Nullcon Berlin 2023 | Server Side Prototype Pollution: Blackbox Detection Without The DoS by Gareth
About this talk
This talk explores the challenges of detecting server-side prototype pollution (SSPP) without risking denial-of-service (DoS) issues. The speaker presents multiple techniques for identifying SSPP that do not require access to the server's source code, discussing the advantages and disadvantages of each method. Additionally, the session covers how to identify the JavaScript engine used on various sites through specially crafted requests. The speaker introduces an open-source Burp extension that facilitates SSPP detection within Burp Suite and concludes with defensive measures and a Q&A session.
More from this event
See all 17 talks →
Nullcon Berlin 2023 | Why I Write My Own Security Tooling & Why You Should Too! by James Forshaw
41:49
Nullcon Berlin 2023 | SCCI: The Road To Side-Channel Regression Testing In CI Development by Witold
46:39
Nullcon Berlin 2023 | Panel: Securing the Road to Autonomy
36:23
Nullcon Berlin 2023 | Dirty Stream Attack, Turning Android Share Targets To Attack Vectors
42:02