BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web Applications
Fengyu Liu, Yuan Zhang, Enhao Li, Wei Meng, Youkun Shi, Qianheng Wang, Chenlin Wang, Zihan Lin, Min Yang
Abstract
Broken-Access-Control (BAC) vulnerabilities have consistently been ranked among the most critical security risks in web applications, occupying the top positions in the OWASP Top 10 over the past several years. These vulnerabilities allow attackers to bypass access control mechanisms and perform unauthorized operations, posing serious security and privacy threats to sensitive business and user data. Despite substantial attention given to BAC vulnerabilities, effective and reliable approaches to detecting these issues remain limited. In this work, we present BACScan, a novel black-box approach to detect BAC vulnerabilities in web applications. Unlike existing response similarity-based oracles that check only unauthorized read accesses, BACScan introduces an innovative feedback-driven oracle, which determines whether unauthorized read or modification operations have occurred by inferring operationally-dependent web pages and analyzing the operational feedback. We evaluated BACScan on 20 real-world applications and successfully identified 89 vulnerabilities, including 54 previously unreported ones, outperforming state-of-the-art tools. We reported all newly identified vulnerabilities to the affected vendors. To date, 35 new CVE IDs have been assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 42e05dc9-2bbc-486d-8b22-04e94d94cfe5Builds on17
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 85 citations
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung et al.USENIX Security 2019 · 77 citations
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 65 citations
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 59 citations
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
Related papers
- BACAgent: LLM-Powered Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Zheng Lou, Tian Chen et al.CCS 2026
- Uncovering Hidden Attack Surfaces in Web Applications via Semantic-Aware Black-Box ScanningFukun Mei, Peiyang Li, Miao Chen, Beijie Hou et al.CCS 2026
- Beacon: Detecting Broken Access Control Vulnerabilities in DBMSs via System Catalog Consistency ValidationZongrui Peng, Jingzhou Fu, Zhiyong Wu, Jie Liang et al.OOPSLA 2026
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
- 403 Forbidden? Ethically Evaluating Broken Access Control in the WildSaiid El Hajj Chehade, Florian Hantke, Ben StockS&P 2025
