new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

injection/general

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Injection Prevention Rule 1: Input validation

Perform proper input validation. Positive or allowlist input validation with appropriate canonicalization is recommended, but is not a complete defense as many applications require special characters in their input.

Injection Prevention Rule 2: Use a safe API

The preferred option is to use a safe API which avoids the use of the interpreter entirely or provides a parameterized interface. Be careful of APIs such as stored procedures that are parameterized but can still introduce injection under the hood.

Injection Prevention Rule 3: Contextually escape user data

If a parameterized API is not available, carefully escape special characters using the specific escape syntax for that interpreter.

Give your agent this brain