Library Hours
Monday to Friday: 9 a.m. to 9 p.m.
Saturday: 9 a.m. to 5 p.m.
Sunday: 1 p.m. to 9 p.m.
Naper Blvd. 1 p.m. to 5 p.m.
     
Limit search to available items
Record 1 of 2
Results Page:  Previous Next
Author Karande, Chetan, author.

Title Patterns in Node package vulnerabilities : essential findings for busy developers / Chetan Karande. [O'Reilly electronic resource]

Edition First edition.
Publication Info. Sebastopol, CA : O'Reilly Media, [2018]
©2018
QR Code
Description 1 online resource (1 volume) : illustrations
data file
Summary With more than 500 new Node.js packages arriving each day, npm is the world's largest reusable package registry and the Node ecosystem's greatest strength. But as the number of detected vulnerabilities continues to rise significantly, the packages themselves are becoming a liability. This ebook shows application developers and penetration testers practical strategies for evaluating and working with today's npm packages. Author Chetan Karande (Securing Node Applications) analyzes package vulnerabilities found by security researchers and the Node community, including common coding mistakes behind the most severe and frequently found problems. While the database is by no means comprehensive due to the flood of new packages, these known vulnerabilities still provide a valuable guide to help you conduct a manual code review of npm packages. You'll examine the top Node package vulnerabilities, including: Insecure access to the filesystem that leads to directory traversal and symlink attacks Pitfalls that often cause Node developers to inadvertently expose sensitive data Denial-of-service attacks that can prevent legitimate users from accessing your service Cross-site scripting (XSS), a prevalent web application security flaw and frequently occurring vulnerability in Node packages Injection vulnerabilities that enable attackers to obtain, corrupt, or destroy server contents.
Subject Node.js.
Node.js
Web applications.
Application software -- Development.
JavaScript (Computer program language)
Applications Web.
Logiciels d'application -- Développement.
JavaScript (Langage de programmation)
Application software -- Development
JavaScript (Computer program language)
Web applications
ISBN 1491999977
9781491999974
Patron reviews: add a review
Click for more information
EBOOK
No one has rated this material

You can...
Also...
- Find similar reads
- Add a review
- Sign-up for Newsletter
- Suggest a purchase
- Can't find what you want?
More Information