跳到主要内容
返回

Web 安全

银牌考试

Twenty-four questions across the whole course at working depth: read real code, spot the usual holes, choose the right fix and run the everyday commands. Think about what happens when each value is hostile.

  • 16 道题
  • 20 分钟
  • 及格线 80%
  • 至少 6 道实操题
考查范围 SQL injectionCross-site scriptingPasswordsSessions, cookies and CSRFAccess controlSecrets and HTTPSSupply chainLogging and alertingThreat modeling

计时无法暂停,中途离开也会算作一次作答。