Spider-Scents: Grey-box Database-aware Web Scanning for Stored XSS
Eric Olsson, Benjamin Eriksson, Adam Doupé, Andrei Sabelfeld
摘要
As web applications play an ever more important role in society, so does ensuring their security. A large threat to web application security is XSS vulnerabilities, and in particular, stored XSS. Due to the complexity of web applications and the difficulty of properly injecting XSS payloads into a web application, many of these vulnerabilities still evade current state-of-the-art scanners. We approach this problem from a new direction-by injecting XSS payloads directly into the database we can completely bypass the difficulty of injecting XSS payloads into a web application. We thus propose Spider-Scents, a novel method for grey-box database-aware scanning for stored XSS, that maps database values to the web application and automatically finds unprotected outputs. Spider-Scents reveals code smells that expose stored XSS vulnerabilities. We evaluate our approach on a set of 12 web applications and compare with three state-of-the-art black-box scanners. We demonstrate improvement of database coverage, ranging from 79% to 100% database coverage across the applications compared to the range of 2% to 60% for the other scanners. We systematize the relationship between unprotected outputs, vulnerabilities, and exploits in the context of stored XSS. We manually analyze unprotected outputs reported by Spider-Scents to determine their vulnerability and exploitability. In total, this method finds 85 stored XSS vulnerabilities, outperforming the union of state-of-the-art's 32.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web ApplicationsFengyu Liu, Youkun Shi, Yuan Zhang, Guangliang Yang 等S&P 2025
- BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsFengyu Liu, Yuan Zhang, Enhao Li, Wei Meng 等CCS 2025
它引用的顶会 Paper5
- T-Fuzz: Fuzzing by Program TransformationHui Peng, Yan Shoshitaishvili, Mathias PayerS&P 2018 · 被引用 326 次
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 被引用 65 次
- Chainsaw: Chained Automated Workflow-based Exploit GenerationAbeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2016 · 被引用 52 次
- SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web ApplicationsAn Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon 等NDSS 2023
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel 等S&P 2023
相关 Paper
- Uncovering Hidden Attack Surfaces in Web Applications via Semantic-Aware Black-Box ScanningFukun Mei, Peiyang Li, Miao Chen, Beijie Hou 等CCS 2026
- Dancer in the Dark: Synthesizing and Evaluating Polyglots for Blind Cross-Site ScriptingRobin Kirchner, Jonas Möller, Marius Musch, David Klein 等USENIX Security 2024 · 被引用 9 次
- Splendor: Static Detection of Stored XSS in Modern Web ApplicationsHe Su, Feng Li, Lili Xu, Wenbo Hu 等ISSTA 2023 · 被引用 11 次
- XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent FuzzingYoukun Shi, Yuan Zhang, Tianhao Bai, Feng Xue 等USENIX Security 2025
- Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement LearningSoyoung Lee, Seongil Wi, Sooel SonWWW 2022 · 被引用 34 次
