new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf

2 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Use CSRF protection

Implement CSRF protection for AJAX endpoints. Refer to the Cross-Site Request Forgery (CSRF) Prevention cheat sheet for specific controls.

Login endpoint rate limits must use two independent buckets

A correct login-endpoint rate limit applies two separate token-bucket or sliding-window rate limit buckets, both of which must be under their threshold for the request to pass. The per-username bucket limits attempts against any single account regardless of source IP, defending against targeted distributed attacks. The per-IP (or per-IP+ASN) bucket limits the volume of attempts originating from one source against any account, defending against credential-stuffing sweeps. Do not combine IP and username into a single bucket key, as this allows a single IP to attempt the threshold against an unlimited number of usernames before triggering a limit.

Give your agent this brain