Skip to main content

Mistake Clinic

Module-Specific Mistake Radar

MistakeSignalRepair
Scanner equals verificationBusiness flaws absentMap threats and manual tests
Payload blocklistEncoding bypass worksRemove executable interpretation
CORS as authorizationNon-browser client succeedsEnforce server policy
Route-level role onlyCross-object accessCheck subject-object-action
Patch without scopeSibling route remains vulnerableSearch variants and add regressions

Practice Mistake Checks

Verify canonicalization, parameterization, output context, browser boundaries, every authorization route, upload and fetch constraints, invariants under concurrency, sensitive data paths, dependencies, regression, scope, and disclosure.

Required evidence

Submit authorized reproduction, request and response evidence with secrets removed, code and configuration repair, bypass variants, deterministic regression, ASVS mapping, scope analysis, and residual risk. Raw scanner severity is not accepted without triage.

Oral defense

Demonstrate the violated invariant, explain why the repair generalizes, run a bypass attempt, and identify adjacent routes or versions included in scope.

Source backbone

Use OWASP ASVS, OWASP WSTG, OWASP Cheat Sheets, and NIST SSDF.