Skip to content
← LibraryTechnique entry
W-PROTOTYPE-SERVERExecution

Server-Side Prototype Pollution → RCE

Polluting Object.prototype in Node lets you set unexpected child-process / spawn options leading to RCE.

§ Where this technique fits

W-PROTOTYPE-SERVER is catalogued under the Execution tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×
  2. 02seen 1×