From the course: CISSP Cert Prep (2021): 8 Software Development Security
Unlock the full course today
Join today to access over 22,500 courses taught by industry experts or purchase this course individually.
Code execution attacks
From the course: CISSP Cert Prep (2021): 8 Software Development Security
Code execution attacks
- [Instructor] Code execution attacks are a special class of attack where the attacker exploits a vulnerability in the system that allows them to run commands on that system. There are many different ways that an attacker might gain this foothold on a system but it's normally through some resource that the target system exposes to the world. For example, a public-facing web server must expose ports 80 and/or 443 to the world. And those ports provide access to the web server such as Apache or Microsoft IIS. If an attacker learns of a code execution vulnerability in that web server software, the attacker may exploit that vulnerability on an unpatched server and use it to execute whatever commands they desire on the system. This condition, where an attacker runs commands of his or her choice, is known as arbitrary code execution. When it takes place from a remote system, it's also known as remote code execution. Attackers…
Contents
-
-
-
-
-
OWASP Top 105m 36s
-
Application security4m 13s
-
Preventing SQL injection4m 25s
-
Understanding cross-site scripting3m 17s
-
Request forgery4m 8s
-
Defending against directory traversal3m 6s
-
Overflow attacks3m 21s
-
Explaining cookies and attachments4m 25s
-
Session hijacking4m 8s
-
Code execution attacks2m 43s
-
Privilege escalation1m 56s
-
Driver manipulation2m 16s
-
Memory vulnerabilities3m 34s
-
Race condition vulnerabilities2m 13s
-
-
-
-