Dangerous functions (sinks)

intermediateCode Review

TL;DR

A “sink” is a place where data does something dangerous — runs a query, executes a command, touches the filesystem. Learn the categories and you can grep straight to the risky parts of a codebase.

What it is

Most vulnerabilities happen when untrusted input reaches a powerful function without being handled first. Those powerful functions are sinks. You don’t need to memorise every one — just the families.

The families to watch

How to use it

Grep the codebase for these patterns, then work backwards: does any user input reach this sink without being validated or parameterised? The safe forms exist for every one of these (parameterised queries, argument-list APIs, safe deserialisers, output encoding) — the finding is when they’re not used.

← Back to Code Review