谷雨 醉心 冬小麦

生活要坚强,自信
如同冬天的小麦一样散发生机
遇雨更青翠

IT 计算机&信息网络 技术:

URFDS: Systematic discovery of Unvalidated Redirects and Forwards in web applications

Author:
Jing Wang, Hongjun Wu
School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore

Abstract:
URL redirection is necessary in web applications. Well-designed redirection makes better user experience. However, if usedimproperly, it could give rise to attacks such as phishing. These improperly used redirections are called Unvalidated Redirects and Forwards (URF). This paper prescribes a mechanism to systemically discover URF vulnerabilities in web applications. The prototype implementation, that we call Unvalidated Redirects and Forwards Detection System (URFDS), uses a black-box scanning technique to modify URLs and analyse the generated output to identify URF. In order to show the feasible of our approach, we tested 142,522,691 unique links and found a great number of vulnerabilities in top websites and popular applications that were overlooked by previous works.

http://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=7346891


评论

热度(17)

  1. 白帽子安全IT 计算机&信息网络 技术 转载了此图片  到 文豆 & 文库
  2. 點滴的記錄IT 计算机&信息网络 技术 转载了此图片
  3. 谷雨 醉心 冬小麦IT 计算机&信息网络 技术 转载了此图片
  4. 家庭小木屋白帽子安全 转载了此图片
  5. 琐事,日常之事白帽子安全 转载了此图片
  6. 计算机网络技术白帽子安全 转载了此图片
  7. 琐事,日常之事白帽子安全 转载了此图片  到 IT 计算机信息网络安全技术
  8. 白帽子安全IT 计算机&信息网络 技术 转载了此图片