DEV Community

#backend

Desenvolvimento do lado do servidor, APIs, bancos de dados e logica de negocios.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Webhook Signature Bypass: When the Receiver Skips the HMAC Check

Webhook Signature Bypass: When the Receiver Skips the HMAC Check

Comments
5 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Comments
5 min read
SSTI in APIs: When JSON Parameters Reach Template Engines and Become RCE

SSTI in APIs: When JSON Parameters Reach Template Engines and Become RCE

Comments
5 min read
Working: Rate Limiters Key on Raw Paths — Routers Normalize After

Working: Rate Limiters Key on Raw Paths — Routers Normalize After

Comments
4 min read
API Versioning: When /api/v1/ Survives Without the Authentication Added in /api/v2/

API Versioning: When /api/v1/ Survives Without the Authentication Added in /api/v2/

Comments
5 min read
gRPC Server Reflection: The Unauthenticated API Catalog in Your Production Service

gRPC Server Reflection: The Unauthenticated API Catalog in Your Production Service

Comments
5 min read
CRLF Injection in API Responses: When User Input Reaches HTTP Headers

CRLF Injection in API Responses: When User Input Reaches HTTP Headers

Comments
5 min read
Framework Binding Gap: How the ORM Accepts Fields You Never Documented

Framework Binding Gap: How the ORM Accepts Fields You Never Documented

Comments
6 min read
gRPC Security: The Authorization Model REST Scanners Cannot See

gRPC Security: The Authorization Model REST Scanners Cannot See

Comments
5 min read
Race Conditions in APIs: TOCTOU in Payments, Coupons, and Rate Limiting

Race Conditions in APIs: TOCTOU in Payments, Coupons, and Rate Limiting

Comments
6 min read
Mass Assignment in REST APIs: When the Framework Binds More Than It Should

Mass Assignment in REST APIs: When the Framework Binds More Than It Should

Comments
5 min read
REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

Comments
6 min read
Non-Constant-Time Comparison Turns Every API Token into a Character-by-Character Oracle

Non-Constant-Time Comparison Turns Every API Token into a Character-by-Character Oracle

Comments
5 min read
The most dangerous API response is HTTP 200 with an empty body

The most dangerous API response is HTTP 200 with an empty body

Comments
4 min read
API Token in Query Parameter: Six Places the Credential Persists Without You Knowing

API Token in Query Parameter: Six Places the Credential Persists Without You Knowing

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.