#prototypepollution
If I ever had to record a motivation video, this talk would be it 😅 Check it out and don't let "unexploitable" stop you! youtu.be/H-bhmSwnRdY

#defcon32 #bugbounty #rce #prototypepollution #nodejs #npm
DEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty - Mikhail Shcherbakov
YouTube video by DEFCONConference
youtu.be
November 27, 2024 at 9:08 AM
🛠 Breaking out of isolated containers via RCE-by-design.
💥 Turning Prototype Pollution from "just a DoS" into full #RCE with new gadgets in #Nodejs and #NPM packages.
🧩 Combining an "unexploitable" highly-restricted #PrototypePollution with a fixed one to achieve RCE.
November 27, 2024 at 9:08 AM
Google engineers plot to mitigate prototype pollution

https://cybersonar.org/go/JwChvU
Posted at 16:57

#PrototypePollution #JavaScriptSecurity #CodeOrganizationMatters
February 28, 2025 at 1:45 PM
At its core, this is a prototype-pollution flaw—dangerous on its own—but in Elysia’s validation/merge logic, it becomes a stepping stone to full RCE under the server’s authority.
#PrototypePollution #WebSecurity #SupplyChainSecurity #BackendSecurity 🧵2/5
December 11, 2025 at 3:42 PM
New write-up published: Prototype Pollution in Practice

Using three PortSwigger labs, I walk through a repeatable methodology.

Less about lab solutions, more about the process.

medium.com/@marduk.i.am...

#CyberSecurity #BugBounty #XSS #PrototypePollution
Prototype Pollution in Practice
Solving DOM XSS Labs Methodically
medium.com
June 2, 2026 at 8:56 PM
🚀 Enhanced our security scanner with prototype pollution detection! Now catches unsafe merge patterns and dynamic property access that could lead to security issues. #WebSecurity #JavaScript #PrototypePollution

### 2025-06-21
🚀 Just built a lightweight vulnerability scanner in...
June 22, 2025 at 8:51 PM
あまり使われていない古いライブラリにprototypepollutionからのXSSを見つけたけど深掘りするの面倒なので見なかったことにしよう
January 7, 2024 at 11:14 AM