Six killed in US strike on boat in Caribbean (VIDEO)
President Donald Trump has ordered the military to attack vessels he claims smuggle drugs in the region
Read Full Article at RT.com
More results...
President Donald Trump has ordered the military to attack vessels he claims smuggle drugs in the region
Read Full Article at RT.com
An asylum-seeker sentenced to 12 months in a British prison for sexually assaulting a 14-year-old girl was mistakenly released Friday, prompting an urgent police search for a man whose case had prompted anti-migrant protests.
Ontario Premier Doug Ford says he will run anti-tariff commercials that enraged President Trump during the first two games of the World Series before pulling the ads Monday in hopes of restarting trade talks.
Re: “Trump takes a victory lap in Israel after peace deal” (Oct. 14, Nation & World): I compliment President Donald Trump and his team for getting the remaining hostages back for Israel. Whether or not it is the end of “terror and death” in the Mid…
Colombia’s President Gustavo Petro on Friday responded with defiance to an announcement by the US that he would face sanctions, along with his wife, son and interior minister, for “allowing drug cartels to flourish”. The sanctions come amid a growing …
The prospect of more financial difficulties is likely to exacerbate tensions among the Kremlin elite “extremely unhappy” that Putin rejected a peace deal.
Next.js server actions present an interesting challenge during penetration tests. These server-side functions appear in proxy tools as POST requests with hashed identifiers like a9fa42b4c7d1 in the Next-Action header, making it difficult to understand what each request actually does. When applications have productionBrowserSourceMaps enabled, this Burp extension NextjsServerActionAnalyzer bridges that gap by automatically mapping these hashes to their actual function names.
During a typical web application assessment, endpoints usually have descriptive names and methods: GET /api/user/1 clearly indicates its purpose. Next.js server actions work differently. They all POST to the same endpoint, distinguished only by hash values that change with each build. Without tooling, testers must manually track which hash performs which action—a time-consuming process that becomes impractical with larger applications.
The extension’s effectiveness stems from understanding how Next.js bundles server actions in production. When productionBrowserSourceMaps is enabled, JavaScript chunks contain mappings between action hashes and their original function names.
The tool simply uses flexible regex patterns to extract these mappings from minified JavaScript.
The extension automatically scans proxy history for JavaScript chunks, identifies those containing createServerReference calls, and builds a comprehensive mapping of hash IDs to function names.
Rather than simply tracking which hash IDs have been executed, it tracks function names. This is important since the same function might have different hash IDs across builds, but the function name will remain constant.
For example, if deleteUserAccount() has a hash of a9f8e2b4c7d1 in one build and b7e3f9a2d8c5 in another, manually tracking these would see these as different actions. The extension recognizes they’re the same function, providing accurate unused action detection even across multiple application versions.
A useful feature of the extension is its ability to transform discovered but unused actions into testable requests. When you identify an unused action like exportFinancialData(), the extension can automatically:
This removes the manual work of manually creating server action requests.
We recently assessed a Next.js application with dozens of server actions. The client had left productionBrowserSourceMaps enabled in their production environment—a common configuration that includes debugging information in JavaScript files. This presented an opportunity to improve our testing methodology.
Using the Burp extension, we:
updateUserProfile() and fetchReportData()The function name mapping transformed our testing approach. Instead of tracking anonymous hashes, we could see that b7e3f9a2 mapped to deleteUserAccount() and c4d8b1e6 mapped to exportUserData(). This clarity helped us create more targeted test cases.
submitted by /u/ok_bye_now_
[link] [comments]
President Trump is reportedly set to name the new White House ballroom, costing $300 million, after himself. Dubbed ‘The President Donald J. Trump Ballroom,’ the project, which replaced the East Wing, has raised over $350 million. Trump has pledged mi…
The Trump administration has been blowing up fishing boats in the Caribbean — and now one in the Pacific — claiming without evidence that they’re “drug boats.”These are extrajudicial executions outside any system of law. And there’s a reason we should…
Latest News Latest News https://www.channelnewsasia.com/ CySecBot CySecBot