sourcemap安全漏洞复现
之前部署的xray报了一个漏洞:
dirscan/sourcemap/default
url:
还原源码
安装reverse-sourcemap:
npm install --global reverse-sourcemap
输出源码
reverse-sourcemap -v xx.js.map -o soucecodes
之前部署的xray报了一个漏洞:
dirscan/sourcemap/default
url:
npm install --global reverse-sourcemap
reverse-sourcemap -v xx.js.map -o soucecodes