Web Hack List

Collected research

SYNODE: Understanding and Automatically Preventing Injection Attacks on Node.js

A study of 235,850 npm modules shows exec and eval sinks are widespread and almost never sanitised, so attacker-controlled strings reach the shell or the JavaScript engine and run arbitrary commands. Synode statically infers a string template per sink and rewrites the module so a runtime value is rejected unless it merely fills the template's holes with safe literal nodes.

Record

Researcher
Cristian-Alexandru Staicu, Michael Pradel and Benjamin Livshits
Published by
software-lab.org
Format
Whitepaper
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Cristian-Alexandru Staicu, Michael Pradel and Benjamin Livshits, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .