Open cardosec

Case 6EA876 · Web AppSec · L4 Advanced

Third-Party JavaScript Risk

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Every third-party script runs with full page privileges; one compromised CDN or tag manager affects all users
  2. Magecart-style skimmers inject into checkout pages to exfiltrate card data to lookalike domains
  3. Subresource Integrity (integrity= hash) pins static files but breaks for dynamically updated vendor scripts
  4. CSP connect-src and script-src allowlists limit where injected code loads from and can send data
  5. Govern npm deps with lockfiles, SCA, provenance checks, and monitoring for typosquats and malicious postinstall

If the interviewer pushes back

  • PCI DSS 4.0 added requirements for payment page scripts. How would you implement them?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.