new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

nosql/safe_patterns

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Use ODM/ORM for safe NoSQL query building

Prefer high-level ODM/ORM APIs like Mongoose, Spring Data, or Datastax driver patterns that build queries safely instead of constructing raw query strings.

Avoid eval() and raw query execution in NoSQL

Avoid .eval()-like functionality and raw query execution from untrusted data. Sanitize and validate any raw expressions before passing to the database.

PyMongo safe usage with TLS

Use PyMongo with TLS enabled: from pymongo import MongoClient; client = MongoClient(uri, tls=True); collection = client.mydb.users; user = collection.find_one({"email": email_input}). Use driver query objects rather than building query strings.

Give your agent this brain