Web 安全
银牌考试
Twenty-four questions across the whole course at working depth: read real code, spot the usual holes, choose the right fix and run the everyday commands. Think about what happens when each value is hostile.
- 16 道题
- 20 分钟
- 及格线 80%
- 至少 6 道实操题
考查范围 SQL injectionCross-site scriptingPasswordsSessions, cookies and CSRFAccess controlSecrets and HTTPSSupply chainLogging and alertingThreat modeling
计时无法暂停,中途离开也会算作一次作答。