Writing & Content
PromptBeginner5 minmarkdown
- **Trusting Content-Type headers**: Attackers set any Content-Type they want; validate actual content
not declared type
0
Explore
95,174 skills indexed with the new KISS metadata standard.
not declared type
direct API calls)
Joi
Marshmallow
external API checks)
GraphQL schemas)
Joi
including internal services
size limits
XSS
server
verify:
invalid
not a blocklist
stack traces
past dates
valid foreign keys)
zip bombs
not just MIME type or extension
content types
%2e%2e/) and special characters
parameterization for SQL)
account numbers
XML