Code Monkey home page Code Monkey logo

javascript-iast-sample's Introduction

IAST-Sample

This is a sample app with a Server Side Request Forgery vulnerability for use in an IAST demo lab environment.

This requires NodeJS. Most versions should work. It was tested with NodeJS 20.9.0.

To run:

  1. Clone the repo into a directory.
  2. Change into that directory and run npm install
  3. Run the app with node iast-sample.js.

The app will listen on port 8081. Use your favorite browser to go to localhost:8081. You should see a message Nodetron is in good health.

Then go to localhost:8081/about. That should post some content from example.com.

Now install New Relic's APM agent for NodeJS, enable IAST, and configure it to talk to an account with IAST enabled. Then repeat the above and see how fuzz testing happens and an SSRF is found.

javascript-iast-sample's People

Contributors

alecisaacson avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.