Waptec: Whitebox Analysis Of Web Applications For Parameter Tampering Exploit Construction

CCS'11: the ACM Conference on Computer and Communications Security Chicago Illinois USA October, 2011(2011)

引用 60|浏览146
暂无评分
摘要
Parameter tampering attacks are dangerous to a web application whose server fails to replicate the validation of user-supplied data that is performed by the client. Malicious users who circumvent the client can capitalize on the missing server validation. In this paper, we describe WAPTEC, a tool that is designed to automatically identify parameter tampering vulnerabilities and generate exploits by construction to demonstrate those vulnerabilities. WAPTEC involves a new approach to whitebox analysis of the server's code. We tested WAPTEC on six open source applications and found previously unknown vulnerabilities in every single one of them.
更多
查看译文
关键词
Parameter Tampering,Exploit Construction,Program Analysis,Constraint Solving
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要