>
On page 19 in the The Methbot Operation report they state that ‘White Ops detection technology was able to use a JavaScript language feature called “reflection” to gather extensive, detailed information about its inner workings.’
I have personally never heard about JavaScript reflection before, but it appear to be a debug method for one object to dump information or data about another object.
Maybe the White Ops software loaded some JavaScript that was able to dump much of its environment and send it back to White Ops?
let test = function() { return "hello";}
test.toString()
returns "function() { return "hello";}"
It's not too difficult to imagine that pairing that with some JS parsing would allow you to slowly crawl your way around an app and gather the app structure. Crazy, and fascinating idea.I imagine somewhere in MethBots virtual DOM emulation they got sloppy and ran code (JS) from the server. Using metaprogramming plus some output they could predict they could use runtime reflection and inspect server side JS object.