This is the second & last part of the JavaScript prototype pollution series.
First part of the series: • JavaScript Prototype Pollution - Part 1
This video covers a refresher on the last video, Demo vulnerable example application using Lodash merge function (CVE-2018-16487), and the fix bypass (CVE-2019-10744). Debugging the NodeJS application and looking at the prototype chain.
0:00 Intro
0:21 Prototype Pollution Summary
1:59 Understanding Merge Function
4:40 JSON.parse() quirk
5:40 Demo vulnerable app
6:08 Walking through the code
8:05 HTTP Requests in the application
10:49 Polluting the prototype
12:09 Debugging the code
14:45 Lodash fix and the fix bypass
15:15 Outro
Vulnerable demo app - https://github.com/Kirill89/prototype....
Stok's channel- / @stokfredrik
Video by:
Rahul Maini - / iamnoooob (Presenter)
Harsh Jaiswal - / rootxharsh
Music/Track:
Disfigure - Blank [NCS Release]
• Disfigure - Blank | Melodic Dubstep | NCS ...
On this page of the site you can watch the video online JavaScript Prototype Pollution - Part 2 with a duration of hours minute second in good quality, which was uploaded by the user [HTTPVoid] 18 September 2020, share the link with friends and acquaintances, this video has already been watched 4,629 times on youtube and it was liked by 178 viewers. Enjoy your viewing!