Automatic detection of access control vulnerabilities in web applications by URL crawling and forced browsing
DC Field | Value | Language |
---|---|---|
dc.contributor.author | 도경구 | - |
dc.contributor.author | Song, Hong | - |
dc.contributor.author | Kim, Yukyong | - |
dc.date.accessioned | 2025-04-01T08:32:37Z | - |
dc.date.available | 2025-04-01T08:32:37Z | - |
dc.date.issued | 2012-04 | - |
dc.identifier.uri | https://scholarworks.bwise.kr/erica/handle/2021.sw.erica/123079 | - |
dc.description.abstract | Access control vulnerabilities can be disastrous in Web applications. The vulnerabilities might be introduced when developers set up unsafe policies in design phase or inconsistently implement safe policies. Attackers take advantage of the vulnerabilities to obtain the authority of administrator and the sensitive information of another user. Hence, the early detection of access control vulnerabilities is very important. This paper proposes a dynamic analysis that automatically detects access control vulnerabilities in web applications. Given a web site and authorities, accessible URLs for each authority are collected by crawling the web site, and then a chosen subset of the URLs are tested to check whether or not access control vulnerabilities exist for the given authority. We implemented the idea, experimented it with some selected web applications, and found some real access-control vulnerabilities | - |
dc.language | 영어 | - |
dc.language.iso | ENG | - |
dc.title | Automatic detection of access control vulnerabilities in web applications by URL crawling and forced browsing | - |
dc.type | Conference | - |
dc.citation.title | Information Science and Technology | - |
dc.citation.volume | 3 | - |
dc.citation.number | 2 | - |
dc.citation.startPage | 482 | - |
dc.citation.endPage | 486 | - |
dc.identifier.url | https://www.semanticscholar.org/paper/Automatic-Detection-of-Access-Control-in-Web-by-URL-Song-Kim/b489858736343940cf21214cb3298ce80c1ad9a7 | - |
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.
55 Hanyangdeahak-ro, Sangnok-gu, Ansan, Gyeonggi-do, 15588, Korea+82-31-400-4269 sweetbrain@hanyang.ac.kr
COPYRIGHT © 2021 HANYANG UNIVERSITY. ALL RIGHTS RESERVED.
Certain data included herein are derived from the © Web of Science of Clarivate Analytics. All rights reserved.
You may not copy or re-distribute this material in whole or in part without the prior written consent of Clarivate Analytics.