JavaScript: Security Essentials (2019)

JavaScript: Security Essentials (2019)

45mIntermediate2019-01-18

Authors

Emmanuel Henri

Emmanuel Henri

Executive with 20+ years of experience in programming and design

Course details

Web security guidelines are useful. Penetration testing finds weak points in code and infrastructure. Somewhere in the middle, though, developers need to create resilient code. In this course, Emmanuel Henri equips JavaScript developers with the basic knowledge and techniques they need to keep their JavaScript applications secure. Discover how to approach the challenges of cross-side scripting, cross-site forgery, server-side injection, and obfuscation, as well as how to best approach sensitive data risks. Throughout the course, Emmanuel shows what these threats actually look like in code, demonstrates syntax corrections you can make to fix these issues, and shares best practices for dealing with key threats.

Learning objectives
Key threats to be aware of as a JavaScript developer
Risks posed by cross-site scripting
Best practices for dealing with cross-site forgery threats
Dealing with sensitive data risks
Preventing server-side injection
Preventing obfuscation

Skills covered

Software Development SecurityJavaScriptOracleCybersecurityProgramming LanguagesSoftware DevelopmentDeep Dive (X:Y)

Concepts

Introduction

  • Build effective and secure JavaScript applications
  • What you should know

Overview of Security Concepts

  • Overview of the most common threats
  • List of available resources
  • Overview of this course's approach

Security Applied - XSS

  • What is cross-site scripting (XSS)
  • Example of XSS in code
  • Final syntax applied XSS
  • Best practices for XSS threats

Security Applied - CSRF

  • What is cross-site request forgery (CSRF)
  • Overview of JSON Web Token (JWT)
  • Overview of Auth0
  • Best practices for CSRF threats

Security Applied - Sensitive Data

  • What are sensitive data risks
  • Overview of the encryption
  • List of the crypto libraries
  • Best practices for sensitive data

Security Applied - SSJI

  • What is server-side JavaScript injection (SSJI)
  • Example of SSJI code
  • How to prevent SSJI

Security Applied - Obfuscation

  • What is obfuscation
  • Tools for scrambling your data
  • Best practices for scrambling data

Conclusion

  • Next steps
40,000 Toman