new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

attack-surface/definition

2 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Attack Surface definition and components

The Attack Surface of an application consists of: (1) the sum of all paths for data/commands into and out of the application; (2) the code that protects these paths including resource connection, authentication, authorization, activity logging, data validation and encoding; (3) all valuable data used in the application including secrets, keys, intellectual property, critical business data, personal data and PII; (4) the code that protects this data including encryption, checksums, access auditing, data integrity and operational security controls.

Container supply chain attack targets

Supply chain attacks in Kubernetes environments typically target: base images and dependencies, build processes and CI/CD pipelines, container registries, deployment manifests and Helm charts, and third-party libraries and packages.

Give your agent this brain