SSTI in Django: how Jinja2 MRO traversal achieves RCE, why Django's DTL is safe by design, and where that guarantee evaporates. OWASP A03:2021, CVE-2022-22954.
Read more →
XSS in Django: how stored, reflected and DOM-based attacks work, why mark_safe() and unsafe Markdown open the same hole, and how to migrate to nh3.
Read more →
SQL Injection: how attackers exploit unsanitised queries, why Django's ORM stops them, and where the protection ends. OWASP A03:2021, CySA+ VM.
Read more →
Petição Brasil validates ICP-Brasil digital signatures automatically, enabling legally binding Popular Initiative Bills in Brazil.
Read more →
PUCRS Capstone (10/10): ICP-Brasil PKI and SHA-256 signatures to validate digital petitions with constitutional legal standing in Brazil.
Read more →