Mistake Clinic
Module-Specific Mistake Radar
| Mistake | Signal | Repair |
|---|---|---|
| Scanner equals verification | Business flaws absent | Map threats and manual tests |
| Payload blocklist | Encoding bypass works | Remove executable interpretation |
| CORS as authorization | Non-browser client succeeds | Enforce server policy |
| Route-level role only | Cross-object access | Check subject-object-action |
| Patch without scope | Sibling route remains vulnerable | Search variants and add regressions |
Practice Mistake Checks
Verify canonicalization, parameterization, output context, browser boundaries, every authorization route, upload and fetch constraints, invariants under concurrency, sensitive data paths, dependencies, regression, scope, and disclosure.
Required evidence
Submit authorized reproduction, request and response evidence with secrets removed, code and configuration repair, bypass variants, deterministic regression, ASVS mapping, scope analysis, and residual risk. Raw scanner severity is not accepted without triage.
Oral defense
Demonstrate the violated invariant, explain why the repair generalizes, run a bypass attempt, and identify adjacent routes or versions included in scope.
Source backbone
Use OWASP ASVS, OWASP WSTG, OWASP Cheat Sheets, and NIST SSDF.