new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

attack-surface/users

2 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

User role complexity in Attack Surface

The Attack Surface model should be overlaid with different types of users including roles and privilege levels, both authorized and unauthorized. Complexity increases with the number of different user types. It is important to focus on two extremes: unauthenticated anonymous users and highly privileged admin users such as database administrators or system administrators.

Attack Surface risk assessment for new user types

When adding new user types, roles or privilege levels, perform risk assessment by overlaying the type of access across data and functions to identify problems and inconsistencies. Understand whether the access model is positive (deny by default) or negative (allow by default), as mistakes in defining permitted data/functions for new user types are more easily identified in positive models.

Give your agent this brain