Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Could browser javascript harm my backend server?

I'm coding an application where I want to let the user learn javascript in this way:

  1. The user write javascript code on the browser like in an IDE.
  2. The user saves it and the code will be saved as a string in my backend No-SQL database (MongoDB/CouchDB).
  3. The user opens the application some days later and I pass that string to the web browser where the code will be executed with eval().

There will be only JSON data transferred between backend server and web browser. The server won't do anything on the code string, it will only save it directly into the database.

Could this code possibly do any damage on the server side?

like image 296
never_had_a_name Avatar asked Sep 30 '26 03:09

never_had_a_name


2 Answers

On the server-side, no. Unless the scripts runs on IE and create multiple files disk. Or make some request to your system inserting billions of new entries...

So you have to take care with requests (flood control), be careful with IE and be careful with SQL injections.

Examples

  • Creating file in IE
  • SQL Injection

And the request I'm talking about could be something like:

ajax.post("page_save_js.ext", "code=flood");

Then each time it runs it will insert a new code, flooding the server. StackOverflow controls this flood using captcha after some requests in a short amount of time.

like image 124
BrunoLM Avatar answered Oct 01 '26 15:10

BrunoLM


No harm can come from this if its just stored as a string in the DB.

Its really no different than storing any other string. Its just data at that point.

like image 38
Jonathan S. Avatar answered Oct 01 '26 15:10

Jonathan S.