威胁
约 1 分钟阅读
- threats modelWikipediaThreat modelthreats model · https://kamus.soluto.io/docs/threatmodeling/threatscontrols/ · https://cheatsheetseries.owasp.org/cheatsheets/ThreatModelingCheatSheet.html笔记:威胁
- cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html
- owasp.org/www-community/Threat_Modeling
- owasp.org/www-community/Threat_Modeling_Process
- www.microsoft.com/en-us/securityengineering/sdl/threatmodeling
WEB
- SQL Injection
- XSS - Cross Site Scripting
- CSRF - Cross Site Request Forgery
- IDOR - Insecure Direct Object Reference
- 通过修改 URL 参数访问其他用户的资源
- RCE - Remote Code Execution
- SSRF - Server-Side Request Forgery
- Hash Collision DoS - 哈希碰撞拒绝服务攻击
- Hashtable DoS
- bcrypt DoS
- CAPTCHA PoW
关联信息
反向链接和本文引用的外部资料。
References
Wikipedia
1 条- Threat modelWikipedia:Threat model
其他外链
5 条- cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.htmlcheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html
- kamus.soluto.io/docs/threatmodeling/threats_controlskamus.soluto.io/docs/threatmodeling/threats_controls
- owasp.org/www-community/Threat_Modelingowasp.org/www-community/Threat_Modeling
- owasp.org/www-community/Threat_Modeling_Processowasp.org/www-community/Threat_Modeling_Process
- www.microsoft.com/en-us/securityengineering/sdl/threatmodelingwww.microsoft.com/en-us/securityengineering/sdl/threatmodeling