Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites
Zifeng Kang, Song Li, Yinzhi Cao
2022年份
24顶会引用
摘要
zero-day, exploitable prototype pollution vulnerabilities. We verify that 48 vulnerabilities further lead to XSS, 736 to cookie manipulations, and 830 to URL manipulations. We reported all the findings to website maintainers and so far 185 vulnerable websites have already been patched.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious ConsequencesZhengyu Liu, Kecheng An, Yinzhi CaoS&P 2024 · 被引用 17 次
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang 等OOPSLA 2025 · 被引用 9 次
- Unveiling the Invisible: Detection and Evaluation of Prototype Pollution Gadgets with Dynamic Taint AnalysisMikhail Shcherbakov, Paul Moosbrugger, Musard BalliuWWW 2024 · 被引用 8 次
- To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security LandscapeJannis Rautenstrauch, Metodi Mitkov, Thomas Helbrecht, Lorenz Hetterich 等S&P 2024 · 被引用 6 次
- GHunter: Universal Prototype Pollution Gadgets in JavaScript RuntimesEric Cornelissen, Mikhail Shcherbakov, Musard BalliuUSENIX Security 2024 · 被引用 5 次
它引用的顶会 Paper12
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 被引用 273 次
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits 等S&P 2020 · 被引用 112 次
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 被引用 84 次
相关 Paper
- Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World WebsitesZifeng Kang, Muxi Lyu, Zhengyu Liu, Jianjia Yu 等S&P 2025
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 被引用 49 次
- Bullseye: Detecting Prototype Pollution in NPM Packages with Proof of Concept ExploitsTariq Houis, Shaoqi Jiang, Mohammad Mannan, Amr YoussefNDSS 2026 · 被引用 2 次
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.jsMikhail Shcherbakov, Musard Balliu, Cristian-Alexandru StaicuUSENIX Security 2023
- The First Large-Scale Systematic Study of Python Class Pollution VulnerabilityZhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu 等S&P 2026
