CSRF:html
http://blog.csdn.net/stpeace/article/details/53512283node
Session fixation:session
https://www.cnblogs.com/davidwang456/p/3593578.htmlide
http://www.gooseeker.com/cn/node/knowledgebase/whatissessionfixationspa
HTTP Strict Transport Security(HSTS):.net
HTTPShtm
XSS:blog
https://www.cnblogs.com/suwings/p/6285340.htmlit
https://www.cnblogs.com/digdeep/p/4695348.htmlio