00:00 Introduction
00:22 Server-side vs. Client-side
00:53 XSS
06:49 Consequences of XSS
07:12 Types of XSS
09:08 Same Origin Policy
12:36 Cross-Origin Resource Sharing
14:15 Content Security Policy
15:58 XSS Defense
19:09 Assignment Analysis
This series of lessons was prepared by the CTF team SPRUSH (https://ctftime.org/team/76463) of Department No. 42 "Cryptology and Cybersecurity" at MEPhI.
The group's Telegram channel is https://t.me/mephictf
Want to study information security? Apply to our program in "Information Security" at MEPhI's Institute of Information Security and Cybersecurity. Information about the bachelor's and master's programs can be found at: https://is.mephi.ru
Official website of Department No. 42 "Cryptology and Cybersecurity" at MEPhI: https://kaf42.mephi.ru