THE ARCADE
Arcade
Profile
Sign in with GitHub
Home
/
Web Security
Security practice
Web Security
XSS, CSRF, SSRF, CSP — the web attacker's playbook.
← Back to all areas
2101
·
200 XP
XSS Variants
Reflected, stored, DOM — same bug, three delivery modes.
•
2102
·
200 XP
CSRF & SameSite
Forged requests, anti-CSRF tokens, SameSite cookies.
•
2105
·
250 XP
CSP In Depth
Nonces vs hashes, the unsafe-inline trap, Trusted Types.
•