← All courses
14 lessonsSelf-paced training

Node.js Security: Pentesting and Exploitation - NJS

Pentest and exploit Node.js applications, including the unique attack surface of server-side JavaScript.

Offered by OpSecX

Course Overview

What this course covers

Node.js® is a platform built on Chrome’s JavaScript runtime for easily building fast, scalable network applications. This new technology is widely getting adopted in various organisations. Like any platform, Node.js has it’s on set of features that developers blindly use without much thought on security. The heart of Node is JavaScript, so it inherits most of the issues that are found at client side JavaScript. However on the server side, it executes on V8 JavaScript engine which gives node the capabilities similar to that of any other server side scripting languages. That difference adds some unique attack surface to Node.js platform. Node.js Security: Pentesting & Exploitation course is one it’s kind to teach about Node.js Security.

What are the requirements?

  • Fundamentals of Web Applications
  • How to write and run a simple Node.js application

What am I going to get from this course?

  • Over 14 lectures and 1 hour of content!
  • Learn how to do the Security Certification of Node.js Application
  • Learn how to build a secure Node.js Application
  • Learn how things can go wrong in Node.js
  • Learn to find security issues in Node.js Applications
  • Learn how to exploit the issues for PoC

What is the target audience?

  • Web Developers
  • Web Application Pentesters
  • Security Engineers
  • Web Application Security Consultants
  • Web Security Enthusiasts
  • Hackers
  • Students
  • Web Application Designers

OpSecX Course Certificate

Upon successful completion of the course, you will be given a Certificate of Appreciation and the certificate can be verified from OpSecX online.

Curriculum

Section 1: Introduction

  1. Node.js Security: Pentesting and Exploitation - Overview
  2. Introduction to Node.js

Section 2: Node.js Security Issues

  1. Global Namespace Pollution
  2. HTTP Parameter Pollution (HPP)
  3. Remote Code Execution with eval()
  4. Remote OS Command Execution
  5. Attacks due to Untrusted user input
  6. Regex DoS

Section 3: Information Disclosure

  1. Information Disclosure in Node.js Web Applications

Section 4: Secure Coding

  1. Lack of Secure Code in Node.js

Section 5: Code Review

  1. How to do Code Review of a Node.js Application

Section 6: Automated Code Review

  1. Automated Code Review of Node.js Application with NodeJsScan

Section 7: Conclusion

  1. Conclusion
  2. Course Materials

Syllabus

What you will learn

Introduction

  1. Node.js Security: Pentesting and Exploitation - Overview

    Lesson

  2. Introduction to Node.js

    Lesson

Node.js Security Issues

  1. Global Namespace Pollution

    Lesson

  2. HTTP Parameter Pollution (HPP)

    Lesson

  3. Remote Code Execution with eval()

    Lesson

  4. Remote OS Command Execution

    Lesson

  5. Attacks due to Untrusted user input

    Lesson

  6. Regex DoS

    Lesson

Information Disclosure

  1. Information Disclosure in Node.js Web Applications

    Lesson

Secure Coding

  1. Lack of Secure Code in Node.js

    Lesson

Code Review

  1. How to do Code Review of a Node.js Application

    Lesson

Automated Code Review

  1. Automated Code Review of Node.js Application with NodeJsScan

    Lesson

Conclusion

  1. Conclusion

    Lesson

  2. Course Slides

    Lesson

Frequently asked questions

What is Node.js Security: Pentesting and Exploitation - NJS?

Pentest and exploit Node.js applications, including the unique attack surface of server-side JavaScript. Offered by OpSecX as self-paced application security training.

Who is this training for?

This course is for pentesters, developers, and security practitioners who want hands-on application security skills they can use on real systems.

How long is the training?

The course includes 14 lessons. You work through it at your own pace.

Do I get a certificate?

Yes. Completing a course issues a verifiable OpSecX certificate with a public verification link. You control whether your name is shown on that page.

How do I access the lessons?

After purchase, lessons are available self-paced in your OpSecX dashboard. Preview lessons on this page do not require enrollment.