Zusammenfassung der Ressource
The Tangled Web
- Security in the World of Web Applications
- History of the Web
- GML
- IBM's Generalized Markup Language
- "this is a header", "this is a list"
- SGML
- Standard Generalized Markup Language
- HTML
- Focused on simplicity
- Tim Berners-Lee and Dan Connolly
- HyperText Markup Language
- HTTP
- HyperText Transfer Protocol
- Dedicated scheme for accessing HTML resources using TCP/IP, DNS and file pathes concepts
- Tim's WWW Project
Anmerkungen:
- 1991-1993
- A browser that parsed HTML and allowed navigation from one page to another
- Tim Berners-Lee
- Mosaic Web Browser
- Netscape Navigator
- Spyglass Mosaic
- Microsoft Internet Explorer
- 1960's
- Microsoft XMLHttpRequest
- Web 2.0
- W3C - WWW Consortium
- Risk Management
- CWE
- Homeland Security
- Common Weakness Enumeration
- "Provide a common language"
- CVSS
- Common Vulnerability Scoring System
- method to quantify and score a vulnerability based on risk
- probability * maximum loss = risk
- Anatomy of the Web
- URLs
- HTTP
- HTML
- CSS
- Browser Scripts
- Doc Types
- Plug-ins
- Browser Security
- Content Isolation
- Origin Inheritance
- Outside Same-Origin
- Other Boundaries
- Content Recognition
- Rouge Scripts
- Site Privileges
- Future
- New Security Features
- Other Browser Mechanisms
- Common Web Vulnerabilities