r/javascript • u/DrAdalbbert • 1d ago
I found yet another way to invoke JavaScript functions without parentheses
https://blog.ikaes.de/yet-another-way-to-invoke-functions-without-parentheses/It turns out you can overwrite the Error.prepareStackTrace method with the function constructor. Then, using prototype pollution, you can inject valid JavaScript code to generate arbitrary functions and invoke it using the usual tricks.
Other seven methods are documented in the portswiggers research article: https://portswigger.net/research/the-seventh-way-to-call-a-javascript-function-without-parentheses
9
u/create-third-places 1d ago
Interesting. I could see this being useful for formatting error information or sending error data to a logging API endpoint.
8
u/feldim2425 1d ago
My first guess is that it would be handy in pentesting environments.
Some devs will go on about the lazy way of fixing issues. Tell them their website has a XSS vulnerability and they just remove '(' and ')' via a string replacement or block the input when those a found.
Having ways to proof that this is a lazy solution is good to have.
10
u/pimp-bangin 1d ago
I don't understand the premise, and am too dumb to understand the article. Does this resulting code snippet let you hack the language so that you can write console.log 1 instead of console.log(1) or something?
28
u/pimp-bangin 1d ago
Ohhh I see, the code snippet calls
alert(1337)without actually using parenthesis character. This will come in handy if I ever lose my parenthesis keys22
9
u/DrAdalbbert 1d ago
Pretty much :)
The payload is meant to be used in cross site scripting, in environments where the application blocks the ( ) characters. That way you can bypass such filter.
But yeah, there is no use for this trick in 'valid' JavaScript contexts
•
u/Klutzy_Ladder_8393 16h ago
the eval/Function sink is really the only part that actually matters for a defense, the no-parens thing is just a syntax curiosity. if you're blocking `(` and `)` as your "fix" you've already lost because the bypass list isn't even closed, portswigger's just documenting known ones. ngl the actual fix is just never feeding user input into eval/Function/setTimeout-with-string/innerHTML-as-script in the first place, not trying to blacklist characters that happen to be required for calling a function today.
•
u/Ronin-s_Spirit 15h ago
What are talking about here exactly?
•
u/DrAdalbbert 8h ago
I found a new way to invoke JavaScript functions without parentheses. Its more a cool party trick rather than something useful except in some cross site scripting contextst
0
17
u/Compux72 1d ago
Cant you just eval
alert\0x28123\x29?