Building Software

Engineering Fundamentals for the Agent Era

Contents Section 8, Security

Untrusted Input and Injection

Mistakes to catch in review

  1. A database query or shell command built by string concatenation with user input.

  2. User-supplied content rendered as raw HTML, allowing cross-site scripting.

  3. A server that fetches any URL a user provides, letting attackers reach internal services and cloud metadata endpoints.

  4. A file-upload handler that trusts the client's file name, letting a name like ../../config overwrite files outside the upload folder.

Treating every input as hostile, and understanding the family of attacks where data ends up executed as code or commands.

Topics

The Injection Family
SQL, command, template and path traversal injection, with parameterization as the general cure.
Cross-Site Scripting and Output Encoding
Escaping for the context where data lands, with content security policies as a backstop.
Server-Side Request Forgery
Why servers should fetch user-supplied URLs only against a strict allow-list.
Deserialization and File Uploads
Parsing untrusted formats and accepting files without handing attackers a way to run code.
Prompt Injection
Untrusted text steering a language model, contained by limiting what the model is able to do.
Validation and Parsing at the Edge
Parsing input into well-typed values at the boundary and rejecting anything that does not fit.

You understand it when you can

  • Exploit and then fix an injection bug in a deliberately vulnerable practice application.
  • Explain why output encoding must match the context the data lands in: HTML, attribute, URL, query or shell.
  • Explain why prompt injection cannot be fully solved by filtering input, and what limits the damage it can do.

Drill

An agent built a 'save as PDF' feature that downloads a user-supplied URL and passes the page title into a shell command, plus a support bot that reads ticket text and can issue refunds. Find the three injection paths and the smallest change that closes each one.

Start here

Watch

Running an SQL Injection Attack - Computerphile

Mike Pound, 2016. 17-minute explainer.

Exploits a concatenated query live, dumping data table by table, then shows why parameterized queries close the hole: the model for the whole injection family.

Watch

Cross-Site Scripting (XSS) Explained

PwnFunction, 2020. 11-minute explainer.

Animated walk through reflected, stored and DOM XSS, showing how user content becomes script when it is not encoded for the context it lands in.

Prompt Injection, explained

Simon Willison, 2023. 12-minute talk.

The researcher who named prompt injection explains why filtering cannot fix it and why the defense is limiting what a model with untrusted input is allowed to do, as with the refund-issuing support bot.

Read

Web Application Security: Exploitation and Countermeasures for Modern Web Applications

Andrew Hoffman, 2024, 2nd edition.

Covers XSS, injection, SSRF and deserialization from both the attack and the defense side, updated for modern stacks such as GraphQL and server-side rendering.

Secure by Design

Dan Bergh Johnsson, Daniel Deogun and Daniel Sawano, 2019.

Teaches domain primitives and strict parsing at the boundary: turn raw input into well-typed values once and reject anything that doesn't fit, which prevents whole classes of injection.

The Tangled Web: A Guide to Securing Modern Web Applications

Michal Zalewski, 2011.

The classic on how browsers actually parse HTML, URLs and scripts, which explains why output encoding must match each context.

Primary sources