• XSS.stack #1 – первый литературный журнал от юзеров форума

Web penetration discussion

tkboom

CD-диск
Пользователь
Регистрация
16.12.2024
Сообщения
11
Реакции
0
Let's discuss a question.
The website uses a relay site (CDN) to connect to the main website (server) through an API.
What is its security level: low, medium, or high?
Can general SQL and other technologies have the effect of accessing the backend?
I would be grateful to get your feedback
 
Последнее редактирование:
Let's discuss a question.
The website uses a relay site (CDN) to connect to the main website (server) through an API.
What is its security level: low, medium, or high?
Can general SQL and other technologies have the effect of accessing the backend?
I would be grateful to get your feedback
From my POV, it's fine if an API is secured right. SQL-injections can be used if the API doesn't validate incoming data, also cached old data is a vulnerability if the CDN holds it. There is quite a lot of issues I think of if the API is shit.
 
From my POV, it's fine if an API is secured right. SQL-injections can be used if the API doesn't validate incoming data, also cached old data is a vulnerability if the CDN holds it. There is quite a lot of issues I think of if the API is shit.
It is currently impossible to determine the quality of the API
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх