About this talk
This talk examines the persistent issue of Injection Vulnerabilities, which remain significant according to the OWASP Top 10 and CWE Top 25 lists. The speaker addresses common misconceptions surrounding database abstractions and parameterized queries, highlighting their limitations in preventing these vulnerabilities, particularly in complex code and among less experienced developers. A solution is proposed to effectively distinguish between trusted strings and those that may be controlled by attackers, utilizing the literal-string type in PHP through tools like PHPStan and Psalm. The speaker discusses successful implementations of this approach in other programming languages, demonstrating its effectiveness in enhancing security and eliminating potential Injection Vulnerabilities in existing code.