July 4, 2023, 4 p.m. | Dana Epp

Security Boulevard securityboulevard.com

Learn how to use server-side prototype pollution (SSPP) to abuse an API written in NodeJS for privilege escalation and remote code execution.


The post How to exploit an API using prototype pollution appeared first on Dana Epp's Blog.


The post How to exploit an API using prototype pollution appeared first on Security Boulevard.

abuse api api hacking techniques blog code code execution epp escalation exploit learn privilege privilege escalation prototype remote code remote code execution security server written

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States