DEV Community

#backend

Desenvolvimento do lado do servidor, APIs, bancos de dados e logica de negocios.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Building a Secure Employee Management System Using Ballerina, PostgreSQL, Docker, and React

Building a Secure Employee Management System Using Ballerina, PostgreSQL, Docker, and React

Comments
4 min read
Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Comments
5 min read
Webhook Signature Bypass: When the Receiver Skips the HMAC Check

Webhook Signature Bypass: When the Receiver Skips the HMAC Check

Comments
5 min read
Web Cache Deception Against APIs: CDNs Cache What Backends Serve Privately

Web Cache Deception Against APIs: CDNs Cache What Backends Serve Privately

Comments
6 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Comments
5 min read
Working: Prototype Pollution in Node.js APIs Is a Process-Wide Trust Failure, Not a Library Bug

Working: Prototype Pollution in Node.js APIs Is a Process-Wide Trust Failure, Not a Library Bug

Comments
5 min read
HTTP Verb Tampering in REST APIs: When OPTIONS and HEAD Bypass Access Control

HTTP Verb Tampering in REST APIs: When OPTIONS and HEAD Bypass Access Control

Comments
5 min read
Working: OTel Spans Are Secret Stores — How Distributed Traces Leak Bearer Tokens to Anyone With Observability Access

Working: OTel Spans Are Secret Stores — How Distributed Traces Leak Bearer Tokens to Anyone With Observability Access

Comments
4 min read
Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Comments
4 min read
API Key Scope Validation Failures: When 'Read-Only' Is a Documentation Claim, Not a Backend Constraint

API Key Scope Validation Failures: When 'Read-Only' Is a Documentation Claim, Not a Backend Constraint

Comments
5 min read
SSTI in APIs: When JSON Parameters Reach Template Engines and Become RCE

SSTI in APIs: When JSON Parameters Reach Template Engines and Become RCE

Comments
5 min read
Working: Rate Limiters Key on Raw Paths — Routers Normalize After

Working: Rate Limiters Key on Raw Paths — Routers Normalize After

Comments
4 min read
gRPC Security: The Authorization Model REST Scanners Cannot See

gRPC Security: The Authorization Model REST Scanners Cannot See

Comments
5 min read
Race Conditions in APIs: TOCTOU in Payments, Coupons, and Rate Limiting

Race Conditions in APIs: TOCTOU in Payments, Coupons, and Rate Limiting

Comments
6 min read
REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

REST API File Upload Attack Chains: MIME Bypass, Path Traversal, and SVG-to-XSS

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.