Collected research
Abusing Hidden Properties to Attack the Node.js Ecosystem
Hidden property abusing exploits the gap between how client-supplied objects are serialised and how server code reads them, letting a remote attacker inject internal object properties the developer never meant to expose.
Record
- Researcher
- Feng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang, Hong Hu, Guofei Gu and Wenke Lee
- Published by
- usenix.org
- Topic
- Server
In the archive
Related sources
- Discovering Hidden Properties to Attack the Node.js Ecosystem
- DEF CON Safe Mode - Feng Xiao - Discovering Hidden Properties to Attack Node js Ecosystem
- USENIX Security '21 - Abusing Hidden Properties to Attack the Node.js Ecosystem
Tags
This page is the archive's own catalogue record. The research is the work of Feng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang, Hong Hu, Guofei Gu and Wenke Lee, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .