Injection attacks
SQL injection
Buffer overflows
Replay attack
Privilege escalation
Gain higher-level access to a system– Exploit a vulnerability– Might be a bug or design flaw
* Higher-level access means more capabilities– This commonly is the highest-level access– This is obviously a concern
* These are high-priority vulnerability patches– You want to get these holes closed very quickly– Any user can be an administrator
* Horizontal privilege escalation– User A can access user B resources
Mitigating privilege escalation
Cross-site requests
The client and the server
Cross-site request forgery
Directory traversal
Cross Site request forgery