الثغرات الأمنية الشائعة وإصلاحاتها
حدّدوا الثغرات الأمنية الشائعة في تطبيقات الويب، مثل XSS وCSRF وحقن SQL، وعالجوها ضمن سياق Spring Security.
الثغرات الأمنية الشائعة وإصلاحاتها درس مجاني في Spring Security 6 & JWT Authentication على CoddyKit. هذا هو الدرس 3 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Spring Security 6 & JWT Authentication، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Spring Security 6 & JWT Authentication 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
Web Vulnerabilities Overview
Welcome! In this lesson, we'll dive into common web application security vulnerabilities. Understanding these threats is crucial for building robust and secure applications.
Even with frameworks like Spring Security, knowing how common attacks work helps you write safer code and configure your app effectively.
What is Cross-Site Scripting?
Cross-Site Scripting (XSS) occurs when attackers inject malicious scripts (usually JavaScript) into web pages viewed by other users.
These scripts can steal session cookies, deface websites, or redirect users to phishing sites. It tricks the user's browser into executing untrusted code.
Reflected, Stored, and DOM XSS
XSS comes in a few flavors:
- Reflected XSS: Malicious script is part of the request (e.g., URL parameter) and immediately 'reflected' back in the response.
- Stored XSS: Malicious script is permanently stored on the target server (e.g., in a database via a comment field) and served to all visitors.
- DOM-based XSS: The vulnerability lies in client-side code modifying the Document Object Model (DOM) based on user input, rather than server-side generation.
XSS Prevention: Input & Output
The best defenses against XSS are:
- Input Validation: On the server, strictly validate and sanitize all user input. Don't trust anything coming from the client.
- Output Encoding: Before displaying user-supplied data in HTML, always 'escape' it. This turns malicious code into harmless text, preventing the browser from executing it.
Spring frameworks often provide utilities for output encoding.
Encoding User Input
Here's a simple Java example demonstrating output encoding. Notice how special HTML characters like < and > are converted to their entity equivalents (<, >).
This makes the script harmless when rendered in a browser.
import org.springframework.web.util.HtmlUtils;
public class XssPrevention {
public static void main(String[] args) {
String userInput = "<script>alert('You are hacked!');</script>";
String safeOutput = HtmlUtils.htmlEscape(userInput);
System.out.println("Original: " + userInput);
System.out.println("Encoded: " + safeOutput);
}
}What is Cross-Site Request Forgery?
Cross-Site Request Forgery (CSRF) is an attack that tricks a logged-in user into submitting a request they did not intend. For example, changing their password or making a purchase.
The attacker crafts a malicious web page that sends a request to your application, and if the user is logged in, their browser automatically includes authentication credentials (like cookies).
Spring Security's CSRF Defense
Spring Security provides robust, built-in CSRF protection. By default, it generates a unique, synchronized token (a CSRF token) for each session.
This token must be included in non-GET requests (like POST, PUT, DELETE). If the token is missing or invalid, Spring Security rejects the request, preventing CSRF attacks.
What is SQL Injection?
SQL Injection (SQLi) is a common attack where malicious SQL code is inserted into input fields to manipulate backend database queries.
Attackers can use SQLi to bypass authentication, retrieve sensitive data, modify data, or even take control of the database server. It's often exploited when an application constructs SQL queries using concatenated strings.
SQLi Prevention: Parameterized Queries
The primary defense against SQL Injection is using parameterized queries (also known as prepared statements).
Instead of concatenating user input directly into the SQL string, placeholders are used. The database then treats user input as data, not as executable SQL code, neutralizing the attack.
import java.sql.*;
public class SqlInjectionPrevention {
public static void main(String[] args) {
String username = "admin' OR '1'='1"; // Malicious input
// GOOD: Parameterized Query (Safe concept)
String goodSql = "SELECT * FROM users WHERE username = ?";
System.out.println("Safe SQL (PreparedStatement concept): " + goodSql);
System.out.println("Parameter used: " + username);
// In a real app, 'username' would be set as a parameter
// on a PreparedStatement object.
}
}Vulnerability Check
Which of the following is the most effective way to prevent SQL Injection attacks?
Lesson Summary
Great job! You've explored three critical web vulnerabilities and their fixes:
- XSS: Prevent with input validation and output encoding.
- CSRF: Spring Security handles this by default with CSRF tokens.
- SQL Injection: Prevent with parameterized queries (prepared statements).
Always remember to validate all input, encode all output, and leverage your framework's built-in security features!
الأسئلة الشائعة
هل درس «الثغرات الأمنية الشائعة وإصلاحاتها» مجاني؟
نعم — نص درس «الثغرات الأمنية الشائعة وإصلاحاتها» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Spring Security 6 & JWT Authentication، انتقل إلى CoddyKit PRO. تتضمن دورة Spring Security 6 & JWT Authentication 4 دروس في المجموع.
ماذا ستتعلم في «الثغرات الأمنية الشائعة وإصلاحاتها»؟
حدّدوا الثغرات الأمنية الشائعة في تطبيقات الويب، مثل XSS وCSRF وحقن SQL، وعالجوها ضمن سياق Spring Security. تتمرن على Spring Security 6 & JWT Authentication مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ Spring Security 6 & JWT Authentication؟
لا تُشترط خبرة سابقة. Spring Security 6 & JWT Authentication على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 3 من أصل 4.
كم من الوقت يستغرق درس «الثغرات الأمنية الشائعة وإصلاحاتها»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس Spring Security 6 & JWT Authentication هذا؟
نعم. كل درس في Spring Security 6 & JWT Authentication يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- تعزيز الأمان لبيئة الإنتاج
- تسجيل أحداث الأمان ومراقبتها
- الثغرات الأمنية الشائعة وإصلاحاتها
- تهيئة ترويسات الأمان وHTTPS