Dangerous functions (sinks)
TL;DR
A “sink” is a place where data does something dangerous — runs a query, executes a command, touches the filesystem. Learn the categories and you can grep straight to the risky parts of a codebase.
What it is
Most vulnerabilities happen when untrusted input reaches a powerful function without being handled first. Those powerful functions are sinks. You don’t need to memorise every one — just the families.
The families to watch
- Database queries built as strings → SQL injection.
- Command / shell execution → command injection.
- Deserialization of untrusted data → often remote code execution.
- File paths and operations → path traversal and file disclosure.
- Template rendering / dynamic evaluation (
eval-like) → injection and RCE. - Output written into a page without encoding → XSS.
How to use it
Grep the codebase for these patterns, then work backwards: does any user input reach this sink without being validated or parameterised? The safe forms exist for every one of these (parameterised queries, argument-list APIs, safe deserialisers, output encoding) — the finding is when they’re not used.