<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Alek&#x27;s Blog - application-security</title>
    <subtitle>Production notes on Kubernetes, OpenShift, and OVHcloud: observability, log archiving, service mesh, LLM inference, and digital sovereignty.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.none.at/tags/application-security/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.none.at"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2026-06-27T00:00:00+00:00</updated>
    <id>https://blog.none.at/tags/application-security/atom.xml</id>
    <entry xml:lang="en">
        <title>What is Application Security</title>
        <published>2026-06-20T00:00:00+00:00</published>
        <updated>2026-06-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              aleks
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.none.at/blog/2026/2026-06-19-ddos-application/"/>
        <id>https://blog.none.at/blog/2026/2026-06-19-ddos-application/</id>
        
        <summary type="html">&lt;p&gt;The third part of the (D)DoS series — but a step sideways: this post covers attacks at the Application layer that affect &lt;strong&gt;confidentiality and integrity&lt;&#x2F;strong&gt; rather than availability. SQL Injection, Log4Shell, and similar vulnerabilities have a different threat model than the DDoS attacks covered in the &lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-06-19-ddos-technical&#x2F;&quot;&gt;technical part&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;</summary>
        
    </entry>
    <entry xml:lang="en">
        <title>(D)DoS and Application Security: The Complete Guide</title>
        <published>2026-06-19T00:00:00+00:00</published>
        <updated>2026-06-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              aleks
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.none.at/blog/2026/2026-06-19-ddos-guide/"/>
        <id>https://blog.none.at/blog/2026/2026-06-19-ddos-guide/</id>
        
        <summary type="html">&lt;p&gt;This is the index and reading guide for a three-part series on denial-of-service and application
security. The first two parts cover &lt;strong&gt;availability&lt;&#x2F;strong&gt; attacks — a service being made unreachable or
unusable — at levels most people don’t associate with the term “DDoS”: the business level (losing
the people who run the service), the social level (manipulating the humans behind it), the
informational level (reputational disruption), and finally the technical level most readers expect
(network floods, BGP hijacking, Layer 7 exhaustion). The third part is a deliberate step sideways,
into application-layer attacks — SQL Injection, Log4Shell, the OWASP Top 10 — that threaten
&lt;strong&gt;confidentiality and integrity&lt;&#x2F;strong&gt; instead of availability.&lt;&#x2F;p&gt;</summary>
        
    </entry>
</feed>
