<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
      <title>Alek&#x27;s Blog - application-security</title>
      <link>https://blog.none.at</link>
      <description>Production notes on Kubernetes, OpenShift, and OVHcloud: observability, log archiving, service mesh, LLM inference, and digital sovereignty.</description>
      <generator>Zola</generator>
      <language>en</language>
      <atom:link href="https://blog.none.at/tags/application-security/rss.xml" rel="self" type="application/rss+xml"/>
      <lastBuildDate>Sat, 27 Jun 2026 00:00:00 +0000</lastBuildDate>
      <item>
          <title>What is Application Security</title>
          <pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-06-19-ddos-application/</link>
          <guid>https://blog.none.at/blog/2026/2026-06-19-ddos-application/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-06-19-ddos-application/">&lt;p&gt;The third part of the (D)DoS series — but a step sideways: this post covers attacks at the Application layer that affect &lt;strong&gt;confidentiality and integrity&lt;&#x2F;strong&gt; rather than availability. SQL Injection, Log4Shell, and similar vulnerabilities have a different threat model than the DDoS attacks covered in the &lt;a href=&quot;https:&#x2F;&#x2F;blog.none.at&#x2F;blog&#x2F;2026&#x2F;2026-06-19-ddos-technical&#x2F;&quot;&gt;technical part&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;</description>
      </item>
      <item>
          <title>(D)DoS and Application Security: The Complete Guide</title>
          <pubDate>Fri, 19 Jun 2026 00:00:00 +0000</pubDate>
          <author>aleks</author>
          <link>https://blog.none.at/blog/2026/2026-06-19-ddos-guide/</link>
          <guid>https://blog.none.at/blog/2026/2026-06-19-ddos-guide/</guid>
          <description xml:base="https://blog.none.at/blog/2026/2026-06-19-ddos-guide/">&lt;p&gt;This is the index and reading guide for a three-part series on denial-of-service and application
security. The first two parts cover &lt;strong&gt;availability&lt;&#x2F;strong&gt; attacks — a service being made unreachable or
unusable — at levels most people don’t associate with the term “DDoS”: the business level (losing
the people who run the service), the social level (manipulating the humans behind it), the
informational level (reputational disruption), and finally the technical level most readers expect
(network floods, BGP hijacking, Layer 7 exhaustion). The third part is a deliberate step sideways,
into application-layer attacks — SQL Injection, Log4Shell, the OWASP Top 10 — that threaten
&lt;strong&gt;confidentiality and integrity&lt;&#x2F;strong&gt; instead of availability.&lt;&#x2F;p&gt;</description>
      </item>
    </channel>
</rss>
