new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

serialization

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Avoid writing serialization code

Writing serialization code is difficult and even small mistakes can cause large security issues. Use existing frameworks to provide this functionality instead of implementing custom serialization.

Avoid building XML or JSON dynamically

Do not dynamically build XML or JSON by hand, as this may cause XML injection bugs or JSON injection vulnerabilities. Use an encoding library or safe JSON or XML library to make attributes and element data safe.

Use framework for XML and JSON serialization server-side

Use the framework to serialize data when building XML and JSON responses. Building payloads by hand can introduce security issues.

Give your agent this brain