Privilege escalation
Data Execution Prevention
- Ex: data in the data section can’t run
Address Space Layout Randomization
Horizontal level access
CVE 2020-1530
Cross-site scripting
Non-persistent (reflected) XSS attack
Persistent (stored) XSS attack
Reflected vs stored XSS attack
Protecting yourself against XSS
Injection attacks
SQL Injection
XML Injection
LDAP Injection
DLL Injection
Buffer Overflow Attack
Cross-site requests
Cross site request forgery
SSRF
Traditional anti-virus
Zero-day attack
Driver attack
Shimming
Refactoring