{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 38 - Web Security Known Web Attacks | Episode 2: RCE Filter Bypassing and JSON Hijacking","slug":"course-38-web-security-known-web-attacks-episode-2-rce-filter-bypassing-and-json-hijacking","published_at":"2026-07-03T06:00:03+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-38-web-security-known-web-attacks-episode-2-rce-filter-bypassing-and-json-hijacking","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-38-web-security-known-web-attacks-episode-2-rce-filter-bypassing-and-json-hijacking--72711319","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72711319/bypassing_filters_and_hijacking_json_data.mp3","summary":"In this lesson, you’ll learn about: bypassing weak RCE filters and understanding JSON hijacking (legacy browser vulnerability)1. Why RCE Filters Fail🔹 Common mistake: Developers block specific characters (like ;) 🔹 Problem: Attack surface is much larger than one delimiter 👉 Key Insight Blacklisting single characters is not real security2. Alternative Command Operators🔹 Even if ; is blocked, others exist: &amp;&amp; → execute if first succeeds || → execute if first fails | → pipe output &amp; → background execution 👉 Key Insight There are multiple ways to chain commands, not just one3. Encoding to Bypass Filters🔹 Web applications often filter raw characters🔹 Bypass technique: Use URL encoding 🔹 Example: &amp;&amp; → %26%26 👉 Key Insight Filters that don’t normalize input can be bypassed easily4. Logic-Based Exploitation🔹 Operator behavior matters: &amp;&amp; → requires success || → requires failure 🔹 Attacker strategy: Force first command to fail → trigger second 👉 Key Insight Exploitation is about logic control, not just syntax5. Core Defense Principle🔹 Problem: Input filtering ≠ protection 🔹 Real solution: Never pass user input to system commands 👉 Key Insight Eliminate the sink, not just sanitize input6. What is JSON Hijacking🔹 Definition: A client-side data theft attack exploiting browser behavior 🔹 Related concept: Similar to Cross-Site Request Forgery (CSRF) 👉 Key Insight It abuses authenticated requests + weak browser protections7. How JSON Hijacking Works (Conceptually)🔹 Key idea: 🔹 Attack flow: Victim is logged in Attacker loads sensitive API via Browser sends cookies automatically Data is exposed to attacker-controlled logic 👉 Key Insight Same-Origin Policy historically did not fully protect script loading8. The Role of JavaScript InternalsUsing JavaScript:🔹 T…","meta_description":"In this lesson, you’ll learn about: bypassing weak RCE filters and understanding JSON hijacking (legacy browser vulnerability)1. Why RCE Filters Fail🔹 Com…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1417,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-38-web-security-known-web-attacks-episode-2-rce-filter-bypassing-and-json-hijacking/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-38-web-security-known-web-attacks-episode-2-rce-filter-bypassing-and-json-hijacking.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}