You are helping a penetration tester exploit misconfigured Active Directory
日本語の概要は準備中です。原文の説明を表示しています。
Detect method clobbering via user-controlled object keys that overwrite built-in methods like toString, valueOf, or hasOwnProperty, causing crashes or logic bypass.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Audit CSV/form/query string parsers that create plain objects from untrusted input where the attacker can control property names (keys), not just values.
When a parser creates a plain object {} from user input, the attacker can set keys like toString, valueOf, hasOwnProperty to non-function values. Any code that later calls these methods on the object will throw a TypeError.
Important: JSON.parse can do the same thing. You MUST show why the library-specific clobbering is worse than what JSON.parse enables. Show a REAL crash path, not just theoretical property overwrite.
| Key | Normal Type | Effect When Clobbered |
|---|---|---|
toString | Function | obj + "" throws TypeError |
valueOf | Function | obj == x or coercion throws TypeError |
hasOwnProperty | Function | obj.hasOwnProperty(k) throws TypeError |
constructor | Function | Type checks fail |
__proto__ | Object | Prototype pollution (see prototype-pollution skill) |
__defineGetter__ | Function | Legacy getter/setter manipulation |
__defineSetter__ | Function | Legacy getter/setter manipulation |
__lookupGetter__ | Function | Legacy getter/setter introspection |
toJSON | undefined | JSON.stringify(obj) throws TypeError |
then | undefined | await obj or Promise.resolve(obj) treats obj as thenable |
grep -rn "\[key\]\s*=" . --include="*.js" --include="*.ts"
grep -rn "\[header\]\|\[field\]\|\[name\]\|\[prop\]" .
grep -rn "result\[\|output\[\|obj\[\|data\[\|parsed\[" .
Common sources of attacker-controlled keys:
grep -rn "Object\.create(null)" . # Null prototype = safe
grep -rn "hasOwnProperty\|toString\|valueOf" . | grep -i "filter\|block\|skip"
grep -rn "Object\.keys\|Map\|new Map" .
You MUST show one of:
obj.toString() or obj.hasOwnProperty() on the parsed resultobj.hasOwnProperty(x) for security decisionsawait or Promise.resolve() on the parsed object# Find code that calls methods on parsed objects
grep -rn "\.toString()\|\.valueOf()\|\.hasOwnProperty(" .
grep -rn "JSON\.stringify(" . # Uses toJSON
grep -rn "await\|Promise\.resolve" . # Uses then
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
You are helping a penetration tester exploit misconfigured Active Directory
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester enumerate an Active Directory domain and
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester establish persistent access in Active
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester exploit ADCS through template/CA access
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester establish persistence through AD CS
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester exploit misconfigured AD CS certificate
日本語の概要は準備中です。原文の説明を表示しています。