new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

injection/definitions

2 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Injection flaws definition and scope

Injection flaws occur when an application sends untrusted data to an interpreter. They are particularly prevalent in legacy code and commonly found in SQL queries, LDAP queries, XPath queries, OS commands, and program arguments. Injection flaws are easy to discover during code review but more difficult to find through testing.

Injection types by technology

Injection attacks target different technologies including SQL queries, LDAP queries, XPath queries, OS commands, scripting languages (via eval), and network protocols (SMTP, IMAP, FTP). All of these can be susceptible to injection attacks.

Give your agent this brain