From the course: ISACA Certified Information Systems Auditor (CISA) Cert Prep
Unlock this course with a free trial
Join today to access over 24,900 courses taught by industry experts.
Cross-site attacks
From the course: ISACA Certified Information Systems Auditor (CISA) Cert Prep
Cross-site attacks
- [Kelly] Let's look at one of the more common attacks towards websites, and that is cross-site scripting. And we also have cross-site request forgery that we're going to talk about in this category too, and they have some similarities and then a very essential sort of difference as far as how the exploits happen. But let's start off with cross-site scripting. Now, with cross-site scripting, the idea is we're going to exploit a vulnerable website. That's traditionally how cross-site scripting attacks have happened. So just like we talked about a few minutes ago, one of the easiest ways to prevent your site being maliciously commandeered for a cross-site scripting attack is to have good input validation. So again, like everything, these attacks that we talk about, we can defend against them, but we have to be security minded in order to do so, okay? So the way these cross-site scripting attacks happen is through input code injection. Alright? So couple of different types. There are…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
(Locked)
Introduction and privacy principles5m 40s
-
(Locked)
Physical and environmental controls3m 1s
-
(Locked)
Identity and access management5m 21s
-
(Locked)
SOCs and SLAs2m 48s
-
(Locked)
Networking basics11m 34s
-
(Locked)
The OSI and TCP reference models7m 9s
-
(Locked)
OSI Layers 1 and 215m 11s
-
(Locked)
OSI Layers 3–7 and TCP model15m 54s
-
(Locked)
Network devices10m 36s
-
(Locked)
NAT and PAT5m 38s
-
(Locked)
Firewalls10m 38s
-
(Locked)
Additional security devices, part 110m 23s
-
(Locked)
Additional security devices, part 26m 4s
-
(Locked)
Cryptography basics2m 23s
-
(Locked)
Symmetric cryptography9m 1s
-
(Locked)
Asymmetric cryptography18m 13s
-
(Locked)
Hybrid cryptography5m 21s
-
(Locked)
Integrity4m 45s
-
(Locked)
PKI and wrap-up6m 4s
-
(Locked)
Wireless security5m 6s
-
(Locked)
Indicators of attacks, part 114m 9s
-
(Locked)
Indicators of attacks, part 213m 13s
-
(Locked)
Indicators for application attacks7m 15s
-
(Locked)
Cross-site attacks9m 3s
-
(Locked)
Timing attacks6m 6s
-
(Locked)
Memory issues2m 20s
-
(Locked)
Network-based attacks18m 49s
-
(Locked)
Threat actors and vectors8m 17s
-
(Locked)