teampizza / backpack

_you_ got your back
GNU Affero General Public License v3.0
5 stars 1 forks source link

security audit #9

Open ghost opened 10 years ago

ghost commented 10 years ago

We should get a security audit at least before open beta.

ghost commented 10 years ago

Possible concern: JSON injection through HTTP packets--the POC model for example, uses regex on the packet which it then puts unfiltered into JSON and then the mongo database.