File upload security is easy to underestimate. An avatar picker or an invoice upload looks like a small feature, but it lets anyone with an account put a file of their choosing on your servers. If the app trusts the…
Security testing
37 posts
A CORS misconfiguration usually starts with a red error in the browser console. Someone searches the message, finds a line that makes it go away, and ships it. The error is gone, but the API may now let any website read…
If you want to prepare for a penetration test, the most useful work happens before the testers touch your app. A penetration test is a security test where someone tries to find and prove weaknesses in your system, with…
Excessive agency is what OWASP calls the risk of an AI agent that can do more than its job needs. When you connect a model to email, files, a database or a payments API, every tool you hand it is something it might use…
Broken access control is when your app lets a signed-in user see or change something that belongs to someone else, or reach a feature meant for a different role. It is the most common serious flaw in web apps, and it is…
Most security problems in a young web app are not exotic. They sit in the two places every product has to get right on day one: sign-in, where a mistake hands someone else's account to a stranger, and payments, where a…
Adding an AI assistant to a product is now a weekend job. Prompt injection testing, the work of checking what the assistant does when someone tries to turn it against you, usually is not done at all. Prompt injection is…