Skip to content
RU

Articles & Guides

Useful resources for web developers and system administrators

Found 67 · Security · Reset

Security
Prevent XSS Attacks: Escaping, CSP and Trusted Types
XSS types — stored, reflected, DOM-based — and how to stop them with context-aware escaping, CSP, Trusted Types, and HttpOnly cookies.
15.04.2026 · 3 min · 296 views
Security
Clickjacking Prevention: X-Frame-Options vs frame-ancestors
Clickjacking attacks explained: X-Frame-Options, CSP frame-ancestors, SameSite cookies, JS frame-busting. nginx setup and verification.
15.04.2026 · 3 min · 393 views
Security
How to Check a Website for Malware: 4 Layers and a Cleanup
Check a website for malware: infection symptoms, external scanners, DevTools, hunting backdoors on the server and in the database, cloaking tests and a cleanup plan.
01.04.2026 · 34 min · 1217 views
Security
SPF, DKIM and DMARC: Why You Need Them and How to Set Up
Complete guide to SPF, DKIM, and DMARC email authentication. Learn how to protect your domain from spoofing, improve deliverability, and pass Gmail and Yahoo requirements.
01.04.2026 · 6 min · 269 views
Security
HSTS and Preload List: Complete Implementation Guide
Complete guide to HTTP Strict Transport Security (HSTS) header and preload list. Implementation steps, risks, rollback strategy, and best practices.
16.03.2026 · 6 min · 514 views
Security
Web Server Security Hardening Checklist: Nginx and Apache
Complete web server hardening checklist for nginx and Apache. File permissions, security headers, TLS configuration, access control, and monitoring.
16.03.2026 · 5 min · 616 views
Security
Two-Factor Authentication Guide: TOTP, SMS, and Hardware Keys
A comprehensive guide to two-factor authentication types including TOTP, SMS verification, and hardware security keys with implementation best practices.
16.03.2026 · 5 min · 327 views
Security
Rate Limiting Strategies for Web APIs and Applications
Explore rate limiting algorithms — token bucket, sliding window, fixed window — and learn how to implement effective API rate limiting.
16.03.2026 · 4 min · 293 views
Security
WAF Rules: Writing Effective Web Application Firewall Policies
Learn how to write effective WAF rules, understand rule types, avoid false positives, and protect your web application from common attacks.
16.03.2026 · 5 min · 417 views
Security
CORS Explained: Cross-Origin Resource Sharing Guide
Understand CORS — how cross-origin requests work, preflight checks, headers, common errors, and how to configure CORS correctly for your web application.
16.03.2026 · 7 min · 380 views