Cheat sheets

One-page references for the stuff you keep googling. Print them, pin them, or save them as PDF (choose “Save as PDF” in the print dialog).

HTTP status codes

The three-digit number a server sends back with every response. The first digit tells you the family.

CodeNameIn plain English
1xx · Informational
101Switching Protocols“OK, let's switch to WebSockets.”
2xx · Success
200OKHere's what you asked for.
201CreatedI made the new thing.
204No ContentDone, nothing to send back.
3xx · Redirection
301Moved PermanentlyIt lives at a new address now. Update your links.
302FoundGo over there for now.
304Not ModifiedNothing changed, use your cached copy.
308Permanent RedirectLike 301, but keep the same method (POST stays POST).
4xx · Client error (your request)
400Bad RequestI can't understand that request.
401UnauthorizedWho are you? Log in first.
403ForbiddenI know who you are. You're still not allowed.
404Not FoundNothing lives here.
405Method Not AllowedYou can't POST (or DELETE…) to this.
409ConflictThat clashes with the current state.
422Unprocessable ContentI understood it, but the data is invalid.
429Too Many RequestsSlow down. You've hit a rate limit.
5xx · Server error (their problem)
500Internal Server ErrorSomething broke on the server.
502Bad GatewayThe server behind me sent nonsense.
503Service UnavailableDown or overloaded. Try again later.
504Gateway TimeoutThe server behind me took too long.

Memory trick: 401 = “who are you?”, 403 = “I know who you are, and no.”

Common ports

A port is like an apartment number on a server: the IP address finds the building, the port finds the service.

PortProtocolServiceNote
20, 21TCPFTPFile transfer. Unencrypted: prefer SFTP.
22TCPSSH / SFTPSecure remote login. Don't expose it to the whole internet.
23TCPTelnetOld and unencrypted. Avoid.
25TCPSMTPServer-to-server email.
53UDP/TCPDNSName → IP lookups.
67, 68UDPDHCPHands out IP addresses on a network.
80TCPHTTPWeb, unencrypted.
110TCPPOP3Download email (old style).
123UDPNTPClock sync.
143TCPIMAPRead email on the server.
443TCP (UDP for HTTP/3)HTTPSWeb, encrypted with TLS.
445TCPSMBWindows file sharing. Never expose to the internet.
587TCPSMTP submissionSending email from an app or client.
993TCPIMAPSIMAP over TLS.
3306TCPMySQLDatabase. Keep it private.
3389TCPRDPWindows Remote Desktop. A favourite attack target.
5432TCPPostgreSQLDatabase. Keep it private.
6379TCPRedisIn-memory store. Keep it private.
8080TCPHTTP (alt)Common for dev servers and proxies.
27017TCPMongoDBDatabase. Keep it private.

Cloud rule of thumb: only 80 and 443 should be open to the whole internet (0.0.0.0/0).

Git commands

Save points for your code. These cover 95% of everyday work.

CommandWhat it does
Start
git initTurn the current folder into a Git repo.
git clone <url>Download a copy of a repo.
Save changes
git statusWhat changed? What's staged?
git add <file> / git add .Stage one file / everything for the next commit.
git commit -m "message"Save a snapshot with a message.
git diffShow unstaged changes line by line.
git log --onelineShort history of commits.
Branches
git switch -c <name>Create a new branch and move to it.
git switch <name>Move to an existing branch.
git merge <name>Bring another branch's changes into this one.
Share
git pullDownload and merge the latest from the remote.
git pushUpload your commits to the remote (e.g. GitHub).
git fetchDownload remote changes without merging.
Undo
git restore <file>Throw away unsaved changes to a file.
git restore --staged <file>Unstage a file, keep the changes.
git stash / git stash popPark changes for later / bring them back.
git revert <commit>Undo a commit safely by adding a new one.
git reset --soft HEAD~1Undo the last commit but keep its changes.

Never commit secrets. Add them to .gitignore before your first commit.

AWS IAM terms

IAM (Identity and Access Management) decides who can do what in an AWS account.

Root user
The account owner with unlimited power. Turn on MFA, then lock it away and don't use it day to day.
User
A person or app with long-term credentials. Prefer roles or SSO for humans.
Group
A set of users that share the same permissions.
Role
An identity you temporarily “assume” to get short-lived credentials. Used by services, apps and other accounts.
Policy
A JSON document listing what is allowed or denied.
Identity-based policy
Attached to a user, group or role: “what can this identity do?”
Resource-based policy
Attached to a resource like an S3 bucket: “who can use this thing?” Has a Principal.
Principal
Who the statement applies to. "*" means anyone.
Effect
Allow or Deny.
Action
The API operation, like s3:GetObject. "*" means every action.
Resource
What the action applies to, written as an ARN.
Condition
Extra rules, like “only from this IP” or “only with MFA”.
ARN
Amazon Resource Name, a unique ID like arn:aws:s3:::my-bucket.
Evaluation rule
Everything starts denied. An Allow grants access. An explicit Deny always wins.
Least privilege
Grant only what's needed, nothing more.
Permissions boundary
A ceiling on the maximum permissions a user or role can ever have.
SCP (Service Control Policy)
An AWS Organizations guardrail that limits what whole accounts can do.
Access key
A long-term key pair for programmatic access. Avoid where possible, rotate them, never commit them to Git.

Paste a policy into the IAM policy explainer to see it in plain English.

OWASP Top 10 (2025), in plain English

The ten most critical web application security risks, from the OWASP Top 10:2025.

  1. A01 Broken Access Control

    People can see or do things they shouldn't, like changing an ID in the URL to read someone else's order. Now also covers SSRF (tricking a server into fetching internal URLs).

    Defend: deny by default and check permissions on the server for every request.

  2. A02 Security Misconfiguration

    Default passwords, public cloud storage, detailed error pages, features left switched on.

    Defend: hardened defaults, automated config checks, remove what you don't use.

  3. A03 Software Supply Chain Failures

    Vulnerable or malicious dependencies, compromised packages or build pipelines.

    Defend: know your dependencies (SBOM), keep them updated, verify what you install, lock down CI/CD.

  4. A04 Cryptographic Failures

    Sensitive data sent or stored without proper encryption, weak algorithms, fast unsalted password hashes.

    Defend: TLS everywhere, modern algorithms, bcrypt or Argon2 for passwords.

  5. A05 Injection

    Untrusted input gets treated as code: SQL injection, command injection, cross-site scripting (XSS).

    Defend: parameterised queries, output encoding, validate input.

  6. A06 Insecure Design

    The plan itself is flawed, like a password reset with no rate limit or a checkout that trusts the price from the browser.

    Defend: threat-model early and use proven secure design patterns.

  7. A07 Authentication Failures

    Weak logins: credential stuffing, no MFA, guessable passwords, sessions that never expire.

    Defend: MFA, rate limiting, breached-password checks, secure session handling.

  8. A08 Software or Data Integrity Failures

    Trusting updates, plugins or data without verifying them, including unsafe deserialisation.

    Defend: signatures and integrity checks on code and data.

  9. A09 Security Logging & Alerting Failures

    Attacks happen and nobody notices, or nobody gets alerted in time.

    Defend: log security events, alert on them, and test that the alerts work.

  10. A10 Mishandling of Exceptional Conditions

    Errors handled badly: failing open, leaking details in error messages, crashing on odd input.

    Defend: fail closed, handle errors consistently, show users generic messages.