SQLiFuzz: Uncovering SQL Injection in Any Web Applications
I Putu Arya Dharmaadi, Van-Thuan Pham, Fadi Mohsen, Fatih Turkmen
摘要
SQL injection (SQLi) is one of the most critical and prevalent security vulnerabilities, as it enables attackers to manipulate backend databases, bypass authentication, and even gain complete control of the underlying system. Since web applications are the primary targets of SQLi, they must be thoroughly tested to ensure they are free of this vulnerability. Recently, several fuzz testing solutions tailored to SQLi vulnerabilities have been developed; however, our preliminary analysis reveals key limitations that hinder their effectiveness: they primarily focus on GUI-based inputs while neglecting API endpoints, rely on less effective request selection and generation strategies, and require complex configurations to be deployed in practice.
To address these gaps, we propose SQLiFuzz, a universal and simple-to-deploy SQL injection fuzzer that operates across both GUI (web pages) and API entry points. SQLiFuzz introduces three key distinguishing features: (i) a reverse proxy that unifies request collection and fuzzing, and allows seamless integration with existing crawlers and API scanners, (ii) a database proxy that enables request-query matching and serves as a reliable oracle, and (iii) a feedback-driven fuzzer that prioritizes potentially effective requests and parameters, and validates exploitability through database responses. We evaluated SQLiFuzz on six security benchmarks and ten real-world applications. SQLiFuzz successfully detects the majority of known SQLi cases in benchmarks and uncovered nine new vulnerabilities that had been overlooked by state-of-the-art tools in real-world applications. These results highlight SQLiFuzz's ability to detect SQL injection across diverse web application frameworks and architectures while maintaining practicality and ease of deployment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- Automated test generation for REST APIs: no time to rest yetMyeongsoo Kim, Qi Xin, Saurabh Sinha, Alessandro OrsoISSTA 2022 · 被引用 67 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- Vulnerability-oriented Testing for RESTful APIsWenlong Du, Jian Li, Yanhao Wang, Libo Chen 等USENIX Security 2024 · 被引用 17 次
- SoK: State of the Krawlers - Evaluating the Effectiveness of Crawling Algorithms for Web Security MeasurementsAleksei Stafeev, Giancarlo PellegrinoUSENIX Security 2024 · 被引用 12 次
- The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the WebSoheil Khodayari, Thomas Barber, Giancarlo PellegrinoS&P 2024 · 被引用 12 次
相关 Paper
- SQIRL: Grey-Box Detection of SQL Injection Vulnerabilities Using Reinforcement LearningSalim Al Wahaibi, Myles Foley, Sergio MaffeisUSENIX Security 2023
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang 等S&P 2024 · 被引用 15 次
- DeepSQLi: deep semantic learning for testing SQL injectionMuyang Liu, Ke Li, Tao ChenISSTA 2020 · 被引用 47 次
- Towards Generic Database Management System FuzzingYupeng Yang, Yongheng Chen, Rui Zhong, Jizhou Chen 等USENIX Security 2024 · 被引用 8 次
- Efficiently Detecting DBMS Bugs through Bottom-up Syntax-based SQL GenerationYu Liang, Peng LiuNDSS 2026
