https://hub.jhu.edu/2022/03/14/computer-scientist-identifies-javascript-vulnerability/ Skip to main content * Menu * Hub Open Hub + About the Hub + Announcements + For Media + Faculty Experts Guide + Subscribe to the newsletter + Explore by Topic + Arts+Culture + Athletics + Health + Politics+Society + Science+Technology + Student Life + University News + Voices+Opinion * Events * At Work Open At Work + About Hub at Work + Classifieds + Gazette Archive + Explore by Topic + News+Info + Benefits+Perks + Health+Wellness + Tools+Tech + Happenings * Johns Hopkins Magazine Open Johns Hopkins Magazine + Current Issue + About the Magazine + Past Issues + Contact + Support Johns Hopkins Magazine + Subscribe to the Magazine * jhu.edu * Search Hub Hub Johns Hopkins University Johns Hopkins University A developer's view of javascript Credit: Getty Images Computer scientist identifies JavaScript vulnerability in thousands of websites ProbeTheProto framework developed by computer scientist Yinzhi Cao helps identify and alert websites vulnerable to a flaw that allows malicious actors to 'pollute' important web code By Catherine Graham / Published March 14, 2022 Millions of developers use JavaScript to build websites and mobile apps, making it one of the most popular programming languages in the world. But according to Johns Hopkins researchers, thousands of JavaScript websites are vulnerable to a security flaw that could result in manipulating the site's URL or stealing a user's profile information. Known as prototype pollution, the flaw allows attackers to modify, or "pollute," a prototype, which is a built-in property of a JavaScript object. An attacker who manages to alter a JavaScript object prototype can execute a variety of malicious actions. With a framework they call ProbeTheProto, researchers from the Johns Hopkins Information Security Institute analyzed one million websites running on JavaScript and found that more than 2,700 websites--some of them the most visited in the world--had multiple flaws that could expose them to prototype pollution. Ten of the sites were among the top 1,000 most visited websites of the year, including Weebly.com, CNET.com, and McKinsey.com. "Our ProbeTheProto tool can automatically and accurately detect a wide range of potential attacks. And we've found that many developers are happy that we are helping them stay ahead of cybersecurity threats." Yinzhi Cao Assistant professor of computer science "Only recently have researchers started looking closely at prototype pollution and realizing it's a matter of great concern," said cybersecurity expert Yinzhi Cao, an assistant professor of computer science in the Johns Hopkins Whiting School of Engineering. "Many in the developer community may not be aware that prototype pollution vulnerabilities can have severe consequences." In Javascript, an object is a collection of related data or functionality; for example, a user account object may contain such data as usernames, passwords, and e-mail addresses. Once an attacker makes a change to an object prototype, it will affect how the object works throughout the entire application and opens the door for more serious vulnerabilities, Cao adds. He and his team set out to the study this snowball effect using dynamic taint analysis, a method in which inputs to the application are labeled with a special "tainted" marker and the researchers observe how the tainted data propagates through the program. If the marker is still there at the program's output, the researchers know that the application is vulnerable to exploitable input attacks that could lead to some unplanned action. "Imagine a very long pipe in a big black box and I want to know whether Points A and B are connected. If they are, I can put some toxic liquid at Point A to attack Point B. What we do is to drop a bit of red dye in the water at Point A and then observe the water color at Point B. If I can see Point B is also red, I know A and B are connected and then we can launch attacks," Cao said. The researchers identified three major input attacks that can be caused by prototype pollution: cross-site scripting (XSS), cookie manipulation, and URL manipulation. Such vulnerabilities on public websites provide ample opportunities for cyber criminals to hijack passwords and install malware, among other nefarious activities. Cao says that researchers have a responsibility to report prototype pollution vulnerabilities to website owners and even recommend the best patch for their code. Thanks to Cao's team sounding the alarm, so far 293 vulnerabilities have already been fixed by developers. "Organizations don't even know these vulnerabilities exist. Our ProbeTheProto tool can automatically and accurately detect a wide range of potential attacks. And we've found that many developers are happy that we are helping them stay ahead of cybersecurity threats," Cao said. Computer science graduate students Zifeng Kang and Song Li contributed to the research. The team members will present their paper "Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites," at the Network & Distributed System Security Symposium April 24-28 in San Diego. Posted in Science+Technology Tagged cybersecurity, information security institute Share on Twitter Pin it on Pinterest Email More social media options Share on LinkedIn Share on Reddit Share on Tumblr Share on Twitter Pin it on Pinterest Email More social media options Share on LinkedIn Share on Reddit Share on Tumblr Related Content A person enters a passcode on their phone Cybersecurity Now's the time to protect your computer networks from cyberattack Published March 4, 2022 Anton Dahbura from the Information Security Institute suggests that individuals and enterprises should take steps now to secure cyber systems against attack from Russian agents Vladimir Putin Q+A Russia-Ukraine conflict maxes out cyberattack risk assessment index Published Feb 15, 2022 Cyber Attack Predictive Index predicts the potential for cyberattacks between nations; Tool finds "extremely high likelihood" of attack against Ukraine by Russia News from Johns Hopkins delivered to your inbox You might also like Trending News Network * The Hub * At Work * Johns Hopkins Magazine * Search Explore by Topic * Health * Science+Technology * Arts+Culture * Politics+Society * University News * Student Life * Athletics * Voices+Opinion Resources * About the Hub * Get Email Updates * Events * Submit an Announcement * Submit an Event * Community guidelines * For Media * Faculty Experts Guide * Privacy Statement * Accessibility * Contact Us Discover JHU * jhu.edu * About the University * Schools & Divisions * Academic Programs * Admissions * Plan a Visit * Employment * my.JohnsHopkins.edu Johns Hopkins University Johns Hopkins University Johns Hopkins University Johns Hopkins University * (c) 2022 Johns Hopkins University. All rights reserved. * Office of Communications * 3910 Keswick Rd., Suite N2600, Baltimore, MD * Twitter Facebook LinkedIn YouTube Instagram