Collected research
plORMbing your Prisma ORM with Time-based Attacks
In Prisma a controlled where clause picks field and operator, and nested some objects loop a many-to-many back on itself to reach users and unpublished rows the endpoint never exposes. With no visible response difference, the payload puts the negated leak filter first in an OR with a thousand contains terms: PostgreSQL flattens the OR and stops at the first true term, so a matching character costs about 400 ms. plormber decides each character by paired concurrent requests and t-tests.
Record
- Researcher
- Alex Brown
- Published by
- elttam.com
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Alex Brown, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .