Injection & the untrusted-input lens
P57.vuln-classes.01 · Audience: guest, it-ml, language-pro · Prerequisites: AuthZ models: RBAC, ABAC, ReBAC
Welcome to Application & API Security — the first pillar of Domain C, and where the protocol and identity knowledge of P52–P56 meets the code you actually write. One mental model covers a whole family of bugs: untrusted input that crosses a trust boundary and gets interpreted as code. This track instantiates it twice — in SQL, and in the path resolver.
Same thread as every module here: concept → protocol → attack → defence. Every kata is fix-the-function: hostile strings appear only as test inputs your defence must neutralise, and the graded work is always the fix.
The code runs entirely in your browser (Pyodide) against stubbed APIs — no real database, shell, or filesystem is involved.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — fix a SQL-injectable query builder
Loading exercise…
Rung 2 — confine a file path (stop traversal)
Loading exercise…
My notes on this module
Loading your notes...
Where next?
Later in Vulnerability Classes
This module unlocks