Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites
Zifeng Kang, Song Li, Yinzhi Cao · 2022
While prototype pollution is starting to draw people's attentions [6], [24], [29], one major remaining research question is what further consequence a prototype pollution can lead to beyond polluting a prototypical object after successful exploitation.Say, for example, if another snippet of JavaScript code co-located with a prototype pollution vulnerability loops through all the properties with constant values under an object to generate an HTML code, this prototype pollution will allow an adversary to inject arbitrary JavaScript code, leading to a Cross-site Scripting (XSS).Recently, people are realizing the importance in studying the further consequence of prototype pollution.For example, a blog post [9] and a Github repository [10] both illustrate some prototype pollution examples that may lead to consequences such as the aforementioned XSS.However, to the best of our knowledge, no prior works have systematically studied the further consequences of prototype pollution especially among client-side JavaScript in real-world websites.Prior academic works [6], [24], [29] detect only the existence of prototype pollution in server-side Node.js applications but not their consequence.The aforementioned blog post and repository [9], [10] only illustrate some possible consequences with manual analysis but do not detect them in real-world websites automatically let alone perform a large-scale measurement.Putting aside the consequence analysis, prior server-side detections are not scalable or accurate for client-side prototype pollution either.ObjLupAnsys [29], the state of the art, is not scalable to analyze client-side JavaScript, because their heavy-weight abstract interpretation leads to path and object explosion.DAPP [24], a closed-source static analysis tool, has very large false positives (>50%) and can only rely on human exports to check the exploitability of the found vulnerabilities.Arteau [6] explores Node.js packages with a set of pre-defined, server-side exploit inputs to package's exported functions: Such a method is not applicable at the client side where inputs are diversified (e.g., message, URLs, and cookies) and only part of the inputs contain the exploit whereas the rest may be for satisfying the vulnerable condition.In this paper, we present PROBETHEPROTO, the first largescale measurement of client-side prototype pollution vulnerabilities and their consequences among one million real-world websites.The key insight here is to track adversary-controlled inputs into vulnerable property lookups, such as obj[prop], via dynamic taint analysis to detect prototype pollution vulnerabilities, and then guide object lookups in propagating taints Abstract-Prototype pollution is a relatively new type of JavaScript vulnerabilities, which allows an adversary to inject a property into a prototypical object, such as Object.prototype.The injected property may be used later in other sensitive locations like innerHTML, leading to Crosssite Scripting (XSS), or document.cookie,leading to cookie manipulations.Prior works proposed to detect prototype pollution in Node.js application using static analysis.However, it still remains unclear how prevalent prototype pollution is in clientside JavaScript, let alone what consequences (e.g., XSS and cookie manipulations) prototype pollution could lead to.In this paper, we propose PROBETHEPROTO, the first largescale measurement study of client-side prototype pollution among one million real-world websites.PROBETHEPROTO consists of two important parts: dynamic taint analysis that tracks so-called joint taint flows connecting property lookups and assignments, and input/exploit generation that guides joint taint flows into final sinks related to further consequences.PROBETHEPROTO answers the questions of whether a prototypical object is controllable, whether and what properties can be manipulated, and whether the injected value leads to further consequences.We implemented a prototype of PROBETHEPROTO and evaluated it on one million websites.The results reveal that 2,738 real-world websites-including ten among the top 1,000-are vulnerable to 2,917 zero-day, exploitable prototype pollution vulnerabilities.We verify that 48 vulnerabilities further lead to XSS, 736 to cookie manipulations, and 830 to URL manipulations.We reported all the findings to website maintainers and so far 185 vulnerable websites have already been patched.