错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Web Application Exploitation and Account Takeover: A Comprehensive Study of Techniques and Mitigation Strategies

  • Shubham Gupta,
  • Swetta Kukreja,
  • Deepa Parasar,
  • Naufil Kazi

摘要

This study investigates effective ways to prevent web application exploitation and account takeovers. It emphasizes the need to secure online accounts against evolving digital threats by analyzing various vulnerabilities like XSS, CSRF, broken authentication, password attacks, and business logic flaws. The paper uniquely examines advanced attack techniques such as Unicode mapping collision, OAuth threats, host header injection, and response manipulation, detailing their reproduction steps. It proposes mitigation strategies including secure coding, input validation, robust session management, two-factor authentication, and user awareness, advancing over current practices. By offering a detailed analysis of attack methods and countermeasures, the study contributes significantly to web security research, providing practical solutions and setting a benchmark for future work in this area.