How to Secure an Android App


    The Android operating system has lots of built-in security features, such as application sandboxing, protection against buffer and integer overflow attacks, and segregated memory areas for program instructions and data. As a result, simple Android apps that don't perform any file system or networking operations can often be considered secure by default.


    XSS - Cross-Site Scripting (Part-1)

    What is XSS?

    Cross-site scripting (XSS) is a code injection attack that allows an attacker to execute malicious JavaScript in another user's browser.

    The attacker does not directly target his victim. Instead, he exploits a vulnerability in a website that the victim visits, in order to get the website to deliver the malicious JavaScript for him. To the victim's browser, the malicious JavaScript appears to be a legitimate part of the website, and the website has thus acted as an unintentional accomplice to the attacker.


    Difference between WebService and API

    Web Service
    Interaction between two machines over a network. Interaction between two API.
    Uses SOAP, REST, and XML-RPC as a means of communication. It may use any way to communication
    Web Services involves calling of system. We can render form in one line, one by one element, element OR  decorator OR error separately.
    Web service might not contain a complete set of specifications and sometimes might not be able to perform all the tasks that may be possible from a complete API. An API consists of a complete set of rules and specifications for a software program to follow in order to facilitate interaction.
    All Web services are APIs All APIs are not Web services
    A Web service always needs a network for its operation API doesn't need a network for its operation
    WebServices are services available over internet. You can call these services and get so information in your application without know how it works. For example weather webservices gives you information about the city weather. API is a collection of class which provide you some functionality like Google api gives google-search.
