Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Node.js: Security (2018)

Node.js: Security (2018)

52mIntermediate2018-08-31

Authors

Emmanuel Henri

Emmanuel Henri

Executive with 20+ years of experience in programming and design

Course details

How can you protect your Node.js applications from potential threats? In this course, Emmanuel Henri shares best practices that can help Node.js developers secure their apps at all levels, from packages to the server level. Emmanuel helps to familiarize you with the most common security risks in Node.js., including cross-site scripting and server-side injection. He dives into best practices around packages, data, and the server level. Plus, he covers tools—such as Snyk and Burp—that you can use to test your Node.js projects.
Learning objectives
OWASP resources and security threats
Cross-site scripting and denial of service attacks
Managing packages in a Node.js app
Adding two-factor and read-only tokens with npm
Using prepared statements for SQL/NoSQL
Encrypting user data and session management
Adding HTTPS protocol to an application
Using cookie attributes
Tools for testing

Skills covered

NPMNode.jsJavaScript FrameworksWeb DevelopmentOpen SourceDeep Dive (X:Y)

Concepts

0. Introduction

  • 01 - Securing your Node.js projects
  • 02 - What you should know

1. Security Overview

  • 03 - Introduction to OWASP and other sources
  • 04 - OWASP top 10 in Node.js
  • 05 - Overview of cross-site scripting
  • 06 - Overview of denial of service
  • 07 - Overview of server-side injection

2. Best Practices - Packages

  • 08 - Hands-on base template overview
  • 09 - Maintain package dependencies
  • 10 - Add two-factor and read-only tokens with npm

3. Best Practices - Data

  • 11 - Data handling with type and validation
  • 12 - Use prepared statements for SQL NoSQL
  • 13 - Set proper HTTP headers with Helmet
  • 14 - Encrypt user data and session management

4. Best Practices - Server Level

  • 15 - Use secure HTTPS protocol
  • 16 - Rate limiting against DoS attacks
  • 17 - Use csurf to prevent CSRF attacks
  • 18 - Use cookie attributes

5. Tools for Testing

  • 19 - Introduction to OWASP dependency check
  • 20 - Find vulnerabilities with Snyk
  • 21 - Penetration testing with Burp

Conclusion

  • 22 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal