USENIX Security2024Top-tier venue
Argus: All your (PHP) Injection-sinks are belong to us
Rasoul Jahanshahi, Manuel Egele
Abstract
Injection-based vulnerabilities in web applications such as cross-site scripting (XSS), insecure deserialization, and command injection have proliferated in recent years, exposing both clients and web applications to security breaches. Current studies in this area focus on detecting injection vulnerabilities in applications. Crucially, existing systems rely on manually curated lists of functions, so-called sinks, to detect such vulnerabilities. However, current studies are oblivious to the internal mechanics of the underlying programming language. In such a case, existing systems rely on an incomplete set of sinks, which results in disregarding security vulnerabilities. Despite numerous studies on injection vulnerabilities, there has been no study that comprehensively identifies the set of functions that an attacker can exploit for injection attacks. This paper addresses the drawbacks of relying on manually curated lists of sinks to identify such vulnerabilities. We devise a novel generic approach to automatically identify the set of sinks that can lead to injection-style security vulnerabilities. To demonstrate the generality, we focused on three types of injection vulnerabilities: XSS, command injection, and insecure deserialization. We implemented a prototype of our approach in a tool called Argus to identify the set of PHP functions that deserialize user-input, execute operating system (OS) commands, or write user-input to the output buffer. We evaluated our prototype on the three most popular major versions of the PHP interpreter. Argus detected 284 deserialization functions that allow adversaries to perform deserialization attacks, an order of magnitude more than the most exhaustive manually curated list used in related work. Furthermore, we detected 22 functions that can lead to XSS attacks, which is twice the number of functions used in prior work. To demonstrate that Argus produces security-relevant findings, we integrated its results with three existing analysis systems -Psalm and RIPS, two static taint analyses, and FUGIO, an exploit generation tool. The modified tools detected 13 previously unknown deserialization and XSS vulnerabilities in WordPress and its plugins, of which 11 have been assigned CVE IDs and designated as high-severity vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 31c9f419-008d-4335-9dcd-ea9f18e5e2d0Builds on3
- Saphire: Sandboxing PHP Applications with Tailored System Call AllowlistsAlexander Bulekov, Rasoul Jahanshahi, Manuel EgeleUSENIX Security 2021 · 30 citations
- FUGIO: Automatic Exploit Generation for PHP Object Injection VulnerabilitiesSunnyeo Park, Daejun Kim, Suman Jana, Sooel SonUSENIX Security 2022
- SerialDetector: Principled and Practical Exploration of Object Injection Vulnerabilities for the WebMikhail Shcherbakov, Musard BalliuNDSS 2021
Related papers
- ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsSiddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl et al.USENIX Security 2023
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang et al.S&P 2024 · 15 citations
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- CoBrA: Context-, Branch-sensitive Static Analysis for Detecting Taint-style Vulnerabilities in PHP Web ApplicationsYichao Xu, Mingqing Kang, Neil Thimmaiah, Rigel Gjomemo et al.ICSE 2026
- FIXX: FInding eXploits from eXamplesNeil P. Thimmaiah, Yashashvi J. Dave, Rigel Gjomemo, V. N. VenkatakrishnanUSENIX Security 2025
