19: Node.js Application Security

Опубликовано: 16 Июнь 2026
на канале: The Web Platform Podcast
262
1

Chetan Karande (@karande_c), talks about Node.js App security and ways developers can prevent attacks. He goes into detail about working with Express.js in particular, NodeGoat, & his work with OWASP. Chetan is a team lead and senior software engineer at Omgeo and frequently speaks at conferences about JavaScript, Front End Technologies, Java, & Node.js.Resources:




Chetan’s Twitter -   / karande_c  




Chetan’s G+ - https://plus.google.com/1033188080825...




FluentConf Interview -    • Video  




FluentConf Slides - https://speakerdeck.com/ckarande/top-...




jssummit - http://environmentsforhumans.com/2014...




omgeo- https://www.omgeo.com/




node.js vulnerabilities http://blog.nodejs.org/vulnerability/




Express vulnerabilities - http://expressjs.com/advanced/securit...




node security project - https://nodesecurity.io/advisories




node-goat - https://www.owasp.org/index.php/OWASP...




retire.js - http://open.bekk.no/retire-js-what-yo...




OWASP ZAP Proxy - https://www.owasp.org/index.php/OWASP...




grunt-zap - https://www.npmjs.org/package/grunt-z...




chetan github - https://github.com/ckarande




CVSS (Common vulnerability  Scoring System) - http://nvd.nist.gov/cvss.cfm?calculat...




ReDos RegEx Test Tools -





RXRR - http://www.cs.bham.ac.uk/~hxt/researc...)




SDL RegEX Fuzzer -  http://www.microsoft.com/en-us/downlo...