Collected research
Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites
ProbeTheProto instruments a browser to follow joint taint flows, where a property lookup and an assignment meet on a prototype object, then generates inputs that drive a polluted property into a sink. A scan of one million sites found 2,738 vulnerable, with pollution reaching XSS, cookie manipulation and URL manipulation.
Record
- Researcher
- Zifeng Kang, Song Li and Yinzhi Cao
- Published by
- NDSS Symposium
- Topic
- Injection
In the archive
Related sources
- NDSS 2022 Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Mill...
- NDSS 2022 Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Mill...
Tags
This page is the archive's own catalogue record. The research is the work of Zifeng Kang, Song Li and Yinzhi Cao, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .