OWL SECTORCyber Security - Freemont Starfire Cadet Squadron
Lesson 05 / 05 · 15–20 minutes

Web Exploitation

Web exploitation takes advantage of weaknesses in websites. Understanding those weaknesses helps us build and use safer systems.

What you’ll learn

  • Explain what the browser controls and what the server must check.
  • Recognize access-control, injection, and scripting problems.
  • Practice in a simulation with explicit permission.

Browser versus server

The browser displays HTML, styles, and JavaScript. The server handles requests and should enforce access rules. Anything sent to the browser can be inspected or changed by its user. Hiding a button, answer, or password in page source does not protect it. Secrets and authoritative validation belong on the server.

Broken access control

Authentication asks “Who are you?” Authorization asks “Are you allowed to do this?” A logged-in user should not be able to read someone else’s private records by changing an ID in a URL. The server must check permission for every protected request.

Injection and cross-site scripting

Injection happens when untrusted input is treated as instructions, such as part of a database query. Parameterized queries help keep data separate from SQL instructions. Cross-site scripting (XSS) happens when untrusted content runs as script in another user’s browser. Context-appropriate output encoding and safe rendering help prevent it.

Test with permission

Use training labs or systems you are explicitly authorized to test, within the agreed scope. Do not try attacks on unrelated sites. For your own applications, keep software updated, protect sessions, validate input, encode output, and enforce permissions on the server. HTTPS protects transport; it does not fix application bugs.

Try it

Access-control simulator

You are signed in as Alex. Alex owns note 101; Jordan owns note 102. Change the requested note and compare a vulnerable server with a protected one. This simulation sends no network requests.

All names and notes are fictional. A real server must enforce this check regardless of changes made in the browser.

Check your understanding

Choose one answer for each question, then check your answers. You can retry as often as you like.

1. A page hides an administrator button. Is that sufficient protection?
2. What helps prevent SQL injection?
3. Where should you practice exploitation?

Keep learning

OWASP: web application security risks (opens a new tab)