Writing
Blog
Writing on React, web performance, and the craft of building software.
Blog
Security
Web Security, v2
Expand All
01
Introduction
1 article
•
Not started
1
The Mental Model For Web Security
6 min read
•
Web security is not a checklist you run through once. It is a way of looking at every feature you ship and asking what happens if the person using it is not who they say they are.
02
Cookies And Sessions
6 articles
•
Not started
1
How Cookies Fake A Login On A Stateless Web
5 min read
•
HTTP has no idea what 'logged in' means. Cookies are the mutually agreed hack that layers a session on top of a protocol that forgets you the instant a response is sent.
2
Cookie Attributes Expiry Path And Domain Traps
5 min read
•
You can't actually delete a cookie, only lie to it about the date. And one leading dot in the domain attribute can hand your session cookie to every other app on a shared platform.
3
The Plain Text Username Mistake
5 min read
•
If a cookie holds a raw username and the server trusts it unconditionally, becoming another user is not hacking. It's editing a text field in DevTools.
4
Httponly Cookies And Why Sessions Exist
5 min read
•
HttpOnly blocks JavaScript from ever reading a cookie, which matters most when an attacker doesn't need to hack anything, just run one line of script on your page.
5
Signing Cookies And Building Real Sessions
6 min read
•
Signing a cookie doesn't hide the value, it proves nobody changed it. Combined with a random session ID stored server-side, that's what a real login system actually looks like.
6
Same Origin Policy And What Cookies Cant Protect
5 min read
•
Origin is a three-part match: protocol, host, and port. All three exist because the browser's first attempt at sharing across sites, document.domain, was a security hole waiting to happen.
03
Session Hijacking And Injection
4 articles
•
Not started
1
Privilege Escalation And How Attackers Actually Probe
5 min read
•
Privilege escalation isn't just becoming an admin. It's doing anything an account was never supposed to be able to do, and most of it starts with someone patiently watching for a crack.
2
Sql Injection And Why String Interpolation Is The Enemy
7 min read
•
A single quote and two dashes can turn a login form into an open door. The whole trick lives in how the query string gets built, not in anything SQL itself does wrong.
3
Mass Assignment And Why Allow Lists Beat Deny Lists
5 min read
•
No linter flags this bug, because nothing about the code is malformed. Spreading a request body onto a database record just quietly trusts fields the UI never meant to expose.
4
Man In The Middle Samesite And The Rest Of The Injection Family
6 min read
•
HTTPS quietly defeats most man-in-the-middle attacks by default. SameSite, site versus origin, and the rest of the injection family close out the gaps that HTTPS alone doesn't.
04
Cross Site Request Forgery
5 articles
•
Not started
1
Csrf Case Studies When Your Browser Lies For You
7 min read
•
CSRF never steals a cookie or a password. It tricks an already-logged-in browser into sending a request it never meant to send, and the attacker never even sees what happens next.
2
The Three Ingredients Of A Csrf Attack
5 min read
•
Every CSRF attack, no matter how it's delivered, needs exactly three things to line up at once. Take out any one of them and there's nothing left to exploit.
3
Cookie Defenses Alone Arent Enough
5 min read
•
A real session cookie and a real POST endpoint were all it took to move money out of an account that was never compromised. SameSite narrows that gap. It doesn't close it.
4
Csrf Tokens The Fix That Actually Works
6 min read
•
The fix for CSRF was never the cookie. It's a value the attacker's forged request cannot possibly know, generated per session, checked on every state-changing request.
5
What A Get Request Taught Me About Csrf
6 min read
•
A single hidden CSRF token stops most forged requests. A GET endpoint that never got one taught me why the request method matters as much as the token itself.
05
Cors And Cross Site Scripting
4 articles
•
Not started
1
What Cors Actually Protects And What It Doesnt
7 min read
•
CORS never protects a form-submitted POST request, only fetch and XHR calls, which is exactly why CSRF tokens are still necessary even when every API call on your site is fully locked down.
2
What Makes Xss Actually Different From Csrf
6 min read
•
CSRF is a forged request arriving from outside. Cross-site scripting is the attacker's own code running inside your origin, which is why none of the defenses from the last chapter touch it.
3
Famous Xss Attacks And What They Actually Cost
6 min read
•
The Samy Worm wasn't a one-off. British Airways, TweetDeck, eBay, and Fortnite all shipped the same underlying mistake, and the stakes only went up from there.
4
Sanitizing Input And Picking Safe Sinks
5 min read
•
Most frameworks already sanitize for you unless you deliberately opt out, and that opt-out is the tell. textContent is a safe sink; innerHTML hands the DOM a loaded weapon.
06
Content Security Policy
3 articles
•
Not started
1
Csp The Second Layer After Sanitization
5 min read
•
Having any Content Security Policy at all, even a permissive one, disables inline scripts by default. That one fact does more work than most of what comes after it.
2
Building A Csp Directive By Directive
5 min read
•
Build a CSP by allow-listing your way up from nothing, not by deny-listing your way down from everything. Someone will always find the thing you didn't think to block.
3
Nonces And Subresource Integrity For Scripts You Cant Avoid
6 min read
•
A nonce protects a script you wrote. Subresource Integrity protects a script someone else hosts. Neither claims to be a perfect wall, both just shrink what's left to attack.
07
Other Attack Vectors
5 articles
•
Not started
1
Clickjacking And The Invisible Frame Trick
5 min read
•
Clickjacking doesn't trick your browser and doesn't trick your code, it tricks you, into clicking a real button you never meant to click.
2
Postmessage And Checking Who Youre Actually Talking To
5 min read
•
postMessage is how two different origins are allowed to talk at all. Skip the origin check on either end, and that permission becomes the vulnerability.
3
Tabnabbing And Breaking The Window Opener Link
5 min read
•
Tabnabbing doesn't attack you the second a tab opens, it waits until you've stopped paying attention to it.
4
Jwts Identity Without A Session Table
5 min read
•
A JWT answers a scaling problem this whole course quietly assumed away, one shared server checking one shared session table, by carrying identity in the token itself.
5
Where To Actually Put A Jwt
5 min read
•
Every JWT storage option is a trade-off, but only one of them gets every protection this entire course has already covered.
08
Wrapping Up
1 article
•
Not started
1
Password Salting And The Throughline Of This Course
6 min read
•
This course built an entire security model on top of passwords without ever explaining how one should actually be stored. Time to close that gap, and close the course with it.
Web Security, v2 | Writing & Engineering | Durgesh Rai