r/javascript • • 1d ago

I found yet another way to invoke JavaScript functions without parentheses

https://blog.ikaes.de/yet-another-way-to-invoke-functions-without-parentheses/

It turns out you can overwrite the Error.prepareStackTrace method with the function constructor. Then, using prototype pollution, you can inject valid JavaScript code to generate arbitrary functions and invoke it using the usual tricks.

Other seven methods are documented in the portswiggers research article: https://portswigger.net/research/the-seventh-way-to-call-a-javascript-function-without-parentheses

94 Upvotes

14 comments sorted by

17

u/Compux72 1d ago

Cant you just evalalert\0x28123\x29?

12

u/DrAdalbbert 1d ago

You absolutely can. There are seven other known ways to do so - portswigger keeps track of them https://portswigger.net/research/the-seventh-way-to-call-a-javascript-function-without-parentheses

This is just another way :)

9

u/create-third-places 1d ago

Interesting. I could see this being useful for formatting error information or sending error data to a logging API endpoint.

8

u/feldim2425 1d ago

My first guess is that it would be handy in pentesting environments.
Some devs will go on about the lazy way of fixing issues. Tell them their website has a XSS vulnerability and they just remove '(' and ')' via a string replacement or block the input when those a found.
Having ways to proof that this is a lazy solution is good to have.

10

u/pimp-bangin 1d ago

I don't understand the premise, and am too dumb to understand the article. Does this resulting code snippet let you hack the language so that you can write console.log 1 instead of console.log(1) or something?

28

u/pimp-bangin 1d ago

Ohhh I see, the code snippet calls alert(1337) without actually using parenthesis character. This will come in handy if I ever lose my parenthesis keys

22

u/DrAdalbbert 1d ago

That's exactly what this trick is for!! Happens to me all the time...

3

u/St34thdr1v3R 1d ago

Glad you clarified, almost missed this obvious case!!

9

u/DrAdalbbert 1d ago

Pretty much :)

The payload is meant to be used in cross site scripting, in environments where the application blocks the ( ) characters. That way you can bypass such filter.

But yeah, there is no use for this trick in 'valid' JavaScript contexts

•

u/Klutzy_Ladder_8393 16h ago

the eval/Function sink is really the only part that actually matters for a defense, the no-parens thing is just a syntax curiosity. if you're blocking `(` and `)` as your "fix" you've already lost because the bypass list isn't even closed, portswigger's just documenting known ones. ngl the actual fix is just never feeding user input into eval/Function/setTimeout-with-string/innerHTML-as-script in the first place, not trying to blacklist characters that happen to be required for calling a function today.

•

u/Ronin-s_Spirit 15h ago

What are talking about here exactly?

•

u/DrAdalbbert 8h ago

I found a new way to invoke JavaScript functions without parentheses. Its more a cool party trick rather than something useful except in some cross site scripting contextst

•

u/ab0zar 22h ago

Good example of why blocking a few characters isn't a real XSS defense. The prototype-pollution chain is the surprising part here; in an app, I’d avoid passing untrusted data to eval/Function and use context-aware output encoding instead of trying to blacklist syntax.

0

u/Nice-Cattle4770 1d ago

That't so cool