You are helping a penetration tester exploit misconfigured Active Directory
日本語の概要は準備中です。原文の説明を表示しています。
Detect prototype pollution via object merge/clone/assign operations where __proto__ or constructor.prototype keys can modify Object.prototype.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Audit merge/clone/deep-assign utilities, query string parsers, JSON parsers, config mergers, and any package that recursively sets object properties from untrusted input.
Key insight: Only ~50% acceptance rate. Must demonstrate REAL impact beyond just polluting prototype.
grep -rn "Object\.assign\|Object\.defineProperty\|Object\.create" .
grep -rn "merge\|extend\|deepMerge\|deepExtend\|deepAssign\|mixin" .
grep -rn "clone\|deepClone\|cloneDeep\|deepCopy" .
grep -rn "set\|setPath\|setValue\|lodash\.set\|_.set" .
grep -rn "\[.*\]\s*=" . --include="*.js" # Bracket notation assignment
Look for patterns where object keys from user input are used as property paths:
// VULNERABLE: recursive merge without key filtering
function merge(target, source) {
for (const key in source) {
if (typeof source[key] === 'object') {
target[key] = merge(target[key] || {}, source[key]);
} else {
target[key] = source[key];
}
}
}
grep -rn "__proto__\|constructor\|prototype" . | grep -i "filter\|block\|skip\|ignore\|reject"
grep -rn "Object\.create(null)" . # Null prototype objects are safe
grep -rn "hasOwnProperty\|Object\.keys\|Object\.entries" .
Prototype pollution alone is often not enough. Look for impact:
| Key | Effect | Impact |
|---|---|---|
__proto__ | Sets properties on Object.prototype | All objects affected |
constructor.prototype | Same effect via constructor chain | All objects affected |
constructor | Overwrites constructor reference | Type confusion |
toString | Overwrites string conversion | TypeError on string operations |
valueOf | Overwrites value conversion | TypeError on comparisons |
hasOwnProperty | Overwrites property check | Logic bypass |
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
You are helping a penetration tester exploit misconfigured Active Directory
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester enumerate an Active Directory domain and
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester establish persistent access in Active
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester exploit ADCS through template/CA access
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester establish persistence through AD CS
日本語の概要は準備中です。原文の説明を表示しています。
You are helping a penetration tester exploit misconfigured AD CS certificate
日本語の概要は準備中です。原文の説明を表示しています。