What HTML form attack vectors exist?

I'm starting to look at the security of HTML forms. So far, my research has identified three main areas of attack:

  • Cross Site Request Forgery (CSRF)
  • Cross Site Scripting (XSS)
  • SQL injection

My question is: Are there more attack vectors for HTML forms than these ? I'm interested in a list of possible attacks through HTML forms.

+3
source share
4 answers

URI , . " " , SQL-, XSS .. , , JavaScript , .

, , :

  • =
  • HTTPS
  • (, N , - )
  • , PHP, GET POST , $_POST, $_GET

- , :

  • , A, B, , . ( , .)
  • . , . , ops, " " , , , DoS.
+1

, .

( SQL-).

+2

10. A1-Injection. , CSRF/XSS/Injection , GET HTTP.

<form>, , URL- HTTPS, . "" .

+1

. , - :

<img src="http://mysite.com/delete_post/4" style="display:none">

, . , , . .

, - (, ), . , . , , .

0

Source: https://habr.com/ru/post/1762272/


All Articles