Author: Hackers Colony

  • Finding a Stored XSS in a Popular React Component Library

    Finding a Stored XSS in a Popular React Component Library

    Finding a Stored XSS in a Popular React Component Library

    Introduction

    Last month, while auditing a widely-used React component library for a client project, I stumbled upon a stored Cross-Site Scripting (XSS) vulnerability that had been hiding in plain sight for over two years.

    The Vulnerability

    The library provided a MarkdownRenderer component that allowed users to render markdown content. The issue was in how it handled HTML sanitization…

    // Vulnerable code
    function MarkdownRenderer({ content }) {
      const html = markdownToHtml(content);
      return <div dangerouslySetInnerHTML={{ __html: html }} />;
    }
    

    The library used a popular sanitization library but had misconfigured it to allow data- attributes, which led to the bypass.

    The Exploit

    An attacker could craft markdown like:

    ![image](x onerror=alert(1) data-x=")
    

    This would execute JavaScript in the context of any application using the component.

    Responsible Disclosure

    1. Day 1: Reported to maintainers via GitHub Security Advisory
    2. Day 3: Maintainers acknowledged and began working on a fix
    3. Day 7: Patch released in v3.2.1
    4. Day 14: Public disclosure after users had time to update

    Lessons Learned

    1. Never trust dangerouslySetInnerHTML – Even with sanitization
    2. Audit your dependencies – Regular security reviews are essential
    3. Use Content Security Policy – Defense in depth matters
    4. Test with real attack vectors – Automated tools miss context-specific issues

    Conclusion

    This vulnerability affected over 500,000 weekly downloads. The fix was straightforward, but the impact could have been massive. Always sanitize, always validate, and never assume a popular library is immune to security issues.

  • Zero-Knowledge Proofs: A Practical Introduction for Developers

    Zero-Knowledge Proofs: A Practical Introduction for Developers

    Zero-Knowledge Proofs: A Practical Introduction

    What Are Zero-Knowledge Proofs?

    A zero-knowledge proof allows one party (the prover) to convince another party (the verifier) that a statement is true, without revealing any information beyond the validity of the statement itself.

    Types of ZK Proofs

    ZK-SNARKs

    • Succinct Non-interactive Argument of Knowledge
    • Requires trusted setup
    • Small proof size (~200 bytes)
    • Fast verification

    ZK-STARKs

    • Scalable Transparent Argument of Knowledge
    • No trusted setup required
    • Larger proof size (~50-100 KB)
    • Quantum resistant

    Practical Example: Private Voting

    // Simplified circuit for private voting
    fn voting_circuit(
        vote: bool,      // Private input
        nullifier: u64,  // Private input
        commitment: u64, // Public input
    ) -> bool {
        // Verify the vote is valid (0 or 1)
        // Verify nullifier hasn't been used
        // Verify commitment matches
        true
    }
    

    Getting Started

    1. Learn Circom – Circuit language for ZK-SNARKs
    2. Try snarkjs – JavaScript library for proof generation
    3. Explore RISC Zero – ZK virtual machine for general computation
    4. Join the community – ZK Hack, zkSummit, and more

    Resources

    The field is moving fast. What seemed impossible two years ago is now production-ready.

  • Reverse Engineering Modern Malware with Ghidra: A Hands-On Guide

    Reverse Engineering Modern Malware with Ghidra: A Hands-On Guide

    Reverse Engineering Modern Malware with Ghidra

    Setting Up Ghidra

    Download from ghidra-sre.org and ensure you have JDK 17+ installed.

    Sample Analysis: Lumma Stealer

    We’ll analyze a recent Lumma Stealer sample (SHA256: a1b2c3d4...).

    Initial Triage

    $ file sample.exe
    sample.exe: PE32+ executable (GUI) x86-64, for MS Windows
    
    $ strings sample.exe | head -20
    ...
    kernel32.dll
    advapi32.dll
    crypt32.dll
    ...
    

    Anti-Analysis Techniques

    The sample employs several anti-analysis techniques:

    1. VM Detection – Checks for VMware, VirtualBox artifacts
    2. Debugger Detection – IsDebuggerPresent, CheckRemoteDebuggerPresent
    3. Timing Checks – RDTSC-based timing analysis
    // Decompiled anti-VM check
    BOOL CheckVM() {
        HKEY hKey;
        RegOpenKeyExA(HKEY_LOCAL_MACHINE,
            "SYSTEM\\CurrentControlSet\\Services\\Disk\\Enum",
            0, KEY_READ, &hKey);
        // Checks for "VMware", "VBOX", "QEMU" in device names
    }
    

    Extracting IOCs

    Using Ghidra’s script manager, we can automate IOC extraction:

    # Ghidra Python script
    from ghidra.app.decompiler import DecompInterface
    from ghidra.util.task import ConsoleTaskMonitor
    
    def extract_strings():
        # Extract all strings and filter for URLs, IPs, domains
        pass
    

    Conclusion

    Ghidra has become an indispensable tool for malware analysis. Its decompiler, scripting capabilities, and active community make it a viable alternative to commercial tools.

  • Kubernetes Security Best Practices for 2024

    Kubernetes Security Best Practices for 2024

    Kubernetes Security Best Practices for 2024

    Cluster Hardening

    1. Control Plane Security

    # Audit policy
    apiVersion: audit.k8s.io/v1
    kind: Policy
    rules:
      - level: Metadata
        resources:
          - group: ""
            resources: ["secrets", "configmaps"]
      - level: RequestResponse
        resources:
          - group: ""
            resources: ["pods/exec", "pods/portforward"]
    

    2. Network Policies

    apiVersion: networking.k8s.io/v1
    kind: NetworkPolicy
    metadata:
      name: default-deny
    spec:
      podSelector: {}
      policyTypes:
        - Ingress
        - Egress
    

    Runtime Security

    • Falco – Runtime threat detection
    • Tracee – eBPF-based runtime security
    • KubeArmor – Cloud-native runtime enforcement

    Supply Chain Security

    • Sigstore/Cosign – Container signing
    • SBOM – Software Bill of Materials with Syft
    • Admission Controllers – Kyverno, OPA Gatekeeper

    Monitoring & Compliance

    • kube-bench – CIS Benchmark checks
    • kube-hunter – Penetration testing
    • Popeye – Cluster sanitizer

    Security is a journey, not a destination.

  • Secure Coding in Rust: Leveraging Ownership and Borrowing

    Secure Coding in Rust: Leveraging Ownership and Borrowing

    Secure Coding in Rust

    Memory Safety Without Garbage Collection

    Rust achieves memory safety through its ownership system:

    1. Each value has a single owner
    2. Ownership can be transferred (move semantics)
    3. References are either mutable XOR shared

    Preventing Use-After-Free

    // This won't compile - use after move
    fn main() {
        let s = String::from("hello");
        let s2 = s; // ownership moved
        println!("{}", s); // ERROR: borrow of moved value
    }
    

    Preventing Data Races

    // This won't compile - mutable and immutable references coexist
    fn main() {
        let mut data = vec![1, 2, 3];
        let r1 = &data;
        let r2 = &mut data; // ERROR: cannot borrow as mutable
        println!("{:?}", r1);
    }
    

    Real-World Impact

    These compile-time guarantees eliminate entire classes of vulnerabilities:

    • Buffer overflows
    • Use-after-free
    • Double-free
    • Data races
    • Null pointer dereferences

    Further Reading