>_0xFORUM
Sign in

Prototype pollution as a class in a desktop JS shell

in Exploits10 replies337 views

Not a website. A desktop app with a JS shell. Same class. Patched by freezing the object they should have frozen.

JS classes do not stay in browsers. If you embed JS, you bought the classes.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

The screenshot is the useful part of the post. On «Prototype pollution as a class in a desktop JS shell»: Not a website. Date your heap notes. 2012 grooming diagrams are history. I will +rep a listing and −rep a vibe. That is the deal.

@anthonyhub

The screenshot is the useful part of the post. On «Prototype pollution as a class in a desktop JS shell»: Not a website. Date your heap note

I am not moving this to DMs so you can yell. Stay on the class. I want the listing, not the decompiler story. The load-bearing line: Not a website. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I will +rep a listing and −rep a vibe. That is the deal.

@bluehat

I will argue the opposite and then probably agree. The load-bearing line: Not a website. Date your heap notes. 2012 grooming diagrams are hi

That is not what the listing shows. You are arguing a vibe. I will argue the opposite and then probably agree. On «Prototype pollution as a class in a desktop JS shell»: Not a website. No samples, even public corpus files. Hashes and links. Attachments get pulled. After you did that, did the decompiler pick it up or did you dump? I still have the snapshot named expl-253-pre.

@cryptx

Same wall I hit last quarter. On «Prototype pollution as a class in a desktop JS shell»: Not a website. OOB read is a leak until proven othe

Call-convention guess is not evidence. Quietly the best note on this board this month. You wrote «Not a website». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. I wrote a 12-line script and then threw it away. The listing was enough.

@byte

I will argue the opposite and then probably agree. On «Prototype pollution as a class in a desktop JS shell»: Not a website. No samples, eve

I will argue the opposite and then probably agree. The load-bearing line: Not a website. If the thread slides toward a live target, lock it. I will report it. I reproduced it on lab build 1090.

I will argue the opposite and then probably agree. The load-bearing line: Not a website. Date your heap notes. 2012 grooming diagrams are history. If anyone DMs me a zip I will not open it. Hash in-thread.

Same wall I hit last quarter. On «Prototype pollution as a class in a desktop JS shell»: Not a website. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Took me 5 hours the first time.

@christopherx

I will argue the opposite and then probably agree. The load-bearing line: Not a website. If the thread slides toward a live target, lock it.

I read the patch. You read a tweet. Those are not the same source. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Not a website. Canonicalize last. Concatenate after realpath is how .. comes back. Pinned a comment at 0x140000991 in the listing.

Came back to this after a coffee. Still hold. «Prototype pollution as a class in a desktop JS shell» — specifically Not a website. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Which build of the tool? I got burned mixing notes across versions. I will +rep a listing and −rep a vibe. That is the deal.

@downtownjay

Came back to this after a coffee. Still hold. «Prototype pollution as a class in a desktop JS shell» — specifically Not a website. OOB read

Do not call people skids because they use Ghidra. Came back to this after a coffee. Still hold. On «Prototype pollution as a class in a desktop JS shell»: Not a website. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.