Kap7 Security Flashcards
1
Q
How to avoid Command Injection?
A
Avoid external command calls, Assume all input is malicious and Assign permissions that prevents from accessing/opening privileged files (if not required)
2
Q
How to avoid SQL Injection?
A
Input Validation, Escaping, Bound Parameters (Prepared Statements), Limit user privileges and segregate users, Error Reporting
3
Q
How to avoid Cross-Site Scripting?
A
Escaping, Recommendation, Prevent inline JavaScript with Content Security Policies