6 lessons

Injection & Untrusted Input

The same bug in six costumes: data crossing a boundary and being interpreted as instructions — SQL, shell, paths, URLs, serialized objects.

Asset→Threat→Attack Surface→Trust Boundary→Vulnerability→Exploit Path→Impact→Mitigation→Defense in Depth→Residual Risk

Every lesson below identifies the asset, attacker capability and boundary before naming the vulnerability. Controls are split into prevention, detection and recovery; residual risk is explicit.