Prototype Pollution Leads to RCE: Gadgets Everywhere

  Рет қаралды 3,640

Black Hat

Black Hat

Күн бұрын

Many have heard about Prototype Pollution vulnerabilities in JavaScript applications. This kind of vulnerability allows an attacker to inject properties into an object's root prototype that may lead to flow control alteration and unexpected program behavior. Every time a successful exploit looks like magic or is limited to a denial of service (DoS). Would you be surprised if I told you that every application has a chain of methods that can be triggered by Prototype Pollution and leads to arbitrary code execution? Such gadgets populated Node.js core code and popular NPM packages. Keep calm. Not every app can be exploited! However, this fact increases the risk of exploitation many times over.
In our research, we studied Prototype Pollution beyond DoS and analyzed Node.js source code against the gadgets.....
By: Mikhail Shcherbakov
Full Abstract and Presentation Materials:
www.blackhat.c...

Пікірлер
Миллионер | 3 - серия
36:09
Million Show
Рет қаралды 2,2 МЛН
How To Choose Mac N Cheese Date Night.. 🧀
00:58
Jojo Sim
Рет қаралды 109 МЛН
Long Nails 💅🏻 #shorts
00:50
Mr DegrEE
Рет қаралды 19 МЛН
Симбу закрыли дома?! 🔒 #симба #симбочка #арти
00:41
Симбочка Пимпочка
Рет қаралды 6 МЛН
SnykCon CTF - "Invisible Ink" Prototype Pollution
12:57
John Hammond
Рет қаралды 30 М.
malicious javascript injected into 100,000 websites
12:28
Low Level
Рет қаралды 215 М.
Prototype Pollution for Beginners
12:40
The Cyber Mentor
Рет қаралды 4,7 М.
Prototype Pollution | Applied Review #28
24:26
Hacking With Gabe
Рет қаралды 98
Understanding Prototype Pollution w/ Isaac Burton
45:04
Black Hills Information Security
Рет қаралды 908
one wrong npm package
19:27
PwnFunction
Рет қаралды 183 М.
Миллионер | 3 - серия
36:09
Million Show
Рет қаралды 2,2 МЛН