During his secure code review, John, an independent application security expert, found that the developer has used Java code as highlighted in the following screenshot. Identify the security mistake committed by the developer?
I bet the developer is just trying to make the code 'edgy' by using Blacklisting. Gotta stay hip, you know? But security should come first, not fashion.
Ah, the old Whitelist vs. Blacklist debate. I'm with John on this one - Blacklisting is a recipe for disaster. Does the developer even know what they're doing?
Looks like the developer is trying to use Blacklisting Input Validation, which is a big no-no. Can't believe they're still using that outdated technique!
Barrett
1 months agoLorean
1 months agoMable
2 days agoWillodean
9 days agoSkye
9 days agoMari
12 days agoXochitl
23 days agoJulio
1 months agoDaron
2 months agoDell
2 months agoMing
25 days agoOnita
28 days agoHoward
2 months agoQuiana
1 months agoIrma
1 months agoGearldine
2 months agoPamella
2 months agoTerrilyn
2 months ago