USENIX Security2021Top-tier venue
Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web
Marco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara, Matteo Maffei
Abstract
Related-domain attackers control a sibling domain of their target web application, e.g., as the result of a subdomain takeover. Despite their additional power over traditional web attackers, related-domain attackers received only limited attention from the research community. In this paper we define and quantify for the first time the threats that related-domain attackers pose to web application security. In particular, we first clarify the capabilities that related-domain attackers can acquire through different attack vectors, showing that different instances of the related-domain attacker concept are worth attention. We then study how these capabilities can be abused to compromise web application security by focusing on different angles, including cookies, CSP, CORS, postMessage, and domain relaxation. By building on this framework, we report on a large-scale security measurement on the top 50k domains from the Tranco list that led to the discovery of vulnerabilities in 887 sites, where we quantified the threats posed by related-domain attackers to popular web applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers22
- Spook.js: Attacking Chrome Strict Site Isolation via Speculative ExecutionAyush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel et al.S&P 2022 · 32 citations
- SoK: State of the Krawlers - Evaluating the Effectiveness of Crawling Algorithms for Web Security MeasurementsAleksei Stafeev, Giancarlo PellegrinoUSENIX Security 2024 · 12 citations
- Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the WildZhenrui Zhang, Geng Hong, Xiang Li, Zhuoqun Fu et al.CCS 2023 · 9 citations
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang et al.OOPSLA 2025 · 9 citations
- Cloudy with a Chance of Cyberattacks: Dangling Resources Abuse on Cloud PlatformsJens Frieß, Tobias Gattermayer, Nethanel Gelernter, Haya Schulmann et al.NSDI 2024 · 5 citations
Builds on18
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire WebJosh Aas, Richard Barnes, Benton Case, Zakir Durumeric et al.CCS 2019 · 138 citations
Related papers
- Internet's Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the WildYuejia Liang, Jianjun Chen, Run Guo, Kaiwen Shen et al.CCS 2024 · 1 citation
- Towards Realistic and ReproducibleWeb Crawl MeasurementsJordan Jueckstock, Shaown Sarker, Peter Snyder, Aidan Beggs et al.WWW 2021 · 52 citations
- Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain VerificationRuixuan Li, Xingyu Zhao, Yunyi Zhang, Baojun Liu et al.USENIX Security 2026
- Too Much Sharing, Too Little Security: Authentication Cookie Theft At ScaleTobias Gattermayer, Haya SchulmannWWW 2026
- State of Browser Process-Isolation: The Same-Site WeaknessFabian Kilger, Hannah Fischer, Adrian Staeves, Robin Marchart et al.S&P 2026
