본문으로 건너뛰기
아카데미
초급 코드 지구

웹 보안

가장 흔한 공격으로부터 사용자를 지키세요.

Most attacks on websites are not clever. They abuse the same few mistakes, again and again, with automated tools. This track teaches you to look at your own app the way an attacker does, and then to close each door: SQL injection, cross-site scripting, weak password storage, stolen sessions, cross-site request forgery, leaked secrets, missing HTTPS and broken access control.

Every attack is shown in small, real code in JavaScript, Go, SQL and raw HTTP, next to the fix you can use today.

레슨
14
시간
2시간
난이도
초급

이 코스의 레슨은 당분간 영어로 제공돼요.

  • 브론즈 도전 가능
  • 실버 도전 가능
  • 골드 잠김

실력을 증명할 준비됐나요?

브론즈, 실버, 골드 세 가지 시험이 기다리고 있어요.

시험 보러 가기

이 코스를 마치면 할 수 있는 것

  • Treat every input as untrusted and stop SQL injection with parameterized queries
  • Prevent cross-site scripting with escaping, safe DOM methods and a Content Security Policy
  • Store passwords with Argon2id or bcrypt and slow down password guessing
  • Protect sessions with HttpOnly, Secure and SameSite cookies, and stop CSRF
  • Keep secrets out of code, and serve every page over HTTPS with security headers
  • Check on the server that every user may touch the data they ask for

여정

  1. 1
    챕터 1

    Think like an attacker

    Untrusted input, the OWASP Top 10, SQL injection, cross-site scripting and safe password storage.

    0 / 5
  2. 2
    챕터 2

    Protect the session

    Sessions and cookies, cross-site request forgery, access control, secrets, HTTPS and security headers.

    0 / 5
  3. 3
    챕터 3

    Next level

    Threat modelling, supply chain security, logging and alerting, and a hands-on security review.

    0 / 4

빠른 탐색