LAB 223 - Defending Node.js Applications Against SQL Injection


Course Overview

This lab simulates an Injection vulnerability found in the Gold Standard Cyber Range. The challenge includes a Web App developed in Node.js that fails to implement the security principle of “Establish Secure Defaults”.

Using Visual Studio Code, participants will analyze code to identify and mitigate instances of “Failure to validate input and improper use of user input in SQL statements”. The objective of this lab is to find the vulnerable code and fix the weakness.

Upon completion of this lab participants will:

  • Apply strategic principles to keep Node.js applications safe
  • Demonstrate the skills needed to discover and exploit SQL Injection attacks
  • Fix a vulnerable SQL query in Node.js

Looking To Learn More?

Request more information on our courses and labs.

Course Details

Course Number: LAB 223

Course Duration: 10 minutes

Course CPE Credits: 0.25

Platform

Standard

Technology

Type

Foreign Languages Available:

  • English