Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js M Shcherbakov, M Balliu, CA Staicu 32nd USENIX Security Symposium (USENIX Security 23), 5521-5538, 2023 | 43 | 2023 |
SerialDetector: Principled and Practical Exploration of Object Injection Vulnerabilities for the Web M Shcherbakov, M Balliu Network and Distributed Systems Security (NDSS) Symposium 202121-24 February …, 2021 | 33 | 2021 |
Friendly fire: cross-app interactions in IoT platforms M Balliu, M Merro, M Pasqua, M Shcherbakov ACM Transactions on Privacy and Security (TOPS) 24 (3), 1-40, 2021 | 24 | 2021 |
Unveiling the Invisible: Detection and Evaluation of Prototype Pollution Gadgets with Dynamic Taint Analysis M Shcherbakov, P Moosbrugger, M Balliu Proceedings of the ACM on Web Conference 2024, 1800-1811, 2024 | 6 | 2024 |
GHunter: Universal Prototype Pollution Gadgets in JavaScript Runtimes E Cornelissen, M Shcherbakov, M Balliu 33rd USENIX Security Symposium (USENIX Security 24), 3693-3710, 2024 | 1 | 2024 |
Prototype Pollution Leads to RCE: Gadgets Everywhere M Shcherbakov | 1 | |
Code-Reuse Attacks in Managed Programming Languages and Runtimes M Shcherbakov KTH Royal Institute of Technology, 2024 | | 2024 |
Friendly Fire M Balliu, M Merro, M Pasqua, M Shcherbakov Journal: ACM Transactions on Privacy and Security, 1-40, 2021 | | 2021 |