> For the complete documentation index, see [llms.txt](https://vikram-bajaj.gitbook.io/cs-gy-6083-principles-of-database-systems/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vikram-bajaj.gitbook.io/cs-gy-6083-principles-of-database-systems/main-1/sql/advanced-sql/accessing-sql-from-a-programming-language/some-security-issues.md).

# Some Security Issues

* HTTP sends data in the clear. For real applications that handle sensitive data, we should use HTTPS
  * authenticate server
  * encrypt data sent over network via SSL
* Session hijacking &#x20;
  * Adversary who discovers session ID can take over a session &#x20;
  * Checking the IP address of each request helps mitigate this threat, but doesn’t eliminate it
* SQL injection
  * Malicious user enters input that results in execution of an SQL statement other than the intended one
* Cross-site scripting
  * Malicious user gives input that hides a script in content that others will download
