Identification of Dependency-based Attacks on Node.js
Brian Pfretzschner, Lotfi ben Othmane · 2017
Node.js executes server-side JavaScript-based code. By design Node.js and JavaScript support global variables, monkey-patching, and shared cache of loaded modules. This paper discusses four attacks that exploit these weaknesses, which are: leakage of global variables, manipulation of global variables, manipulation of local variables, and manipulation of the dependency tree. In addition, it describes the static code analysis that we implemented for T.J. Watson Libraries for Analysis (WALA) to detect the identified attacks and the evaluation of the analysis. The analysis is integrated into OpenWhisk, an open source serverless cloud platform.