EvoCrawl: Exploring Web Application Code and State using Evolutionary Search
Xiangyu Guo, Akshay Kawlay, Eric Liu, David Lie
Abstract
—As more critical services move onto the web, it has become increasingly important to detect and address vulnerabilities in web applications. These vulnerabilities only occur under specific conditions: when 1) the vulnerable code is executed and 2) the web application is in the required state. If the application is not in the required state, then even if the vulnerable code is executed, the vulnerability may not be triggered. Previous work naively explores the application state by filling every field and triggering every JavaScript event before submitting HTML forms. However, this simplistic approach can fail to satisfy constraints between the web page elements, as well as input format constraints. To address this, we present EvoCrawl, a web crawler that uses evolutionary search to efficiently find different sequences of web interactions. EvoCrawl finds sequences that can successfully submit inputs to web applications and thus explore more code and server-side states than previous approaches. To assess the benefits of EvoCrawl, we evaluate it against three state-of-the-art vulnerability scanners on ten web applications. We find that EvoCrawl achieves better code coverage due to its ability to execute code that can only be executed when the application is in a particular state. On average, EvoCrawl achieves a 59% increase in code coverage and successfully submits HTML forms 5 × more frequently than the next best tool. By integrating IDOR and XSS vulnerability scanners, we used EvoCrawl to find eight zero-day IDOR and XSS vulnerabilities in WordPress, HotCRP, Kanboard, ImpressCMS, and GitLab.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Autonomy Comes with Costs: Detecting Denial-of-Service Vulnerabilities Caused by Resource Abusing in LLM-based AgentsJiaqi Luo, Jiarun Dai, Fengyu Liu, Songyang Peng et al.USENIX Security 2026
- BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Enhao Li, Wei Meng et al.CCS 2025
- Make Agent Defeat Agent: Automatic Detection of Taint-Style Vulnerabilities in LLM-based AgentsFengyu Liu, Yuan Zhang, Jiaqi Luo, Jiarun Dai et al.USENIX Security 2025
Builds on3
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes et al.CCS 2017 · 74 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel et al.S&P 2023
Related papers
- Automated Generation of Event-Oriented Exploits in Android Hybrid AppsGuangliang Yang, Jeff Huang, Guofei GuNDSS 2018 · 79 citations
- ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application ScanningKostas Drakonakis, Sotiris Ioannidis, Jason PolakisNDSS 2023
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
- Dancer in the Dark: Synthesizing and Evaluating Polyglots for Blind Cross-Site ScriptingRobin Kirchner, Jonas Möller, Marius Musch, David Klein et al.USENIX Security 2024 · 9 citations
- Automatic Web Testing Using Curiosity-Driven Reinforcement LearningYan Zheng, Yi Liu, Xiaofei Xie, Yepang Liu et al.ICSE 2021 · 75 citations
