Web Application Security
The vulnerabilities attackers actually exploit in web apps, and how to prevent them.
Backend Engineer track
Junior
Write correct code, ship small changes safely, ask good questions.
Core: start here
- Cross-Site Scripting (XSS)Injecting scripts into pages other users view.
- IDORReaching other users' data by changing an ID; a missing authorization check.
- Input ValidationChecking every input at the boundary before using it.
- Never Trust the ClientAnything from the browser can be forged, so validate on the server.
- SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.
3 more junior concepts
- Input SanitizationCleaning untrusted input, and why validation and escaping matter more.
- Output Encoding / EscapingEscaping data for the context it's inserted into.
- Parameterized QueryPassing values separately from SQL so they can't change its meaning.
Mid-level
Own a feature end to end without hand-holding.
Core: start here
- CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
- CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
- OWASP Top 10The ten most critical web application security risks.
- Rate LimitingLimiting how many requests a client can make.
18 more mid-level concepts
- Bot Protection and CAPTCHATelling humans apart from automated abuse.
- Broken Access ControlThe #1 OWASP risk: users acting outside their permissions.
- ClickjackingTricking users into clicking hidden elements inside an iframe.
- Command InjectionRunning shell commands through unsanitized input.
- Content Security PolicyA header restricting which scripts and resources a page may load.
- DDoSOverwhelming a service with traffic from many sources.
- File Upload SecurityValidating the type, size and content of uploaded files.
- Mass AssignmentClients setting fields they shouldn't, like isAdmin.
- Open RedirectA redirect parameter abused to send users to malicious sites.
- Path TraversalReaching files outside an allowed directory with ../.
- Prompt InjectionUntrusted text hijacking a model's instructions.
- Prototype PollutionInjecting properties into JavaScript's Object prototype.
- Same-Origin PolicyThe browser rule that isolates content from different origins.
- Security HeadersHTTP headers that harden browsers against attacks.
- Security MisconfigurationDefault passwords, verbose errors and exposed admin panels.
- Stored, Reflected and DOM XSSThe three kinds of XSS and where each comes from.
- Trust BoundaryWhere data crosses from untrusted to trusted; validate there.
- Web Application FirewallFiltering malicious HTTP traffic before it reaches your app.
Senior
Own a system, its failure modes, and its trade-offs.
- Business Logic VulnerabilitiesAbusing legitimate features in unintended ways.
- Insecure DeserializationDeserializing untrusted data in a way that executes code.
- ReDoSRegular expressions that take exponential time on crafted input.
- SSRFTricking a server into making requests to internal systems.
- XXEXML parsers fetching external entities and leaking files.
Staff
Shape how many teams build, across systems.
Nothing here yet.
Principal
Set technical direction for the organization.
Nothing here yet.
Data Analyst track
Junior
Write correct SQL, build trusted dashboards, ask good questions.
Nothing here yet.
Mid-level
Own an analysis end to end, from vague question to recommendation.
- Parameterized QueryPassing values separately from SQL so they can't change its meaning.
- Rate LimitingLimiting how many requests a client can make.
- SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.
Senior
Own experimentation and metrics design; call out bad numbers.
Nothing here yet.
Staff
Shape how the organization measures and decides.
Nothing here yet.
Principal
Set measurement strategy across the company.
Nothing here yet.
Data Engineer track
Junior
Build and fix pipelines from clear specs; write correct SQL.
Nothing here yet.
Mid-level
Own pipelines and models end to end, including their quality.
- Prompt InjectionUntrusted text hijacking a model's instructions.
- Rate LimitingLimiting how many requests a client can make.
Senior
Design the platform's storage, processing and modeling choices.
Nothing here yet.
Staff
Shape how the whole organization produces and uses data.
Nothing here yet.
Principal
Set data strategy and architecture across the company.
Nothing here yet.
Frontend Engineer track
Junior
Build UI that works, ship small changes safely, ask good questions.
Core: start here
- CORSCross-Origin Resource Sharing: how a server lets browsers call it from other origins.
- Cross-Site Scripting (XSS)Injecting scripts into pages other users view.
- Never Trust the ClientAnything from the browser can be forged, so validate on the server.
- Same-Origin PolicyThe browser rule that isolates content from different origins.
5 more junior concepts
- IDORReaching other users' data by changing an ID; a missing authorization check.
- Input SanitizationCleaning untrusted input, and why validation and escaping matter more.
- Input ValidationChecking every input at the boundary before using it.
- Output Encoding / EscapingEscaping data for the context it's inserted into.
- SQL InjectionAttackers running SQL through unescaped input; prevented with parameterized queries.
Mid-level
Own a feature end to end without hand-holding.
Core: start here
- Content Security PolicyA header restricting which scripts and resources a page may load.
- CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
14 more mid-level concepts
- Bot Protection and CAPTCHATelling humans apart from automated abuse.
- Broken Access ControlThe #1 OWASP risk: users acting outside their permissions.
- ClickjackingTricking users into clicking hidden elements inside an iframe.
- DDoSOverwhelming a service with traffic from many sources.
- File Upload SecurityValidating the type, size and content of uploaded files.
- Open RedirectA redirect parameter abused to send users to malicious sites.
- OWASP Top 10The ten most critical web application security risks.
- Prompt InjectionUntrusted text hijacking a model's instructions.
- Rate LimitingLimiting how many requests a client can make.
- Security HeadersHTTP headers that harden browsers against attacks.
- Security MisconfigurationDefault passwords, verbose errors and exposed admin panels.
- Stored, Reflected and DOM XSSThe three kinds of XSS and where each comes from.
- Subresource IntegrityVerifying that third-party scripts haven't been tampered with.
- Trust BoundaryWhere data crosses from untrusted to trusted; validate there.
Senior
Own an app's architecture, performance, and failure modes.
- Business Logic VulnerabilitiesAbusing legitimate features in unintended ways.
- Prototype PollutionInjecting properties into JavaScript's Object prototype.
- ReDoSRegular expressions that take exponential time on crafted input.
Staff
Shape how many teams build, across apps.
Nothing here yet.
Principal
Set technical direction for the organization.
Nothing here yet.