hackgdl.exe
      __ __         __   ________  __ 
     / // /__ _____/ /__/ ___/ _ \/ / 
    / _  / _ `/ __/  '_/ (_ / // / /__
   /_//_/\_,_/\__/_/\_\\___/____/____/

    Turrón track

                
workshop.exe

Unpacking the Bundle - Weaponizing Webpack & Source Maps for Critical Info Disclosure

José Emiliano Pérez
Penetration Tester / Red Teamer

Modern Single Page Applications (SPAs) rely heavily on bundlers like Webpack, Vite, and Parcel to package dependencies and business logic. However, the transition from development to production can leave sensitive information, leading to an information disclosure. In this workshop, I will dissect the internal structure of JavaScript bundles and the associated Source Map standard. We will look specifically at how the devtool configuration in webpack.config.js impacts the final artifact and why developers frequently leave full source recovery enabled by mistake.

José_Emiliano_Pérez.jpg
José Emiliano Pérez
root@hackgdl.net Discord Twitter LinkedIn Instagram