World Congress 2023 Sep 27, 2023

Hack-Proof The Node.js runtime: The Mechanics and Defense of Path Traversal Attacks

Sonya Moisset

Are attackers using basic directory escapes to bypass your filters and steal SSH keys? Discover the exact Node.js API sequence needed to permanently neutralize path traversal attacks.

Pause
Mute Enter Fullscreen
#1 about 4 min

Defining and executing a basic path traversal attack

How directory traversal exploits insecure coding workflows to expose unauthorized files through untracked user inputs.

#2 about 2 min

Recognizing the systemic impacts of path traversal attacks

Why directory traversal enables severe consequences like sensitive information exposure and deep vulnerability chaining.

#3 about 3 min

Examining real-world zero-day exploits in enterprise applications

How high-profile vulnerabilities in server infrastructure expose sensitive credentials and source code directories.

#4 about 1 min

Working securely with Node.js path application programming interfaces

Understanding the native functions responsible for concatenating, resolving, and sanitizing local directory paths.

#5 about 7 min

Bypassing incomplete validation filters using malicious URL encoding

How attackers exploit percent-encoding to bypass incomplete path validation logic across static file servers.

#6 about 6 min

Exploiting path traversal vulnerabilities in code editor extensions

How compromised local development integrations grant unauthorized external access to personal system configurations and credentials.

#7 about 4 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Leveraging offensive security payloads to automatically discover missing sanitization logic during application framework execution.

#8 about 4 min

Mitigating vulnerabilities with automated scanning and secure practices

Implementing automated static application testing within local editor environments to continuously prevent directory traversal injections.

Matching moments

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:44 min

Evaluating framework architectures against cross-site scripting attack vectors

Philippe De Ryck · LIVE

2:12 min

Analyzing real-world structural vulnerabilities in popular npm dependency packages

Liran Tal Liran Tal · WWC 2025

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · WWC Europe 2026

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

5:13 min

Identifying sophisticated supply chain attacks and simulated software vulnerabilities

Mohamed Shiralizadeh · Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali