Web Exploitation
Web exploitation takes advantage of weaknesses in websites. Understanding those weaknesses helps us build and use safer systems.
What you’ll learn
- Explain what the browser controls and what the server must check.
- Recognize access-control, injection, and scripting problems.
- Practice in a simulation with explicit permission.
Browser versus server
The browser displays HTML, styles, and JavaScript. The server handles requests and should enforce access rules. Anything sent to the browser can be inspected or changed by its user. Hiding a button, answer, or password in page source does not protect it. Secrets and authoritative validation belong on the server.
Broken access control
Authentication asks “Who are you?” Authorization asks “Are you allowed to do this?” A logged-in user should not be able to read someone else’s private records by changing an ID in a URL. The server must check permission for every protected request.
Injection and cross-site scripting
Injection happens when untrusted input is treated as instructions, such as part of a database query. Parameterized queries help keep data separate from SQL instructions. Cross-site scripting (XSS) happens when untrusted content runs as script in another user’s browser. Context-appropriate output encoding and safe rendering help prevent it.
Test with permission
Use training labs or systems you are explicitly authorized to test, within the agreed scope. Do not try attacks on unrelated sites. For your own applications, keep software updated, protect sessions, validate input, encode output, and enforce permissions on the server. HTTPS protects transport; it does not fix application bugs.
Access-control simulator
You are signed in as Alex. Alex owns note 101; Jordan owns note 102. Change the requested note and compare a vulnerable server with a protected one. This simulation sends no network requests.
All names and notes are fictional. A real server must enforce this check regardless of changes made in the browser.
Check your understanding
Choose one answer for each question, then check your answers. You can retry as often as you like.