Lazo Lab Sign up

Web Security / Thinking like a defender

Lesson 2 of 27

Never trust input

Anything that comes from the user can be changed: form fields, URLs, cookies, headers, even hidden fields. Validate it on the server, every time.

Key points

  • Client-side checks are for convenience only
  • Validate type, length and format on the server
  • Use allow-lists, not block-lists
Watch a video on thisOpens YouTube search results for “Never trust input” in a new tab

Quiz · +10 XP

Where must input validation happen to be secure?

Log in to save progress and earn XP.