I don't do webapps, but I'm sure everyone's vulnerable somewhere, if they do.
I just dislike the whole "upvote for x" comment that dredges up from Reddit.
'Just lowers the signal-to-noise ratio, and I hate to see things like that creep up on HN.
I just dislike the whole "upvote for x" comment that dredges up from Reddit.
'Just lowers the signal-to-noise ratio, and I hate to see things like that creep up on HN.
The only thing that I've written that could be applied to this is our POS system at the restaurant I work at as a dishwasher and cleaner for. It's in Django though, and the Django project takes care of most issues with that...not that they're really priority #1 security-wise...
I think a better approach is to verify that the framework is correct. You can do this experimentally, by writing unit tests, or by reading and running the unit tests of the framework itself.