[1.XSS原理及防范](1.XSS%E5%8E%9F%E7%90%86%E5%8F%8A%E9%98%B2%E8%8C%83.md) [2.CSRF原理及防范](2.CSRF%E5%8E%9F%E7%90%86%E5%8F%8A%E9%98%B2%E8%8C%83.md) [3.如何保证你的HTTP cookies安全不受XSS攻击](3.%E5%A6%82%E4%BD%95%E4%BF%9D%E8%AF%81%E4%BD%A0%E7%9A%84HTTPcookies%E5%AE%89%E5%85%A8%E4%B8%8D%E5%8F%97XSS%E6%94%BB%E5%87%BB.md)