Web Security

Posts tagged "Web Security"

11 posts found

Prototype Pollution: Engine Internals, Node.js Gadget Chains, and Hardening Architecture

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

13 min read
2,587 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Bypassing WAFs with Unicode Compatibility

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

10 min read
1,951 words
İS

ibrahimsql

Cybersecurity Engineer

Read More