Abstract:In this paper, the category of web attacks is discussed. From attacker's viewpoint, the security of college Web sites is analyzed from many respects, such as web process code, permission of document catalog, system leak, validatory leak of web, CGI parameter, SQL injection and cross-site track.