New game
Download
Get Academic Plan
Share game
Integrate it into your platform

You can integrate the game into an LMS compatible with LTI 1.1 or LTI 1.3 such as Canvas, Moodle, or Blackboard. This way, the scores will be automatically saved into the platform’s gradebook.
Download
You have exceeded the maximum number of games you can integrate into Google Classroom with your current Plan.

To integrate as many games as you want in Google Classroom, you need an Academic Plan or a Commercial Plan.

You have exceeded the maximum number of games you can integrate into Microsoft Teams with your current Plan.

To integrate as many games as you want in Microsoft Teams, you need an Academic Plan or a Commercial Plan.

Downloading games is an exclusive feature for users with an Academic Plan or a Commercial Plan.

Get your Academic Plan or your Commercial Plan now and start integrating your games into your LMS, website or blog.

If you wish, you can download a demo game here and test its integration:

Web Attack Basics Quiz

Quiz

Played 19 %Accuracy 80 Average time 01:34

About this activity

Fundamentals of web attacks

Created by

Qatar

Download the paper version to play

Make your own free game from our game creator
Compete against your friends to see who gets the best score in this game

Top Games

%
Anonymous
Anonymous
%
%
%
You have exceeded the maximum number of games you can print with your current Plan.

To print as many games as you want, you need an Academic Plan or a Commercial Plan.

Print your game
Web Attack Basics Quiz
 

Web Attack Basics QuizOnline version

Fundamentals of web attacks

by k alk
1

What is SQL injection primarily about exploiting in a web app?

2

Which defense uses a unique token to prevent cross-site request forgery?

3

Which attack executes scripts in a user’s browser to steal data or hijack sessions?

4

What is a primary mitigation for SQL injection?

5

Which defense helps prevent an attacker from loading malicious content in a webpage?

6

What does the term SSRF refer to in web security?

7

Which vulnerability involves tricking a user into performing unintended actions via a forged request?

8

Which practice helps defend against brute-force login attempts?

9

Which header helps protect a page from clickjacking?

10

What is a safe practice for file upload handling to mitigate web attacks?

Feedback

SQL injection targets how user input is used in database queries; unsafe queries can expose data.

CSRF tokens help ensure requests come from legitimate pages, preventing unauthorized actions.

XSS injects malicious scripts into trusted websites, affecting users.

Parameterized (prepared) statements keep data separate from code, preventing injections.

CSP restricts sources of content to reduce risk of injection/execution.

SSRF tricks a server into requesting unintended resources.

CSRF exploits authenticated users to perform actions without their consent.

Rate limiting slows attackers; lockouts reduce credential abuse.

X-Frame-Options or CSP frame-ancestors prevents embedding in frames.

Strict validation and scanning reduce risks from uploaded malware.

Are you sure you want to leave the page?

If you leave, you will lose the game in progress.