Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Server-Side Prototype Pollution: Detection and Exploitation Techniques - OWASP AppSec Dublin

OWASP Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course demonstrates server-side prototype pollution techniques, including manipulating JSON responses and detecting JavaScript engines. It also covers generic detection approaches and prevention.

Syllabus

Intro
Prototype chain
Merge operation
Recursive merge function
Encoding property takes the server down
Change the maximum allowed parameters
Allow multiple question marks in param
Convert a parameter into an object
Change the charset of a JSON response
Investigating the charset technique
Change the padding of a JSON response
Change the status code
Generic prototype pollution detection in Blitz
A generic prototype pollution technique
Asynchronous payloads problem
Leaking code
Detecting JavaScript engines
Open source tool
Preventing prototype pollution

Taught by

OWASP Foundation

Reviews

Start your review of Server-Side Prototype Pollution: Detection and Exploitation Techniques - OWASP AppSec Dublin

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.