Case 6EA876 · Web AppSec · L4 Advanced
Third-Party JavaScript Risk
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Every third-party script runs with full page privileges; one compromised CDN or tag manager affects all users
- Magecart-style skimmers inject into checkout pages to exfiltrate card data to lookalike domains
- Subresource Integrity (integrity= hash) pins static files but breaks for dynamically updated vendor scripts
- CSP connect-src and script-src allowlists limit where injected code loads from and can send data
- Govern npm deps with lockfiles, SCA, provenance checks, and monitoring for typosquats and malicious postinstall
If the interviewer pushes back
- PCI DSS 4.0 added requirements for payment page scripts. How would you implement them?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.