Bank of America Interview Question: I was asked about XSS, SQL In... | Glassdoor

Interview Question

Applications Security Engineer Interview(Student Candidate) Chicago, IL

I was asked about XSS, SQL Injection, Tools I have used for

  pen testing.

Interview Answer

1 Answer


Cross-site scripting (XSS) is a type of computer security vulnerability typically found in Web applications. XSS enables attackers to inject client-side script into Web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same origin policy.
- SQL injection is a code injection technique, used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g. to dump the database contents to the attacker).

Interview Candidate on Oct 16, 2014

Add Answers or Comments

To comment on this, Sign In or Sign Up.