web security Flashcards
1
Q
What is SQL Injection?
A
SQL injection is a code injection technique to either bypass authentication or insert malicious code that might destroy your database.
2
Q
Methods to protect from SQL injection?
A
- Sanitization of inputs parameters
- Use Prepared Statements
- Remove literals like ; or ‘
- Use escape for character
3
Q
Types of Cross site scripting( XSS)
A
- Non-persistent/Reflected XSS
- Persistent/Stored XSS
- DOM-based XSS
4
Q
Methods to protect from XSS
A
- Sanitization
2. Check if the input has js code
5
Q
Directory Traversal
A
6
Q
XSRF
A
7
Q
Clickjacking
A