René's URL Explorer Experiment


Title: GitHub - FoxCode2022/strong-node: :heavy_check_mark: More than 100 security checks for your Node.js API · GitHub

Open Graph Title: GitHub - FoxCode2022/strong-node: :heavy_check_mark: More than 100 security checks for your Node.js API

X Title: GitHub - FoxCode2022/strong-node: :heavy_check_mark: More than 100 security checks for your Node.js API

Description: :heavy_check_mark: More than 100 security checks for your Node.js API - FoxCode2022/strong-node

Open Graph Description: :heavy_check_mark: More than 100 security checks for your Node.js API - FoxCode2022/strong-node

X Description: :heavy_check_mark: More than 100 security checks for your Node.js API - FoxCode2022/strong-node

Opengraph URL: https://github.com/FoxCode2022/strong-node

X: @github

direct link

Domain: github.com

route-pattern/:user_id/:repository
route-controllerfiles
route-actiondisambiguate
fetch-noncev2:c216edbd-96c5-aaf2-6e21-1ab06b4d598a
current-catalog-service-hashf3abb0cc802f3d7b95fc8762b94bdcb13bf39634c40c357301c4aa1d67a256fb
request-id81A4:392A33:B35BFC:F0C9B2:6A60174F
html-safe-nonce3caf5c64f59162558b89d3210f6f8f83a3a3eab79f23ab68958459fd86c4302e
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4MUE0OjM5MkEzMzpCMzVCRkM6RjBDOUIyOjZBNjAxNzRGIiwidmlzaXRvcl9pZCI6IjY5MDg4NjkxNTk4ODEyODM0MDciLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ==
visitor-hmac2bb6d2bfd0c53ae3388a2e1c82f89ac6abe536832d71a6f24eb6ee9c22dd94c9
hovercard-subject-tagrepository:386905777
github-keyboard-shortcutsrepository,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location//
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/FoxCode2022/strong-node
twitter:imagehttps://opengraph.githubassets.com/10a8e3b6ad229c35055916dd3430432409fa9114b80bbc89f845898da7b8f056/FoxCode2022/strong-node
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/10a8e3b6ad229c35055916dd3430432409fa9114b80bbc89f845898da7b8f056/FoxCode2022/strong-node
og:image:alt:heavy_check_mark: More than 100 security checks for your Node.js API - FoxCode2022/strong-node
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None399e662401f6b9a532ecd80b305d17b9efadd864681448a290ab2901b98f288a
turbo-cache-controlno-cache
go-importgithub.com/FoxCode2022/strong-node git https://github.com/FoxCode2022/strong-node.git
octolytics-dimension-user_id87217660
octolytics-dimension-user_loginFoxCode2022
octolytics-dimension-repository_id386905777
octolytics-dimension-repository_nwoFoxCode2022/strong-node
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forktrue
octolytics-dimension-repository_parent_id57211422
octolytics-dimension-repository_parent_nwojesusprubio/strong-node
octolytics-dimension-repository_network_root_id57211422
octolytics-dimension-repository_network_root_nwojesusprubio/strong-node
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release2f4d68ce236d24a2cd682f94ef8bd8537c09d73d
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/FoxCode2022/strong-node#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FFoxCode2022%2Fstrong-node
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub Copilot appDirect agents from issue to mergehttps://github.com/features/ai/github-app
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
Code QualityEnforce quality at mergehttps://github.com/features/code-quality
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
View all resourceshttps://github.com/resources
GitHub SponsorsFund open source developershttps://github.com/open-source/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/open-source/accelerator
GitHub Starshttps://stars.github.com
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/enterprise/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FFoxCode2022%2Fstrong-node
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=FoxCode2022%2Fstrong-node
Reloadhttps://github.com/FoxCode2022/strong-node
Reloadhttps://github.com/FoxCode2022/strong-node
Reloadhttps://github.com/FoxCode2022/strong-node
FoxCode2022 https://github.com/FoxCode2022
strong-nodehttps://github.com/FoxCode2022/strong-node
jesusprubio/strong-nodehttps://github.com/jesusprubio/strong-node
Notifications https://github.com/login?return_to=%2FFoxCode2022%2Fstrong-node
Fork 0 https://github.com/login?return_to=%2FFoxCode2022%2Fstrong-node
Star 0 https://github.com/login?return_to=%2FFoxCode2022%2Fstrong-node
Code https://github.com/FoxCode2022/strong-node
Pull requests 0 https://github.com/FoxCode2022/strong-node/pulls
Actions https://github.com/FoxCode2022/strong-node/actions
Projects https://github.com/FoxCode2022/strong-node/projects
Security and quality 0 https://github.com/FoxCode2022/strong-node/security
Insights https://github.com/FoxCode2022/strong-node/pulse
Code https://github.com/FoxCode2022/strong-node
Pull requests https://github.com/FoxCode2022/strong-node/pulls
Actions https://github.com/FoxCode2022/strong-node/actions
Projects https://github.com/FoxCode2022/strong-node/projects
Security and quality https://github.com/FoxCode2022/strong-node/security
Insights https://github.com/FoxCode2022/strong-node/pulse
https://github.com/FoxCode2022/strong-node
Brancheshttps://github.com/FoxCode2022/strong-node/branches
Tagshttps://github.com/FoxCode2022/strong-node/tags
https://github.com/FoxCode2022/strong-node/branches
https://github.com/FoxCode2022/strong-node/tags
38 Commitshttps://github.com/FoxCode2022/strong-node/commits/master/
https://github.com/FoxCode2022/strong-node/commits/master/
examplehttps://github.com/FoxCode2022/strong-node/tree/master/example
examplehttps://github.com/FoxCode2022/strong-node/tree/master/example
.gitignorehttps://github.com/FoxCode2022/strong-node/blob/master/.gitignore
.gitignorehttps://github.com/FoxCode2022/strong-node/blob/master/.gitignore
README.mdhttps://github.com/FoxCode2022/strong-node/blob/master/README.md
README.mdhttps://github.com/FoxCode2022/strong-node/blob/master/README.md
package.jsonhttps://github.com/FoxCode2022/strong-node/blob/master/package.json
package.jsonhttps://github.com/FoxCode2022/strong-node/blob/master/package.json
READMEhttps://github.com/FoxCode2022/strong-node
https://github.com/FoxCode2022/strong-node#strong-nodejs
Node.jshttps://nodejs.org
Expresshttp://expressjs.com
Hapihttp://hapijs.com
SANShttps://www.sans.org/
checklisthttps://www.sans.org/security-resources/posters/securing-web-application-technologies-swat/60/download
dictionaryhttp://cwe.mitre.org/
https://camo.githubusercontent.com/a839eb6020dc566196962be83efc77225f1b3be14aee181da4c9029096f9a754/68747470733a2f2f692e6962622e636f2f377671534b32432f756e647261772d746f2d646f2d6c6973742d613439622e706e67
Awesome Node.js for penetration testershttps://github.com/jesusprubio/awesome-nodejs-pentest
https://github.com/FoxCode2022/strong-node#1-errors
CWE-209http://cwe.mitre.org/data/definitions/209.html
https://github.com/FoxCode2022/strong-node#11-returned-errors-dont-include-sensitive-information-about-the-user-or-other-users-info-cwe-209
https://github.com/FoxCode2022/strong-node#12-returned-errors-dont-include-sensitive-information-about-the-environment-stack-paths-db-queries-etc-cwe-209
https://github.com/FoxCode2022/strong-node#121-the-environment-variable-node_env-environment-variable-is-set-to-production
https://github.com/FoxCode2022/strong-node#13-default-framework-errors-are-never-returned-cwe-209
CWE-756http://cwe.mitre.org/data/definitions/756.html
https://github.com/FoxCode2022/strong-node#14-a-custom-error-page-is-defined-cwe-756
The Default Error Handlerhttp://expressjs.com/en/guide/error-handling.html#the-default-error-handler
http-errorshttps://github.com/jshttp/http-errors
http://stackoverflow.com/a/28044412/2087521http://stackoverflow.com/a/28044412/2087521
http://stackoverflow.com/a/32185406/2087521http://stackoverflow.com/a/32185406/2087521
Boomhttps://github.com/hapijs/boom
"uncaughtException"https://nodejs.org/api/process.html#process_event_uncaughtexception
"denial of service"https://en.wikipedia.org/wiki/Denial-of-service_attack
CWE-248http://cwe.mitre.org/data/definitions/248.html
https://github.com/FoxCode2022/strong-node#15-the-app-takes-care-of-uncaughtexception-events-to-avoid-a-the-application-stop-denial-of-service---cwe-248
"unhandledRejection"https://nodejs.org/api/process.html#process_event_unhandledrejection
promiseshttp://www.html5rocks.com/en/tutorials/es6/promises/?redirect_from_locale=es
https://github.com/FoxCode2022/strong-node#16-the-app-takes-care-of-unhandledrejection-events-the-same-idea-but-with-promises-cwe-248
Uncaught Exceptions in Node.jshttp://shapeshed.com/uncaught-exceptions-in-node
Joyenthttps://www.joyent.com/
http://www.joyent.com/developers/node/design/errorshttp://www.joyent.com/developers/node/design/errors
Poophttps://github.com/hapijs/poop
Dyno crash restart policyhttps://devcenter.heroku.com/articles/dynos#dyno-crash-restart-policy
CWE-203http://cwe.mitre.org/data/definitions/203.html
https://github.com/FoxCode2022/strong-node#17-the-content-of-the-errors-should-avoid-to-reason-about-any-internal-state-of-the-application-cwe-203
CWE-208http://cwe.mitre.org/data/definitions/208.html
https://github.com/FoxCode2022/strong-node#18-the-time-to-return-an-error-should-avoid-to-reason-about-any-internal-state-of-the-application-cwe-208
ESLinthttp://eslint.org/
"detect-possible-timing-attacks"https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-possible-timing-attacks.js
nanownhttps://github.com/ecbftw/nanown
time_trialhttps://github.com/dmayer/time_trial
"cryptiles"https://github.com/hapijs/cryptiles
"credential"https://github.com/ericelliott/credential
"safe-compare"https://github.com/Bruce17/safe-compare
CWE-211http://cwe.mitre.org/data/definitions/211.html
https://github.com/FoxCode2022/strong-node#19-all-dependencies-generated-errors-also-respect-the-points-of-this-section-cwe-211
audit-cihttps://github.com/IBM/audit-ci
auditjshttps://github.com/OSSIndex/auditjs
https://github.com/FoxCode2022/strong-node#2-input-and-output
https://github.com/FoxCode2022/strong-node#21-the-http-header-x-powered-by-is-disabled-in-the-responses
Helmethttps://github.com/helmetjs/helmet
"hide-powered-by" pluginhttps://github.com/helmetjs/hide-powered-by
CWE-172http://cwe.mitre.org/data/definitions/172.html
https://github.com/FoxCode2022/strong-node#22-the-encoding-is-correctly-set-for-all-routes-cwe-172
"body-parser"https://github.com/expressjs/body-parser/
for an specific routehttps://github.com/hapijs/hapi/blob/master/API.md#route-options
CWE-524http://cwe.mitre.org/data/definitions/524.html
https://github.com/FoxCode2022/strong-node#23-inputs-with-sensitive-data-are-never-auto-completedcached-in-the-browser-cwe-524
HTML input "autocomplete" Attributehttp://www.w3schools.com/tags/att_input_autocomplete.asp
https://github.com/FoxCode2022/strong-node#24-the-http-header-cache-control-is-disabled-in-the-responses-cwe-524
https://github.com/FoxCode2022/strong-node#25-the-http-header-etag-is-disabled-in-the-responses-cwe-524
Helmethttps://github.com/helmetjs/helmet
"nocache" pluginhttps://github.com/helmetjs/nocache
Etaghttps://isc.sans.edu/diary/The+Security+Impact+of+HTTP+Caching+Headers/17033
included herehttp://hapijs.com/tutorials/caching
for an specific routehttps://github.com/hapijs/hapi/blob/master/API.md#route-options
CWE-79http://cwe.mitre.org/data/definitions/79.html
https://github.com/FoxCode2022/strong-node#26-the-header-x-xss-protection-is-being-set-cwe-79
Helmethttps://github.com/helmetjs/helmet
"xssFilter" pluginhttps://github.com/helmetjs/x-xss-protection
route optionshttps://github.com/hapijs/hapi/blob/master/API.md#route-options
CWE-77http://cwe.mitre.org/data/definitions/77.html
CWE-89http://cwe.mitre.org/data/definitions/89.html
https://github.com/FoxCode2022/strong-node#27-escaping-potentially-untrusted-inputs-is-applied-for-all-user-entries-cwe-79-cwe-77-cwe-89
Handlebarshttp://handlebarsjs.com/
"escapeExpression"https://github.com/wycats/handlebars.js/blob/88c52ded2e81b4b01d12c16e337b0bc4a453a813/lib/handlebars/utils.js#L52
by defaulthttp://handlebarsjs.com/expressions.html
Dust.jshttp://www.dustjs.com/
by defaulthttps://github.com/linkedin/dustjs/wiki/Dust-Tutorial#more-on-dust-output-and-dust-filters
Swighttp://paularmstrong.github.io/swig
"autoescape"http://paularmstrong.github.io/swig/docs/tags/
express-validatorhttps://github.com/ctavan/express-validator
joihttps://github.com/hapijs/joi
https://github.com/FoxCode2022/strong-node#28-context-sensitive-output-escaping-is-applied-for-all-output-values-cwe-79
Yahoo’s Paranoid Labshttps://yahoo-security.tumblr.com/post/128130790295/paranoid-labs-open-source-and-solving-xss-in
secure-handlebarshttps://github.com/yahoo/secure-handlebars
express-secure-handlebarshttps://github.com/yahoo/express-secure-handlebars
by Yahoohttps://yahoo.github.io/secure-handlebars/blindlyescaping.html
Reducing XSS by way of Automatic Context-Aware Escaping in Template Systemshttps://security.googleblog.com/2009/03/reducing-xss-by-way-of-automatic.html
section A3 of NodeGoat tutorialhttp://nodegoat.herokuapp.com/tutorial/a3
https://github.com/FoxCode2022/strong-node#29-for-ie-specific-output-escaping-is-applied-for-all-output-values
Helmethttps://github.com/helmetjs/helmet
"ienoopen" pluginhttps://github.com/helmetjs/ienoopen
route optionshttps://github.com/hapijs/hapi/blob/master/API.md#route-options
CWE-89http://cwe.mitre.org/data/definitions/89.html
https://github.com/FoxCode2022/strong-node#210-the-app-uses-parametrized-database-queries-if-a-sql-database-is-being-used-cwe-89
MySQLhttps://github.com/felixge/node-mysql#escaping-query-values
PostreSQLhttps://github.com/brianc/node-postgres
section A1 (section B) of NodeGoat tutorialhttp://nodegoat.herokuapp.com/tutorial/a3
CWE-77http://cwe.mitre.org/data/definitions/77.html
https://github.com/FoxCode2022/strong-node#211-the-strict-options-is-used-in-the-whole-code-to-apply-more-defenses-cwe-77
"strict"http://eslint.org/docs/rules/strict
https://github.com/FoxCode2022/strong-node#212-app-code-doesnt-use-eval-at-all-cwe-77
"no-eval"http://eslint.org/docs/rules/no-eval
"detect-eval-with-expression"https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js
https://github.com/FoxCode2022/strong-node#213-app-doesnt-use-any-method-which-leads-to-the-same-result-as-eval-using-user-inputs-cwe-77
"no-implied-eval"http://eslint.org/docs/rules/no-implied-eval
"childProcess"https://nodejs.org/api/child_process.html
https://github.com/FoxCode2022/strong-node#214-app-doesnt-use-any-method-of-the-childprocess-object-using-user-inputs-cwe-77
"detect-child-process"https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-child-process.js
"fs"https://nodejs.org/api/fs.html
https://github.com/FoxCode2022/strong-node#215-non-literals-are-not-allowed-in-any-method-of-the-fs-module-as-a-name-cwe-77
"detect-non-fs-filename"https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-non-fs-filename.js
https://github.com/FoxCode2022/strong-node#216-non-literals-are-not-allowed-in-any-require-cwe-77
"detect-non-literal-require"https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-non-literal-require.js
https://github.com/FoxCode2022/strong-node#217-non-literals-are-not-allowed-in-any-regular-expression-cwe-77
"detect-non-literal-regexp"https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-non-literal-regexp.js
CWE-352http://cwe.mitre.org/data/definitions/352.html
https://github.com/FoxCode2022/strong-node#218-protection-against-cross-site-request-forgery-csrf-is-enabled-cwe-352
section A8 of NodeGoat tutorialhttp://nodegoat.herokuapp.com/tutorial/a8
csurfhttps://github.com/expressjs/csurf
crumbhttps://github.com/hapijs/crumb
Content Security Policyhttps://www.w3.org/TR/CSP/
https://github.com/FoxCode2022/strong-node#219-the-content-security-policy-setup-is-correct-cwe-352
Helmethttps://github.com/helmetjs/helmet
"csp" pluginhttps://github.com/helmetjs/csp
blankiehttps://github.com/nlf/blankie
clickjackinghttps://en.wikipedia.org/wiki/Clickjacking
CWE-693http://cwe.mitre.org/data/definitions/693.html
https://github.com/FoxCode2022/strong-node#220-the-xframe-field-is-used-to-avoid-clickjacking-cwe-693
Helmethttps://github.com/helmetjs/helmet
"frameguard" pluginhttps://github.com/helmetjs/frameguard
route optionshttps://github.com/hapijs/hapi/blob/master/API.md#route-options
CWE-430http://cwe.mitre.org/data/definitions/430.html
https://github.com/FoxCode2022/strong-node#221-the-app-is-adding-headers-to-avoid-the-browsers-sniffing-mimetypes-cwe-430
CVE-2014-7939 Detailhttps://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7939*
Helmethttps://github.com/helmetjs/helmet
"nosniff" pluginhttps://github.com/helmetjs/nosniff
route optionshttps://github.com/hapijs/hapi/blob/master/API.md#route-options
CWE-434http://cwe.mitre.org/data/definitions/434.html
https://github.com/FoxCode2022/strong-node#222-all-uploaded-files-extension-is-checked-the-extension-to-be-among-the-supported-ones-cwe-434
"extname"https://nodejs.org/api/path.html#path_path_extname_p
CWE-22http://cwe.mitre.org/data/definitions/22.html
https://github.com/FoxCode2022/strong-node#223-all-unsafe-paths-names-are-restricted-to-a-root-dir-cwe-22
createWriteStream vulnerable to path traversal?https://github.com/nodejs/node-v0.x-archive/issues/6157#issuecomment-23618929
https://github.com/FoxCode2022/strong-node#3-auditing-and-logging
CWE-778http://cwe.mitre.org/data/definitions/778.html
https://github.com/FoxCode2022/strong-node#31-all-critical-errors-being-logged-at-any-level-of-debugging-cwe-778
https://github.com/FoxCode2022/strong-node#32-an-alert-is-generated-when-a-critical-error-happens
https://github.com/FoxCode2022/strong-node#33-different-levels-of-debugging-are-supported-cwe-778
https://github.com/FoxCode2022/strong-node#34-change-the-debug-level-without-restart-ie-using-environment-variables-cwe-778
https://github.com/FoxCode2022/strong-node#35-all-security-critical-events-are-being-logged-cwe-778
"debug"https://github.com/visionmedia/debug
used in Expresshttp://expressjs.com/es/guide/debugging.html
CWE-223http://cwe.mitre.org/data/definitions/223.html
https://github.com/FoxCode2022/strong-node#36-all-authentication-activities-successful-or-not-are-being-logged-at-any-level-of-debugging-cwe-223-cwe-778
https://github.com/FoxCode2022/strong-node#37-all-privilege-changes-successful-or-not-are-being-logged-at-any-level-of-debugging-cwe-223-cwe-778
https://github.com/FoxCode2022/strong-node#38-all-administrative-activities-successful-or-not-are-being-logged-at-any-level-of-debugging-cwe-223-cwe-778
https://github.com/FoxCode2022/strong-node#39-all-access-to-sensitive-data-are-being-logged-at-any-level-of-debugging-cwe-223-cwe-778
https://github.com/FoxCode2022/strong-node#310-an-alert-is-generated-when-a-critical-security-event-happens-ie-email-slack-etc-cwe-223-cwe-778
CWE-779http://cwe.mitre.org/data/definitions/779.html
https://github.com/FoxCode2022/strong-node#311-anomalous-conditions-can-be-easily-detected-through-the-logs-cwe-779
https://github.com/FoxCode2022/strong-node#312-all-errors-are-logged-at-the-same-level-cwe-779
"Logging v. instrumentation"http://peter.bourgon.org/blog/2016/02/07/logging-v-instrumentation.html
https://github.com/FoxCode2022/strong-node#313-an-user-entry-is-never-written-directly-to-the-logs
CWE-117http://cwe.mitre.org/data/definitions/117.html
https://github.com/FoxCode2022/strong-node#314-logs-never-change-the-app-behavior-cwe-117
https://github.com/FoxCode2022/strong-node#315-statistics-are-not-taken-from-the-logs-cwe-117
CWE-532http://cwe.mitre.org/data/definitions/532.html
CWE-215http://cwe.mitre.org/data/definitions/215.html
https://github.com/FoxCode2022/strong-node#316-logs-do-not-include-sensitive-info-about-users-or-environment-cwe-532-cwe-215
CWE-533http://cwe.mitre.org/data/definitions/533.html
https://github.com/FoxCode2022/strong-node#317-logs-location-is-secure-cwe-533
2-factor authenticationhttps://en.wikipedia.org/wiki/Two-factor_authentication
https://github.com/FoxCode2022/strong-node#4-cryptography
CWE-523http://cwe.mitre.org/data/definitions/523.html
CWE-311http://cwe.mitre.org/data/definitions/311.html
CWE-319http://cwe.mitre.org/data/definitions/319.html
https://github.com/FoxCode2022/strong-node#41-all-routes-which-transmit-sensitive-info-use-ssl-cwe-523-cwe-311-cwe-319
https://github.com/FoxCode2022/strong-node#42-http-access-is-disabled-for-all-routes-which-use-ssl-cwe-523-cwe-311-cwe-319
express-force-sslhttps://github.com/battlejj/express-force-ssl
hapi-require-httpshttps://github.com/bendrucker/hapi-require-https
Expedited SSLhttps://elements.heroku.com/addons/expeditedssl
https://www.youtube.com/watch?v=OcyR7Yus4pchttps://www.youtube.com/watch?v=OcyR7Yus4pc
RFC 6797https://tools.ietf.org/html/rfc6797
https://github.com/FoxCode2022/strong-node#43-the-server-only-allows-ssl-connections-rfc-6797
Helmethttps://github.com/helmetjs/helmet
"hsts" pluginhttps://github.com/helmetjs/hsts
route optionshttps://github.com/hapijs/hapi/blob/master/API.md#route-options
CWE-312http://cwe.mitre.org/data/definitions/312.html
https://github.com/FoxCode2022/strong-node#44-the-passwords-keys-or-certificates-are-not-stored-in-clear-files-cwe-312-cwe-319
https://github.com/FoxCode2022/strong-node#45-the-passwords-keys-or-certificates-are-not-stored-in-clear-in-the-db-cwe-312-cwe-319
GitRobhttps://github.com/michenriksen/gitrob
CWE-261http://cwe.mitre.org/data/definitions/261.html
CWE-257http://cwe.mitre.org/data/definitions/257.html
https://github.com/FoxCode2022/strong-node#46-passwords-keys-or-certificates-are-not-stored-in-a-recoverable-format-cwe-261-cwe-257
don't roll your own crypto!https://www.google.es/search?q=do+not+implement+your+own+crypto&oq=do+not+implement+your+own+crypto&aqs=chrome.0.69i59j69i64.2175j0j7&sourceid=chrome&ie=UTF-8#q=don%27t+roll+your+own+crypto
Passwordless middlewarehttps://passwordless.net/
CWE-309http://cwe.mitre.org/data/definitions/309.html
Passporthttp://passportjs.org/
Bellhttps://github.com/hapijs/bell
CWE-326http://cwe.mitre.org/data/definitions/326.html
https://github.com/FoxCode2022/strong-node#47-the-app-is-using-bcrypt-or-pbkdf2-or-based-library-to-store-the-passwords-securely-cwe-326
bcrypthttps://en.wikipedia.org/wiki/Bcrypt
pbkdf2https://en.wikipedia.org/wiki/PBKDF2
How To Safely Store A Passwordhttps://codahale.com/how-to-safely-store-a-password
CWE-327http://cwe.mitre.org/data/definitions/327.html
https://github.com/FoxCode2022/strong-node#48-the-app-is-using-secure-crypto-libraries-cwe-327
Node v0.12.12 (LTS) releasehttps://nodejs.org/en/blog/release/v0.12.12
TLS Node.js core modulehttps://nodejs.org/api/tls.html
TLS modulehttps://nodejs.org/api/tls.html#tls_tls_createserver_options_secureconnectionlistener
CWE-296http://cwe.mitre.org/data/definitions/296.html
CWE-295http://cwe.mitre.org/data/definitions/295.html
https://github.com/FoxCode2022/strong-node#49-the-app-certificate-respect-the-chain-of-trust-cwe-296-cwe-295
CWE-297http://cwe.mitre.org/data/definitions/297.html
CWE-322http://cwe.mitre.org/data/definitions/322.html
https://github.com/FoxCode2022/strong-node#410-the-app-certificate-match-with-the-host-cwe-297-cwe-295-cwe-322
CWE-298http://cwe.mitre.org/data/definitions/298.html
https://github.com/FoxCode2022/strong-node#411-the-app-certificate-has-a-valid-expiration-date-cwe-298-cwe-295
CWE-299http://cwe.mitre.org/data/definitions/299.html
https://github.com/FoxCode2022/strong-node#412-the-app-certificate-is-not-revoked-cwe-299-cwe-295
https://github.com/FoxCode2022/strong-node#413-all-the-points-of-this-section-are-checked-for-any-application-ssl-connections
TLS Node.js core modulehttps://nodejs.org/api/tls.html#tls_tls_connect_options_callback
"sslyze"https://github.com/iSECPartners/sslyze
Let's Encrythttps://letsencrypt.org/about/
letsencrypt-expresshttps://github.com/Daplie/letsencrypt-express
letsencrypt-hapihttps://github.com/Daplie/letsencrypt-hapi
https://github.com/FoxCode2022/strong-node#5-authentication-and-authorization
CWE-798http://cwe.mitre.org/data/definitions/798.html
https://github.com/FoxCode2022/strong-node#51-neither-passwords-nor-certificate-keys-are-hard-coded-or-in-separate-file-in-the-source-code-of-the-application-cwe-798
GitRobhttps://github.com/michenriksen/gitrob
environment/application variableshttps://devcenter.heroku.com/articles/config-vars
CWE-640http://cwe.mitre.org/data/definitions/640.html
https://github.com/FoxCode2022/strong-node#52-the-password-recovery-mechanism-is-strong-cwe-640
CWE-521http://cwe.mitre.org/data/definitions/521.html
https://github.com/FoxCode2022/strong-node#53-the-users-are-forced-to-enter-a-strong-password-cwe-521
some good moduleshttps://github.com/nowsecure/owasp-password-strength-test
CWE-262http://cwe.mitre.org/data/definitions/262.html
https://github.com/FoxCode2022/strong-node#54-the-users-are-forced-to-change-the-password-in-a-regular-basis-cwe-262
CWE-307http://cwe.mitre.org/data/definitions/307.html
https://github.com/FoxCode2022/strong-node#55-the-application-detects-and-blocks-any-possible-brute-force-attack-cwe-307
https://github.com/FoxCode2022/strong-node#56-the-block-expires-after-a-period-of-time-cwe-307
https://github.com/FoxCode2022/strong-node#57-the-application-support-a-blacklist-of-ip-address-to-block-cwe-307
https://github.com/FoxCode2022/strong-node#58-the-application-can-manually-block-an-ip-address-cwe-307
https://github.com/FoxCode2022/strong-node#59-the-application-can-manually-unblock-an-ip-address-cwe-307
https://github.com/FoxCode2022/strong-node#510-the-application-can-manually-block-a-country-cwe-307
https://github.com/FoxCode2022/strong-node#511-the-application-can-manually-unblock-a-country-cwe-307
node-ratelimiterhttps://github.com/tj/node-ratelimiter
node-geoiphttps://github.com/bluesmoon/node-geoip
multiple optionshttps://www.npmjs.com/browse/keyword/geolocation
node-ipgeoblockhttps://github.com/ilich/node-ipgeoblock
express-limiterhttps://github.com/ded/express-limiter
express-brutehttps://github.com/AdamPflug/express-brute
hapi-ratelimithttps://github.com/creativelive/hapi-ratelimit
https://gist.github.com/whisher/d6e3db7c11d632720133https://gist.github.com/whisher/d6e3db7c11d632720133
CWE-284http://cwe.mitre.org/data/definitions/284.html
https://github.com/FoxCode2022/strong-node#512-all-requests-came-through-an-authentication-middleware-cwe-284
CWE-272http://cwe.mitre.org/data/definitions/272.html
https://github.com/FoxCode2022/strong-node#513-all-new-requests-not-login-users-have-the-least-privilege-possible-cwe-272-cwe-284
https://github.com/FoxCode2022/strong-node#514-all-the-info-taken-in-account-for-authentication-is-taken-from-trusted-sources-cwe-284
section A4 of NodeGoat tutorialhttp://nodegoat.herokuapp.com/tutorial/a4
https://github.com/FoxCode2022/strong-node#515-the-app-doesnt-expose-actual-database-keys-as-part-of-the-access-links-cwe-284
Passporthttp://passportjs.org/
"shortid"https://github.com/dylang/shortid
section A7 of NodeGoat tutorialhttp://nodegoat.herokuapp.com/tutorial/a7
CWE-601http://cwe.mitre.org/data/definitions/601.html
https://github.com/FoxCode2022/strong-node#516-the-app-doesnt-use-url-redirection-cwe-601
https://github.com/FoxCode2022/strong-node#5161-if-url-redirection-is-used-it-doesnt-involve-user-parameters-to-calculate-the-destination
URL redirectionhttps://en.wikipedia.org/wiki/URL_redirection
section A10 of NodeGoat tutorialhttp://nodegoat.herokuapp.com/tutorial/a10
https://github.com/FoxCode2022/strong-node#6-session
CWE-6http://cwe.mitre.org/data/definitions/6.html
https://github.com/FoxCode2022/strong-node#61-the-method-to-generate-session-ids-is-strong-cwe-6
"uid-safe"https://github.com/crypto-utils/uid-safe
"express-session"https://github.com/expressjs/session#compatible-session-stores
"genid"https://github.com/expressjs/session#genid
server.cachehttp://hapijs.com/api#servercacheoptions
"hapi-auth-basic"https://github.com/hapijs/hapi-auth-basic
"hapi-auth-cookie"https://github.com/hapijs/hapi-auth-cookie
"yar"https://github.com/hapijs/yar
CWE-613http://cwe.mitre.org/data/definitions/613.html
https://github.com/FoxCode2022/strong-node#62-the-session-is-destroyed-on-every-user-logout-cwe-613
https://github.com/FoxCode2022/strong-node#63-the-session-is-destroyed-after-an-absolute-session-timeout-cwe-613
https://github.com/FoxCode2022/strong-node#64-the-session-is-destroyed-after-an-iddle-session-timeout-cwe-613
https://github.com/FoxCode2022/strong-node#65-in-all-cases-the-sessions-is-also-dropped-from-persistent-storage-ie-redis-cwe-613
to achieve it from the client-sidehttps://www.npmjs.com/search?q=idle
connect-redishttps://github.com/tj/connect-redis
"server.state"http://hapijs.com/api#serverstatename-options
"server.cache"http://hapijs.com/api#servercacheoptions
"express-session"https://github.com/expressjs/session#compatible-session-stores
"Session.Destroy"https://github.com/expressjs/session#sessiondestroy
"store.destroy"https://github.com/expressjs/session#storedestroysid-callback
catboxhttp://hapijs.com/tutorials/caching
CWE-384http://cwe.mitre.org/data/definitions/384.html
https://github.com/FoxCode2022/strong-node#66-the-server-generate-a-new-session-id-after-an-user-authentication-cwe-384
https://github.com/FoxCode2022/strong-node#67-the-server-generate-a-new-session-id-after-an-user-privilege-level-change-cwe-384
https://github.com/FoxCode2022/strong-node#68-the-server-generate-a-new-session-id-after-an-encryption-level-change-cwe-384
"regenerate"https://github.com/expressjs/session#sessionregenerate
https://github.com/FoxCode2022/strong-node#69-all-cookies-have-a-not-default-name
option "name"https://github.com/expressjs/session#cookie-options
"server.state"https://github.com/hapijs/hapi/blob/master/API.md#serverstatename-options
CWE-614http://cwe.mitre.org/data/definitions/614.html
https://github.com/FoxCode2022/strong-node#610-all-cookies-use-the-secure-flag-to-set-them-only-under-https-cwe-614
option "secure"https://github.com/expressjs/session#cookie-options
"server.state"https://github.com/hapijs/hapi/blob/master/API.md#serverstatename-options
CWE-79http://cwe.mitre.org/data/definitions/79.html
https://github.com/FoxCode2022/strong-node#611-all-cookies-use-the-httponly-flag-to-ensures-they-are-only-sent-over-https-not-client-javascript-cwe-79
option "httpOnly"https://github.com/expressjs/session#cookie
"server.state"https://github.com/hapijs/hapi/blob/master/API.md#serverstatename-options
CWE-565http://cwe.mitre.org/data/definitions/565.html
https://github.com/FoxCode2022/strong-node#612-all-cookies-are-signed-with-a-secret-cwe-565
option "secret"https://github.com/expressjs/session#secret
"server.state"https://github.com/hapijs/hapi/blob/master/API.md#serverstatename-options
https://github.com/FoxCode2022/strong-node#7-environment
CIhttps://en.wikipedia.org/wiki/Continuous_integration
CWE-439http://cwe.mitre.org/data/definitions/439.html
CWE-701http://cwe.mitre.org/data/definitions/701.html
CWE-656http://cwe.mitre.org/data/definitions/656.html
https://github.com/FoxCode2022/strong-node#71-the-app-has-a-ci-system-cwe-439-cwe-701-cwe-656
Travishttps://docs.travis-ci.com/user/getting-started/
Heroku's GitHub integrationhttps://devcenter.heroku.com/articles/github-integration#automatic-deploys
https://github.com/FoxCode2022/strong-node#72-the-coverage-for-the-tests-is-enough
Istanbulhttps://github.com/gotwarlost/istanbul
https://github.com/FoxCode2022/strong-node#73-check-for-dependencies-with-known-vulnerabilities-is-included-in-the-ci
audit-cihttps://github.com/IBM/audit-ci
auditjshttps://github.com/OSSIndex/auditjs
https://github.com/FoxCode2022/strong-node#74-check-for-non-updated-dependencies-is-included-in-the-ci
"npm-check-updates"https://github.com/nodesecurity/npm-check-updates
CWE-185https://cwe.mitre.org/data/definitions/185.html
https://github.com/FoxCode2022/strong-node#75-check-for-insecure-regular-expressions-is-included-in-the-ci-cwe-185
"detect-unsafe-regex"https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-unsafe-regex.js
Semantic versioninghttp://semver.org/
https://github.com/FoxCode2022/strong-node#76-semantic-versioning-is-used-correctly
"package.json"https://docs.npmjs.com/files/package.json
https://nodesource.com/blog/semver-tilde-and-carethttps://nodesource.com/blog/semver-tilde-and-caret
https://github.com/FoxCode2022/strong-node#77-dependency-versions-are-blocked-in-production-to-avoid-surprises
"npm shrinkwrap"https://docs.npmjs.com/cli/shrinkwrap
VU#319816https://www.kb.cert.org/vuls/id/319816
https://github.com/FoxCode2022/strong-node#78-theres-a-npm-task-to-install-dependencies-ignoring-the-scripts-vu319816
Package install scripts vulnerabilityhttp://blog.npmjs.org/post/141702881055/package-install-scripts-vulnerability
https://github.com/FoxCode2022/strong-node#79-the-user-inputs-are-fuzzed-in-a-regular-basis
Surkuhttps://github.com/attekett/Surku
ZAPhttps://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
Node.js bindingshttps://github.com/zaproxy/zaproxy/tree/develop/nodejs/api/zapv2
CWE-15http://cwe.mitre.org/data/definitions/15.html
CWE-656http://cwe.mitre.org/data/definitions/656.html
https://github.com/FoxCode2022/strong-node#710-the-whole-infrastructure-is-secured-cwe-15-cwe-656
Lynishttps://cisofy.com/lynis/
CWE-250http://cwe.mitre.org/data/definitions/250.html
https://github.com/FoxCode2022/strong-node#711-application-with-minimal-privileges-cwe-250
https://github.com/FoxCode2022/strong-node#712-the-team-in-educated-on-security
https://groups.google.com/forum/#!forum/nodejs-sechttps://groups.google.com/forum/#!forum/nodejs-sec
https://github.com/FoxCode2022/strong-node#713-the-team-doesnt-use-company-devices-for-personal-stuff
https://github.com/FoxCode2022/strong-node#714-the-app-respect-some-written-security-requirements
https://github.com/FoxCode2022/strong-node#715-the-application-has-an-incident-plan
https://github.com/FoxCode2022/strong-node#716-a-design-review-is-performed-in-a-regular-basis
keep it simplehttps://en.wikipedia.org/wiki/KISS_principle
CWE-702http://cwe.mitre.org/data/definitions/702.html
https://github.com/FoxCode2022/strong-node#717-a-security-code-audit-is-performed-regular-basis-internal-and-external-cwe-702
https://github.com/FoxCode2022/strong-node#718-a-web-specific-penetration-test-is-performed-in-a-regular-basis-internal-and-external
OWASP Testing guidehttps://www.owasp.org/images/5/52/OWASP_Testing_Guide_v4.pdf
ZAPhttps://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
sqlmaphttp://sqlmap.org/
Skipfishhttps://github.com/spinkham/skipfish
w3afhttp://w3af.org/
Niktohttps://www.cirt.net/Nikto2
https://github.com/FoxCode2022/strong-node#license
http://creativecommons.org/licenses/by/4.0
Creative Commons Attribution 4.0 International Licensehttp://creativecommons.org/licenses/by/4.0
Readme https://github.com/FoxCode2022/strong-node#readme-ov-file
Please reload this pagehttps://github.com/FoxCode2022/strong-node
Activityhttps://github.com/FoxCode2022/strong-node/activity
0 forkshttps://github.com/FoxCode2022/strong-node/forks
Report repository https://github.com/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2FFoxCode2022%2Fstrong-node&report=FoxCode2022+%28user%29
Releaseshttps://github.com/FoxCode2022/strong-node/releases
Packages 0https://github.com/users/FoxCode2022/packages?repo_name=strong-node
Please reload this pagehttps://github.com/FoxCode2022/strong-node
Contributorshttps://github.com/FoxCode2022/strong-node/graphs/contributors
Please reload this pagehttps://github.com/FoxCode2022/strong-node
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.