Security practice
Web Security
XSS, CSRF, SSRF, CSP — the web attacker's playbook.
- •200 XPXSS VariantsReflected, stored, DOM — same bug, three delivery modes.
- •200 XPCSRF & SameSiteForged requests, anti-CSRF tokens, SameSite cookies.
- •250 XPSSRFServer-side request forgery — IMDS, internal scans, allowlists, and the TOCTOU trap.
- •250 XPCORS DeepSame-origin policy, preflights, credentials, and the wildcard-vs-specific tension.
- •250 XPCSP In DepthNonces vs hashes, the unsafe-inline trap, Trusted Types.
- •200 XPClickjackingUI redress, X-Frame-Options vs frame-ancestors, and why frame-busting JS fails.
- •250 XPAuth BypassIDOR, JWT confusion, open redirects, mass assignment — the broken-access-control class.
- •250 XPPrototype PollutionJS-specific Object.prototype mutation. lodash/jQuery/express. Object.create(null) defense.
- •200 XPDependency VulnerabilitiesPackage CVE management. Lockfile hygiene. Dependabot vs Renovate. Patch fatigue.