new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

input_validation/allowlist_vs_denylist

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Denylist validation is flawed approach

Using denylist validation to detect dangerous characters and patterns like apostrophe, string 1=1, or <script> tag is a massively flawed approach as it is trivial for an attacker to bypass such filters. Such filters frequently prevent authorized input like O'Brian where apostrophe is fully legitimate.

Allowlist validation approach

Allowlist validation involves defining exactly what IS authorized, and by definition everything else is not authorized. Allowlist validation is appropriate for all input fields provided by the user. It remains the more robust and secure approach for preventing potentially harmful input.

Denylisting as supplementary defense layer

While denylisting can be useful as an additional layer of defense to catch some common malicious patterns, it should not be relied upon as the primary method and must be supplemented by allowlisting.

Give your agent this brain