>defend against DDoS but not sanitizing user input
>calling a pentested a script kiddie
welp, my work is done here
>calling a pentested a script kiddie
welp, my work is done here
Filtering user inputs is security 101, yet we missed this while focusing on fancy defense mechanics. This large gap between what the engineering team prepared for, and how they were exposed, is what made the outcome "embarrassing" - hence I agreed with GP that CSV/Excel stuff could be a blind spot even for well-trained people.
Atleast you're thinking about it, company I work for definitely prioritizes freedom over security if you know what i mean