Web 安全
保护你的用户免受最常见的攻击。
Most attacks on websites are not clever. They abuse the same few mistakes, again and again, with automated tools. This track teaches you to look at your own app the way an attacker does, and then to close each door: SQL injection, cross-site scripting, weak password storage, stolen sessions, cross-site request forgery, leaked secrets, missing HTTPS and broken access control.
Every attack is shown in small, real code in JavaScript, Go, SQL and raw HTTP, next to the fix you can use today.
- 课时
- 14
- 时长
- 2 小时
- 级别
- 初级
本课程的内容目前为英文。
- 铜牌 可挑战
- 银牌 可挑战
- 金牌 未解锁
准备好证明自己了吗?
三场考试正等着你:铜牌、银牌和金牌。
学完后你将能够
- Treat every input as untrusted and stop SQL injection with parameterized queries
- Prevent cross-site scripting with escaping, safe DOM methods and a Content Security Policy
- Store passwords with Argon2id or bcrypt and slow down password guessing
- Protect sessions with
HttpOnly,SecureandSameSitecookies, and stop CSRF - Keep secrets out of code, and serve every page over HTTPS with security headers
- Check on the server that every user may touch the data they ask for
学习旅程
1 第 1 单元Think like an attacker
Untrusted input, the OWASP Top 10, SQL injection, cross-site scripting and safe password storage.
0 / 52 第 2 单元Protect the session
Sessions and cookies, cross-site request forgery, access control, secrets, HTTPS and security headers.
0 / 53 第 3 单元Next level
Threat modelling, supply chain security, logging and alerting, and a hands-on security review.
0 / 4