Attacker inputs `' OR 1=1 --` into login username field to bypass password checks. Prevented by using Parameterized Queries (Prepared Statements) where input values are separated from SQL execution AST.
// VULNERABLE CODE (SQL Injection): // const query = "SELECT * FROM users WHERE email = '" + req.body.email + "'"; // SECURE CODE (Parameterized Query): const query = "SELECT * FROM users WHERE email = $1"; const result = await db.query(query, [req.body.email]);
Visual representation of control loops, memory layout, and execution flow for Cryptography & OWASP Top 10 Web Vulnerabilities.
Malicious SQL injected into raw query strings; mitigated using Prepared Statements.
Attacker injects malicious JavaScript executing in victim browser; mitigated via HTML Escaping and Content Security Policy (CSP).
Tricks victim browser into executing unwanted actions on authenticated web app; mitigated via Anti-CSRF tokens and SameSite cookies.
Never store plain text passwords; use salted slow adaptive hashing algorithms like bcrypt or Argon2id.
| Feature / Dimension | Symmetric Encryption (e.g. AES-256) | Asymmetric Encryption (e.g. RSA, ECC) |
|---|---|---|
| Key Usage | Uses the EXACT SAME secret key for both encryption and decryption | Uses a Public Key for encryption and a Private Key for decryption |
| Speed | Extremely fast computational performance (ideal for bulk data encryption) | Slower computational performance (used for key exchange and digital signatures) |
| Key Distribution | Difficult; keys must be securely exchanged out-of-band | Easy; anyone can use the public key, private key remains secret |
Detailed answers, interviewer pro tips, key takeaway summaries, and code examples formulated for technical rounds.
✅ Correction: SHA-256 is too fast and vulnerable to GPU brute-force attacks! Passwords MUST be hashed using slow adaptive algorithms with salt like bcrypt, Argon2id, or PBKDF2.
✅ Correction: Cryptographic keys must be treated as production secrets. Store keys in a secure key management system (KMS) or inject them via environment variables at runtime.
Core cryptographic principles and web threat mitigation.