Do all the things like ++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatarSign Up
okkimus28836dValidate all inputs. Validate stuff on server. Don't use technology that isn't maintained security wise.
groot696dXSS, html escape everything while storing or presenting.. validate all forms .. read the owasp guide to prevent such things.. pretty much standard if you are using any good framework which takes care of this for you.
zlice19726dwhy are your rants homework questions? -.-
Just using Dev rant for what it is meant to used.
njpugh901466dDon't rely on client side validation, easy to bypass, if you want some client side validation as someone fills a form out, make sure you check when it gets to the server as well.
sql injection (similar attacks are possible with meteor/mongo if you don't check params to methods)
shit password storage algorithms (try not to roll your own authentication in general)
shit admin passwords
not enforcing ssl (more a problem for the users)
exposing secret api keys
no or wide-open spf/dkim/dmarc policies, enabling phishing
server admin stuff
Hiring developers who can use google
Never trust client.
Hit at least staging, if possible Dev too, with w3af, zap or something similar. Don't go to production while it still finds something... That won't replace a proper pentest, but the absolutely basic and obvious security issues will be identified.
Your Job Suck?
Take a quick quiz from Triplebyte to skip the job search hassles and jump to final interviews at hot tech firms
Get a Better Job