April 21, 2023, 6:30 p.m. | Allam Rachid (zhero_)

InfoSec Write-ups - Medium infosecwriteups.com

Source: somewhere on Twitter

I recently found a vulnerability that is a little less common and quite interesting in how it works.

Hello hunters, today I decided to share with you my last little discovery and to explain a little more in detail how prototype pollution work.

What is prototype pollution?

Definition from PortSwigger : Prototype pollution is a JavaScript vulnerability that enables an attacker to add arbitrary properties to global object prototypes, which may then be inherited by …

bug bounty cybersecurity dom hacking infosec javascript xss

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)