Later archive addition
Abusing Hidden Properties to Attack the Node.js Ecosystem
Hidden property abusing exploits the gap between how client-supplied objects are serialised and how server code reads them, letting a remote attacker inject internal object properties the developer never meant to expose.
Record
- Researcher
- Feng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang, Hong Hu, Guofei Gu and Wenke Lee
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Feng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang, Hong Hu, Guofei Gu and Wenke Lee, first published at the original source. Preserved copies are kept so the citation survives its host.