Guides
Security explainers I kept repeating out loud, so I wrote them down.More whenever the OSCP syllabus throws something new at me.
Clickjacking tricks a user into clicking a button they can't see, on a page they never chose to visit. Here's how the overlay works, how a JavaScript guard detects framing, and the response headers that actually stop it.
Web Security · Clickjacking · HTTP Headers · Content Security Policy · OWASP
Learn how XSS attacks work, why your session cookies are vulnerable, and the exact defense strategies that actually stop attackers—from HTTP-only flags to Content Security Policies.
Web Security · XSS · Session Management · Security Best Practices · Frontend Security
JWT vs OAuth 2.0
· 5 min
Understand the differences between JWT and OAuth 2.0, their use cases, and best practices for secure, scalable authentication in modern web applications.
JWT · OAuth · Authentication · API Security