serialized data types
Lab: Modifying serialized data types
Lab: Arbitrary object injection in PHP
Lab: Arbitrary object injection in PHP
Deserialization - APPRENTICE
Deserialization - APPRENTICE
Lab: CSRF where token is tied to non-session cookie
Posted on
|
Post modified
|
In
Security|Practice|Portswigger Web Security Academy|CSRF|Not Complete
|
Lab: CSRF where token is tied to non-session cookie
Lecture 4
Lecture 4
XXE - APPRENTICE
XXE - APPRENTICE
Lab: Exploiting `XInclude` to retrieve files
Lab: Exploiting XInclude to retrieve files
Lab: Exploiting XXE via image file upload
Lab: Exploiting XXE via image file upload
XSS - APPRENTICE
XSS - APPRENTICE
Lab: Stored DOM XSS
Lab: Stored DOM XSS
Lab: DOM XSS in `document.write` sink using source `location.search` inside a select element
Lab: DOM XSS in document.write sink using source location.search inside a select element
SQLi - APPRENTICE
SQLi - APPRENTICE
Lab: SQL injection attack, querying the database type and version on Oracle
Lab: SQL injection attack, querying the database type and version on Oracle
Lab: SQL injection attack, querying the database type and version on MySQL and Microsoft
Lab: SQL injection attack, querying the database type and version on MySQL and Microsoft
Lab: SQL injection attack, listing the database contents on non-Oracle databases
Lab: SQL injection attack, listing the database contents on non-Oracle databases
Lab: SQL injection attack, listing the database contents on Oracle
Lab: SQL injection attack, listing the database contents on Oracle
Lab: SQL injection UNION attack, retrieving multiple values in a single column
Lab: SQL injection UNION attack, retrieving multiple values in a single column
Lab: SQL injection UNION attack, retrieving data from other tables
Lab: SQL injection UNION attack, retrieving data from other tables
Lab: SQL injection UNION attack, finding a column containing text
Lab: SQL injection UNION attack, finding a column containing text
Lab: SQL injection UNION attack, determining the number of columns returned by the query
Lab: SQL injection UNION attack, determining the number of columns returned by the query
Lab: CSRF where token validation depends on token being present
Posted on
|
Post modified
|
In
Security|Practice|Portswigger Web Security Academy|CSRF|針對CSRF Token與同源政策的繞過手段
|
Lab: CSRF where token validation depends on token being present
Lab: CSRF where token validation depends on request method
Posted on
|
Post modified
|
In
Security|Practice|Portswigger Web Security Academy|CSRF|針對CSRF Token與同源政策的繞過手段
|
Lab: CSRF where token validation depends on request method
Lab: CSRF where token is not tied to user session
Posted on
|
Post modified
|
In
Security|Practice|Portswigger Web Security Academy|CSRF|針對CSRF Token與同源政策的繞過手段
|