Sec24_03_WebAttacks.pdf
Threat Model
- Web Security
- Network Security
Web Attacker
- Controls
attacker.com
- Can obtain SSL/TLS cert
Network Attacker
Types of Web Attacks
- HTTP
- Document Object Model
- Image Tag
- Use another URL
- Hide resulting image
- Spoof other sites
Comparison to Operating Systems
- Primitives
- Primitives (Web)
- DOM
- Frames
- Cookies/localstorage
- Principals: Users
- Discretionary access control
- Principles: Origins (Web)
Browser Security Mechanism