#010 — Web Attacks Overview

Date: July 17, 2026 | 19:00 London / 21:00 Kyiv
Format: Guest talk · technical deep-dive · ~60–70 minutes
Guest: Oleksandr Blazheiko
YouTube: https://youtube.com/live/YDs0AGzYjoI
Participants
Oleksandr Blazheiko — Software Development Engineer · Fullstack
Ukraine
LinkedIn · itvibe.party
What we'll cover
A tour of real attack scenarios against web applications — from the frontend through the backend to the network.
Frontend attacks
XSS (Reflected / Stored / DOM-based), CSRF, Clickjacking, CORS misconfiguration, Open Redirect, Reverse Tabnabbing, Prototype Pollution, compromised npm packages (Supply Chain Attack)
Backend attacks
SQL Injection, Command Injection, Path Traversal / LFI, SSRF, Insecure Deserialization, IDOR / Broken Access Control, Mass Assignment, XXE, Race Condition / TOCTOU
Network, authentication, infrastructure
Broken Authentication / Session Fixation, Brute Force / Credential Stuffing, Man-in-the-Middle, DDoS, Subdomain Takeover
Key takeaways
Added after the stream.
Timecodes
Added after the stream.

