add prompts and knowledge files
This commit is contained in:
parent
2e8d482940
commit
18c36419dc
16 changed files with 516 additions and 0 deletions
18
data/knowledge/security.txt
Normal file
18
data/knowledge/security.txt
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
Buffer overflow occurs when a program writes more data to a buffer than it can hold.
|
||||
Format string vulnerabilities allow reading and writing arbitrary memory locations.
|
||||
SQL injection happens when untrusted input is concatenated into SQL queries.
|
||||
Cross-site scripting (XSS) injects malicious scripts into web pages viewed by others.
|
||||
Privilege escalation exploits bugs to gain higher level access than authorized.
|
||||
Race conditions occur when the timing of events affects program behavior in unintended ways.
|
||||
Integer overflow wraps around to negative or small values causing logic errors.
|
||||
Use-after-free vulnerabilities access memory after it has been freed causing corruption.
|
||||
ASLR randomizes memory addresses to make exploitation more difficult.
|
||||
Stack canaries protect against stack buffer overflows by detecting corruption before return.
|
||||
NX bit marks memory pages as non-executable preventing code execution in data regions.
|
||||
Kernel exploits target vulnerabilities in the operating system kernel for full system compromise.
|
||||
The heartbleed bug in OpenSSL allowed reading memory from servers without authentication.
|
||||
Spectre and Meltdown are CPU vulnerabilities that leak information through side channels.
|
||||
The principle of least privilege says code should run with only the permissions it needs.
|
||||
Defense in depth uses multiple layers of security controls so no single failure is catastrophic.
|
||||
Zero day vulnerabilities are unknown to the vendor and have no available patch.
|
||||
A threat model identifies potential attackers their capabilities and the assets they target.
|
||||
Loading…
Add table
Add a link
Reference in a new issue