Racedb: Detecting Request Race Vulnerabilities in Database-Backed Web Applications
An Chen, Yonghwi Kwon, Kyu Hyung Lee
Abstract
Request race vulnerabilities in database-backed web applications pose a significant security threat. These vulnera-bilities can lead to data inconsistencies, unexpected behavior, and even unauthorized access. Existing automated detection techniques often fall short due to the complexity of race conditions and the intricate interplay between application logic and database interactions. This paper introduces Racedb, a novel system that tackles these challenges through two key innovations. Application-aware Request Race Detection (ARD) provides a comprehensive analysis of data dependencies, considering not only the database query but also the application code. This allows RacedB to identify subtle race conditions that might be missed by existing approaches. Furthermore, Racedbemploys an automated verification technique using replay-based execution. This technique efficiently isolates true races from false positives and generates definitive exploits for verified vulnerabilities. We evaluated Racedb on a dataset of 14 real-world PHP web applications. The results demonstrate the effectiveness of Racedb compared to existing tools. Racedb achieved a superior detection rate, identifying 21 known vul-nerabilities and discovering 18 new vulnerabilities, significantly exceeding the performance of existing tools while also achieving a lower rate of false positives. Finally, we responsibly reported all newly discovered vulnerabilities to the corresponding developers, and 7 of them have been assigned CVE IDs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9a56f080-ef5f-40e3-a562-af871d4a764cRelated papers
- Understanding and detecting server-side request races in web applicationsZhengyi Qiu, Shudi Shao, Qi Zhao, Guoliang JinFSE 2021 · 5 citations
- SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web ApplicationsAn Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon et al.NDSS 2023
- FuzzCache: Optimizing Web Application Fuzzing Through Software-Based Data CachePenghui Li, Mingxue ZhangCCS 2024 · 3 citations
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
- Predator: Directed Web Application Fuzzing for Efficient Vulnerability ValidationChenlin Wang, Wei Meng, Changhua Luo, Penghui LiS&P 2025
