Web Hack List

Later archive addition

SYNODE: Understanding and Automatically Preventing Injection Attacks on Node.js

A study of 235,850 npm modules shows exec and eval sinks are widespread and almost never sanitised, so attacker-controlled strings reach the shell or the JavaScript engine and run arbitrary commands. Synode statically infers a string template per sink and rewrites the module so a runtime value is rejected unless it merely fills the template's holes with safe literal nodes.

Record

Researcher
Cristian-Alexandru Staicu, Michael Pradel and Benjamin Livshits
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Cristian-Alexandru Staicu, Michael Pradel and Benjamin Livshits, first published at the original source. Preserved copies are kept so the citation survives its host.