Skip to content

#010 — Web Attacks Overview

Stream #010

Date: July 17, 2026 | 19:00 London / 21:00 Kyiv
Format: Guest talk · technical deep-dive · ~60–70 minutes
Guest: Oleksandr Blazheiko
YouTube: https://youtube.com/live/YDs0AGzYjoI

Participants

Oleksandr Blazheiko — Software Development Engineer · Fullstack
Ukraine
LinkedIn · itvibe.party

What we'll cover

A tour of real attack scenarios against web applications — from the frontend through the backend to the network.

Frontend attacks

XSS (Reflected / Stored / DOM-based), CSRF, Clickjacking, CORS misconfiguration, Open Redirect, Reverse Tabnabbing, Prototype Pollution, compromised npm packages (Supply Chain Attack)

Backend attacks

SQL Injection, Command Injection, Path Traversal / LFI, SSRF, Insecure Deserialization, IDOR / Broken Access Control, Mass Assignment, XXE, Race Condition / TOCTOU

Network, authentication, infrastructure

Broken Authentication / Session Fixation, Brute Force / Credential Stuffing, Man-in-the-Middle, DDoS, Subdomain Takeover

Key takeaways

Added after the stream.

Timecodes

Added after the stream.

Resources

IT Friday · @zloyleva