{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 39 - NodeJS Security Pentesting and Exploitation | Episode 4: Manual and Automated Code Review Essentials","slug":"course-39-nodejs-security-pentesting-and-exploitation-episode-4-manual-and-automated-code-review-essentials","published_at":"2026-07-10T06:00:02+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-39-nodejs-security-pentesting-and-exploitation-episode-4-manual-and-automated-code-review-essentials","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-39-nodejs-security-pentesting-and-exploitation-episode-4-manual-and-automated-code-review-essentials--72712051","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72712051/hardening_node.mp3","summary":"In this lesson, you’ll learn about: auditing Node.js applications using manual code review techniques and automated static analysis tools to identify security vulnerabilities1. What is Node.js Application Auditing?🔹 Purpose: Systematically review a Node.js codebase to find security weaknesses before attackers do🔹 Two main approaches: Manual code review Automated static analysis 👉 Key idea Real security comes from combining both approaches2. Manual Code Review Strategy🔹 Focus areas during review:🔹 File and database operations Look for unsafe reads/writes Check uncontrolled file paths 🔹 Cryptography usage Weak hashing (e.g., MD5) Disabled SSL verification Improper encryption handling 🔹 User input trackingFollow input from: request → processing → database → response👉 Key Insight Most vulnerabilities appear where input is not properly encoded or escaped🔹 Common resulting vulnerabilities: SQL Injection Cross-Site Scripting (XSS) Remote Code Execution (RCE) 🔹 Reference knowledge base: OWASP Code Review Guide 3. Automated Static Analysis (NodeJsScan)🔹 Tool: NodeJsScan🔹 What it does:Scans code without running it to detect security issues🔹 Key detection capabilities:1. Dangerous functions eval() OS command execution functions 👉 Flags potential RCE paths2. Security misconfigurations Missing CSP headers Missing HSTS Missing X-Frame-Options 3. Dependency vulnerabilities Uses Retire.js Detects outdated or vulnerable libraries 4. Custom rule support Add regex/string patterns Configure rules in rules.xml 4. Practical Workflow ExampleUsing vulnerable apps like NodeGoat: Tool scans entire codebase Flags vulnerable lines Shows file + exact line number Speeds up remediation process 5. Big PictureSecurity auditing is about:Manual review → deep understanding Static analysis → fast detectio…","meta_description":"In this lesson, you’ll learn about: auditing Node.js applications using manual code review techniques and automated static analysis tools to identify secu…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1479,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-39-nodejs-security-pentesting-and-exploitation-episode-4-manual-and-automated-code-review-essentials/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-39-nodejs-security-pentesting-and-exploitation-episode-4-manual-and-automated-code-review-essentials.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}