
Clientseitiger Prototype-Pullution-Schwachstellenscanner
JSPanda ist ein clientseitiger Scanner für Schwachstellen durch Prototype Pollution. Er bietet zwei wesentliche Funktionen: das Scannen von Schwachstellen in den bereitgestellten URLs und die Analyse des Quellcodes von JavaScript-Bibliotheken.
JSPanda kann jedoch keine fortgeschrittenen Prototype-Pollution-Schwachstellen erkennen.
Scan: python3.7 jspanda.py
Grundlegende Quellcode-Analyse: python3.7 analyze.py

Unterstützende Materialien :
https://twitter.com/har1sec/status/1314469278322655233
https://github.com/BlackFan/client-side-prototype-pollution
https://habr.com/ru/company/huawei/blog/547178/
https://github.com/securitum/research/tree/master/r2020_prototype-pollution
Lerne Prototype Pollution in Serie – Teil 2
GitHub - raverrr/plution: Prototype-Pollution-Scanner mit kopflosem Chrome
JavaScript Prototype Poisoning Vulnerabilities in the Wild
Der vollständige Leitfaden zu Prototype-Pollution-Schwachstellen