Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web Applications
Rui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu, Yinzhi Cao
Abstract
Host Name Poisoning (HNP) allows an adversary to craft malicious host names at the client side to hijack server-side web application's functionality. Prior works have studied potential consequences of HNP, such as password resetting, cache poisoning, and origin confusion, but they largely ignored other consequences, such as open redirects, OAuth link hijacking, server-side request forgery (SSRF), and authentication bypasses. A study of HNP and its consequences is challenging due to the multi-layer architecture of server-side web applications. In this paper, we design a novel measurement framework, called HALO, to understand why HNP exists and detect HNP vulnerabilities in real-world, open-source web applications. HALO breaks down the multi-layer structure into individual components and analyzes them using a combination of dynamic testing and static analysis to detect vulnerabilities. Our evaluation of 9,860 open-source applications uncovers 82 zeroday HNP vulnerabilities. We have responsibly disclosed all of them to their developers: So far, we have received 52 Common Vulnerabilities and Exposures (CVEs) and 20 confirmed fixes.
- To simplify terminologies, we use a broader definition of web servers in the paper, which may include a reverse proxy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d05b32c6-7dbf-4c46-aaec-21527e126852Builds on6
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 84 citations
- Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsJianjun Chen, Jian Jiang, Hai-Xin Duan, Nicholas Weaver et al.CCS 2016 · 49 citations
- Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom DomainsKevin Saric, Felix Savins, Gowri Sankar Ramachandran, Raja Jurdak et al.WWW 2024 · 3 citations
- ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsSiddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl et al.USENIX Security 2023
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
Related papers
- Internet's Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the WildYuejia Liang, Jianjun Chen, Run Guo, Kaiwen Shen et al.CCS 2024 · 1 citation
- Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World WebsitesZifeng Kang, Muxi Lyu, Zhengyu Liu, Jianjia Yu et al.S&P 2025
- The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the WebSoheil Khodayari, Thomas Barber, Giancarlo PellegrinoS&P 2024 · 12 citations
- One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On WebsitesJiasheng Huang, Mingxuan Liu, Pei Chen, Baojun Liu et al.CCS 2026
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 56 citations
