Study Notebook / 05
Backend Security
Where you made an assumption, and who is going to find it
Every vulnerability is an assumption someone else found first. Injection across SQL, NoSQL and the shell, password storage done properly, sessions and tokens, and the boundaries where data turns into code.
- pages
- 55
- sections
- 35
- editions
- Reading, Print, Tablet
Sign in to read it
The whole notebook is free for 7 days. No card, no payment. We ask for an account so the download link belongs to someone.
Sign in with GitHub or GoogleWhat is inside
The full table of contents. Nothing here is hidden: if a section you need is not in this list, the notebook is not the right one and you should not spend a week on it.
- The whole book in one question
- 1. Assumptions are the vulnerability
- 2. Your application speaks several languages
- 3. The boundary between data and code
- 4. SQL injection
- 5. Parameterised queries, and what they cannot do
- 6. NoSQL injection
- 7. Command injection
- 8. The argument array
- 9. Build it only if you have a reason
- 10. Never store a password
- 11. Why hashing alone is not enough
- 12. Salt, and the right algorithm
- 13. Sessions
- 14. Cookie flags
- 15. JWT: what you gain and what you give up
- 16. Rate limiting
- 17. The layer where the check belongs
- 18. Broken object level authorization
- 19. What the status code leaks
- 20. Deny by default
- 21. Audit logging
- 22. Cross-site scripting
- 23. Content Security Policy
- 24. Cross-site request forgery
- 25. Clickjacking
- 26. Secrets
- 27. Error messages and debug output
- 28. What you must not log
- 29. Dependencies
- 30. Reviewing an endpoint
- 31. Follow-up question bank
- Appendix A. The response headers
- Appendix B. Glossary
- Appendix C. Self-test
How to read it
Read with a pen. Every notebook opens with a question to answer before you start and asks you to redo the answer at the end, and the margin in the Print edition exists so you have somewhere to be wrong first. The Tablet edition is 16:9 with vector text, so note apps draw on it rather than treating it as a photograph.