BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web Applications
Fengyu Liu, Yuan Zhang, Enhao Li, Wei Meng, Youkun Shi, Qianheng Wang, Chenlin Wang, Zihan Lin, Min Yang
摘要
Broken-Access-Control (BAC) vulnerabilities have consistently been ranked among the most critical security risks in web applications, occupying the top positions in the OWASP Top 10 over the past several years. These vulnerabilities allow attackers to bypass access control mechanisms and perform unauthorized operations, posing serious security and privacy threats to sensitive business and user data. Despite substantial attention given to BAC vulnerabilities, effective and reliable approaches to detecting these issues remain limited. In this work, we present BACScan, a novel black-box approach to detect BAC vulnerabilities in web applications. Unlike existing response similarity-based oracles that check only unauthorized read accesses, BACScan introduces an innovative feedback-driven oracle, which determines whether unauthorized read or modification operations have occurred by inferring operationally-dependent web pages and analyzing the operational feedback. We evaluated BACScan on 20 real-world applications and successfully identified 89 vulnerabilities, including 54 previously unreported ones, outperforming state-of-the-art tools. We reported all newly identified vulnerabilities to the affected vendors. To date, 35 new CVE IDs have been assigned.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper17
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung 等USENIX Security 2019 · 被引用 77 次
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 被引用 65 次
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 被引用 59 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
相关 Paper
- BACAgent: LLM-Powered Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Zheng Lou, Tian Chen 等CCS 2026
- Uncovering Hidden Attack Surfaces in Web Applications via Semantic-Aware Black-Box ScanningFukun Mei, Peiyang Li, Miao Chen, Beijie Hou 等CCS 2026
- Beacon: Detecting Broken Access Control Vulnerabilities in DBMSs via System Catalog Consistency ValidationZongrui Peng, Jingzhou Fu, Zhiyong Wu, Jie Liang 等OOPSLA 2026
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
- 403 Forbidden? Ethically Evaluating Broken Access Control in the WildSaiid El Hajj Chehade, Florian Hantke, Ben StockS&P 2025
