Discovering Hidden Properties to Attack NodeJS Ecosystem
is widely used for developing both server-side and desktop applications. It provides a cross-platform execution environment for JavaScript programs. Due to the increasing popularity, the security of is critical to web servers and desktop clients.
We present a novel attack method against the platform, called hidden property abusing (HPA). The new attack leverages the widely-used data exchanging feature of JavaScript to tamper critical program states of programs, like server-side applications. HPA entitles remote attackers to launch serious attacks, such as stealing confidential data, bypassing security checks, and launching denial of service attacks. To help developers detect the HPA issues of their applications, we develop a tool, named LYNX, that utilizes hybrid program analysis to automatically reveal HPA vulnerabilities and even synthesize exploits. We apply LYNX on a set of widely-used programs and identify 13 previously unknown vulnerabilities. LYNX
1 view
9
1
6 days ago 00:19:59 42
Russia in 4K - Incredible Scenes & Hidden Gems
3 weeks ago 00:00:36 1
Top 3 Shocking Human Reflexes You Didn’t Know Existed
1 month ago 00:36:34 1
We SHIFTED Timelines in 1999: Y2K & CIA’s Secret Time Manipulation Program Exposed!
2 months ago 00:01:13 3
Star Wars Outlaws: A Pirate’s Fortune | Story Pack #2 Reveal Trailer
2 months ago 00:04:35 2
Thunderbolts* Trailer Spoof - TOON SANDWICH
2 months ago 00:03:26 0
Maremma and the Etruscan surroundings | Cinematic 4k Drone Video
3 months ago 00:02:00 0
Everest Base Camp Trek: Ultimate Guide to Reaching the World’s Most Famous Base Camp
3 months ago 00:10:08 2
MONACO’S BILLIONAIRES SECRETS EXPOSED!
3 months ago 01:29:41 1
Ancient DNA Reveals Hidden Migrations: Uncovering the Secrets of Human Evolution & Expansion
3 months ago 00:06:10 0
Who Dem Guyz? - We Can Make It (Eddie Flashin Folkes) 1994 Promo Only
3 months ago 00:10:10 0
Who Dem Guyz? - We Can Make It (Bump UK Club Mix) 1994 Promo Only
4 months ago 00:08:00 16
Dream Theater - Midnight Messiah (Official Video)
4 months ago 00:02:16 0
The End of The Sun - Official Release Date Trailer | A Slavic Mythology Adventure Game
5 months ago 00:35:42 0
Journey to the Center of the Earth (It Took 8 Days, I Lost 10kg)