更糟糕的是,人们可以使用破解版本的客户端软件将伪造的结果注入计算。
Even worse, people can use hacked versions of the client software to inject bogus results into your calculations.
正如我们在XSS示例中所看到的,大多数的攻击都利用了服务器端的弱点,注入恶意脚本。
As you've seen in the XSS examples, most of the attacks exploit server-side vulnerabilities by injecting malicious scripts.
客户端代码和服务代码看起来就像使用了某些魔法,通过来自SCA运行时注入得到了服务和传入的回调的引用。
The code for the client and for the service looks like it USES some piece of magic, with the references for the service and for the callback arriving through injection from the SCA runtime.
应用推荐