Security glossary

55 terms, in plain English, each linked to the exercises that teach it.

ABCDEFGHIJKLMNOPQRSTUVWXYZ

A

Access control
The rules deciding what an authenticated user is allowed to see or do; broken access control is the most common serious web flaw.
Algorithm confusion
A JWT attack where the server trusts the token's header to choose how to verify the signature, including the insecure "none" algorithm.
Allowlist
A validation approach that names exactly what is permitted and rejects everything else; the opposite of a denylist, and far harder to bypass.
API
An interface a program exposes for other programs; on the web, usually HTTP endpoints returning JSON.
Argon2
A modern, deliberately slow password-hashing algorithm with tunable memory and time cost; a recommended choice for storing passwords.
Authentication
Proving who you are, typically with a password, a code or a key. Answers "who are you?", not "what may you do?".
Authorization
Checking what an already-authenticated user is permitted to do with a specific resource. Must happen on the server, on every request.

B

bcrypt
A slow, salted password-hashing algorithm with a cost factor, designed so attackers can only make a few guesses per second.
Blocklist (denylist)
Validation that tries to name every bad input and reject it. Always incomplete, so it is the weaker alternative to an allowlist.

C

Cloud metadata service
An internal endpoint in cloud environments that returns an instance's configuration and sometimes temporary credentials; a prime SSRF target.
Command injection
A flaw where user input is passed to the operating-system shell, so shell syntax in the input is executed as commands by the server.
Content Security Policy (CSP)
A response header that tells the browser which scripts and resources a page may load, limiting what an injected script can do.
Cookie
A small value the server asks the browser to store and send back with every request; session cookies are how a stateless protocol remembers you.
Cross-Site Scripting (XSS)
A flaw where user input is placed into a page without encoding, so attacker-supplied JavaScript runs in other users' browsers.
CSRF
Cross-site request forgery: tricking a logged-in user's browser into sending a request they did not intend, riding on their session cookie.
CVE
Common Vulnerabilities and Exposures: a public identifier (CVE-YYYY-NNNN) for a specific, disclosed vulnerability in a product.

D

Defence in depth
Layering several independent controls so a single missed check is not a catastrophe; e.g. output encoding plus HttpOnly cookies plus a CSP.
DOM-based XSS
XSS where the page's own JavaScript writes attacker-controlled data into the document unsafely, without the server reflecting it.

E

Encoding (output encoding)
Rewriting special characters so data cannot be mistaken for code at its destination, e.g. turning < into &lt; before placing text in HTML.

H

Hash
A fixed-size one-way fingerprint of data. The same input always gives the same hash; you cannot recover the input from it.
HTTP
The text protocol browsers and servers use: a request (method, path, headers, optional body) answered by a response (status code, headers, body).
HttpOnly
A cookie flag that forbids JavaScript from reading the cookie, so an XSS cannot simply steal the session.

I

IDOR
Insecure Direct Object Reference: reaching someone else's record by changing an identifier in a request that the server fails to check ownership of.
Injection
Any flaw where untrusted input is interpreted as code or commands by a downstream system: SQL, OS commands, HTML/JavaScript, LDAP, templates.
Input validation
Checking data as it arrives against strict rules and rejecting what does not fit; best done with an allowlist.

J

JSON Web Token
A signed token (header.payload.signature) that carries identity claims; its security is the signature, not the readable payload.

K

Key
On this platform: the string you submit to prove you completed an exercise. Not case-sensitive; worth points the first time.

N

Nmap
The standard network-mapping tool: it finds live hosts, open ports and the services behind them.

O

OWASP Top 10
The industry's shared list of the most common and impactful categories of web application risk, maintained by OWASP.

P

Parameterised query
Also called a prepared statement: the SQL is sent with placeholders and the values separately, so input can never change the query structure.
Path traversal
Using ../ sequences in a filename parameter to read files outside the directory the application intended.
Payload
The specific input an attacker sends to trigger a vulnerability.
Port
A numbered endpoint on a host where one network service listens; an open port is reachable attack surface.
Port scanning
Probing a host to discover which ports are open; a form of active reconnaissance that must stay within authorised scope.

R

Rainbow table
A precomputed table of hashes for millions of likely passwords, enabling instant lookup of unsalted hashes. Defeated by salting.
Reconnaissance
The information-gathering phase of an assessment; passive recon uses public sources, active recon sends traffic to the target.
Reflected XSS
XSS where the payload travels in the request (usually a URL) and the server immediately echoes it back into the response.
Rules of engagement
The agreement setting out scope, timing, permitted techniques and contacts before a penetration test begins.

S

Salt
A random per-user value mixed into a password before hashing, so identical passwords produce different hashes and precomputed tables are useless.
SameSite
A cookie attribute that tells the browser not to send the cookie with requests from other sites, blunting CSRF.
Sanitiser (HTML)
A library that allows a safe subset of HTML tags and strips scripts, used when a feature must display user-supplied HTML.
Scope
The precise set of systems you are authorised to test on an engagement; anything outside it is off-limits even if reachable.
Secret (hardcoded)
A credential such as an API key written directly into source code. Once committed it lives in history forever and must be rotated.
Secure (cookie flag)
A cookie attribute that makes the browser send the cookie only over HTTPS, so it cannot leak over an unencrypted connection.
Server-Side Request Forgery
Making a server fetch a URL the attacker chooses, so the attacker reaches internal services and cloud metadata the server can see but they cannot.
Session
The server-side record that a particular browser is logged in as a particular user, usually referenced by a session cookie.
Session fixation
Tricking a victim into using a session id the attacker already knows, then waiting for them to log in on it; fixed by regenerating the id at login.
Shell
A program such as bash that interprets command strings; passing it unsanitised user input is what makes command injection possible.
Sink
In code review, a dangerous operation that untrusted data can reach: a query, a shell command, HTML output, a file path.
Source
In code review, a place where attacker-controlled data enters the program: request parameters, headers, cookies, uploaded files.
SQL injection
Input that escapes a string value and becomes part of a database query, letting an attacker read, change or bypass what the query was meant to do.
SSRF
Server-side request forgery: making the server fetch a URL of the attacker's choosing, often to reach internal services.
Status code
The three-digit number in an HTTP response: 2xx success, 3xx redirect, 4xx client error, 5xx server error.
Stored XSS
XSS where the payload is saved on the server (a comment, a profile) and runs for every visitor who views it; the most dangerous kind.

T

Trust boundary
The line between what an application controls (the server) and what it does not (the client). Everything crossing it is untrusted input.