Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web Applications
Qiyi Zhang, Fengyu Liu, Zihan Lin, Yuan Zhang
摘要
URL-based authentication provides a centralized and flexible way to safeguard sensitive resources in Java web applications by enforcing authentication checks based on URL paths. However, inconsistencies in handling flexible routing features (e.g., removing /./) between URL routing and authentication can be exploited to bypass authentication checks, resulting in URL-based Authentication Bypass Vulnerabilities (UABVulns). These vulnerabilities allow attackers to access sensitive resources without authentication, leading to serious security breaches. In this paper, we conduct the first in-depth study of 53 real-world UABVulns in Java web applications. Our study uncovers the root causes of UABVulns and identifies three key findings regarding URL routing, authentication, and sanitization. Guided by these findings, we design and implement UABScan, a static analysis tool that detects UABVulns by matching routing and authentication inconsistencies through pattern-based analysis. We evaluate UABScan on 529 popular Java web applications and successfully report 94 UABVulns across 72 applications, including 35 verified high-risk 0-days. Through manual investigation, UABScan achieves a recall of 87.50% and a precision of 80.00%, and significantly outperforms the state-of-the-art tool. To date, 31 CVE IDs have been assigned.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper13
- Back in Black: Towards Formal, Black Box Analysis of Sanitizers and FiltersGeorge Argyros, Ioannis Stais, Aggelos Kiayias, Angelos D. KeromytisS&P 2016 · 被引用 46 次
- TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP ApplicationsChanghua Luo, Penghui Li, Wei MengCCS 2022 · 被引用 27 次
- Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of ClassicsTian Tan, Yue LiISSTA 2023 · 被引用 26 次
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang 等S&P 2024 · 被引用 15 次
- Detecting Missing-Permission-Check Vulnerabilities in Distributed Cloud SystemsJie Lu, Haofeng Li, Chen Liu, Lian Li 等CCS 2022 · 被引用 12 次
相关 Paper
- Towards Automatic Detection and Exploitation of Java Web Application Vulnerabilities via Concolic Execution guided by Cross-thread Object ManipulationXinyou Huang, Lei Zhang, Yongheng Liu, Peng Deng 等USENIX Security 2025
- BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Enhao Li, Wei Meng 等CCS 2025
- MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web ApplicationsFengyu Liu, Youkun Shi, Yuan Zhang, Guangliang Yang 等S&P 2025
- File Hijacking Vulnerability: The Elephant in the RoomChendong Yu, Yang Xiao, Jie Lu, Yuekang Li 等NDSS 2024
- Demystifying the (In)Security of QR Code-based Login in Real-world DeploymentsXin Zhang, Xiaohan Zhang, Bo Zhao, Yuhong Nan 等USENIX Security 2025
