Pretnje
13 direktnih pogodaka-
№ 041
Cross-Site Request Forgery … equest forgery, or CSRF, exploits the fact that a browser automatically sends existing session cookies to a site where the user is already logged in. The attack …pretnja · applications
-
№ 040
Cross-Site Scripting … script to be displayed and executed in the user's browser. The attacker does not have to break into the web server. It is enough for their code to end up in a p …pretnja · applications
-
№ 013
Cryptominer … infected site that mines while it is open in the browser, and even in the cloud through a hijacked account that runs up machines on someone else's account. In …pretnja · malware
-
№ 057
DNS Poisoning … s that the user types a familiar address into the browser and DNS takes them to the wrong web server. On paper the name is the same. In reality the road leads s …pretnja · availability
-
№ 012
Infostealer … ne basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. I …pretnja · malware
-
№ 005
Loader / Dropper … dropper or a loader hidden in some script in the browser cache, which the antivirus does not read as a threat because it carries none of the marks of malicious …pretnja · malware
-
№ 032
Malvertising … . Sometimes the advert leads to a fake page for a browser update, a program download or a credential entry. In worse cases a vulnerable browser or extension can …pretnja · social eng.
-
№ 045
SSRF … on matters: the request is not sent by the user's browser but by the server. That opens the door to internal services which from the outside ought to remain inv …pretnja · applications
-
№ 019
Session Hijacking … ion is marked by an identifier, usually held in a browser cookie. Session hijacking is the taking over of a session that is already open. The attacker does not …pretnja · identity
-
№ 003
Spyware A browser extension, presented as a coupon finder, records everything the user types while shopping.pretnja · malware
-
№ 018
Token Theft … factor, the service issues a token, stored in the browser, which vouches that you have already been checked the next time round. The token is sent automatically …pretnja · identity
-
№ 036
Watering Hole Attack … isitors are served malicious code that exploits a browser vulnerability.pretnja · social eng.
-
№ 044
Zero-Day Exploitation An unknown vulnerability in a browser is used to install spyware with no visible interaction from the user.pretnja · applications
Tehnike
3 direktna pogotka-
№ 007
Drive-by Download It exploits vulnerabilities in browsers, Java, Flash, or PDF plugins.tehnika · initial access
-
№ 020
Access Token Manipulation Stealing an OAuth token from browser storage via a malicious extensiontehnika · privileges
-
№ 038
Malware Delivery … t automatically downloads malware to a vulnerable browsertehnika · C2