Web Hack List

Top 10 winner

GitHub - HoLyVieR/prototype-pollution-nsec18: Content released at NorthSec 2018 for my talk on prototype pollution

Release material for the NorthSec 2018 talk that turned prototype pollution from a bad practice into an attack: APIs that recursively merge, clone or assign attacker-controlled key paths can write onto the base object prototype, so every object in the application inherits attacker-chosen properties and behaviour changes across the whole program.

Record

Researcher
HoLyVieR
Published by
GitHub
Format
Repository
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of HoLyVieR, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .