Support

  • Why OpSecX
  • Customer Support
OpSecX Navigation

OpSecX

Online Security Education Platform

Home

Shopping Cart

  • $0.00 0 items

Main Menu

  • Online Security Courses
    • View All Courses
    • Automated Mobile Application Security Assessment with MobSF
    • Android Security Tools Expert
    • XSSing JavaScript-MVC Applications
    • Cross Site Scripting (XSS) Attacks for Pentesters
    • Node.js Security: Pentesting and Exploitation
    • WebSecNinja: Lesser Known WebAttacks
    • Windows Exploit Development Megaprimer
    • Mobile Security Bundle
    • Web Security Bundle
  • Services
    • Application Security Services
    • Live Training
      • WebSecNinja 2.0 Live Edition
      • AndroSecNinja Live Edition
      • Mobile Security Framework Live Edition
      • Pentesting modern day application technology stack
  • Resources
    • Blog
    • Security Books
  • My Account
    • Log In
Return to Content

Global Namespace Pollution

Please purchase the course before starting the lesson.

Lesson tags: global name space pollution, namespace pollution, node.js security
Introduction to Node.js
HTTP Parameter Pollution (HPP)
Back to: Node.js Security: Pentesting and Exploitation – NJS > Node.js Security Issues

Node.js Security: Pentesting and Exploitation – NJS

  • Previous
  • Next
  • Introduction

  • Node.js Security: Pentesting and Exploitation - Overview
  • Introduction to Node.js
  • Node.js Security Issues

  • Global Namespace Pollution
  • HTTP Parameter Pollution (HPP)
  • Remote Code Execution with eval()
  • Remote OS Command Execution
  • Attacks due to Untrusted user input
  • Regex DoS
  • Information Disclosure

  • Information Disclosure in Node.js Web Applications
  • Secure Coding

  • Lack of Secure Code in Node.js
  • Code Review

  • How to do Code Review of a Node.js Application
  • Automated Code Review

  • Automated Code Review of Node.js Application with NodeJsScan
  • Conclusion

  • Conclusion
  • Course Slides

Copyright © 2024. All Rights Reserved.

OpSecX. | An OpenSecurity Initiative

Privacy Policy | Terms and Conditions | Customer Support | Security