It's (DOM) Clobbering Time: Attack Techniques, Prevalence, and Defenses
Soheil Khodayari, Giancarlo Pellegrino
摘要
DOM Clobbering is a type of code-less injection attack where attackers insert a piece of non-script, seemingly benign HTML markup into a webpage and transform it to executable code by exploiting the unforeseen interactions between JavaScript code and the runtime environment. The attack techniques, browser behaviours, and vulnerable code patterns that enable DOM Clobbering has not been studied yet, and in this paper, we undertake one of the first evaluations of the state of DOM Clobbering on the Web platform. Starting with a comprehensive survey of existing literature and dynamic analysis of 19 different mobile and desktop browsers, we systematize DOM Clobbering attacks, uncovering 31.4K distinct markups that use five different techniques to unexpectedly overwrite JavaScript variables in at least one browser. Then, we use our systematization to identify and characterize program instructions that can be overwritten by DOM Clobbering, and use it to present TheThing, an automated system that detects clobberable data flows to security-sensitive instructions. We instantiate TheThing on the top of the Tranco top 5K sites, quantifying the prevalence and impact of DOM Clobbering in the wild. Our evaluation uncovers that DOM Clobbering vulnerabilities are ubiquitous, with a total of 9,467 vulnerable data flows across 491 affected sites, making it possible to mount arbitrary code execution, open redirections, or client-side request forgery attacks also against popular websites such as Fandom, Trello, Vimeo, TripAdvisor, WikiBooks and GitHub, that were not exploitable through the traditional attack vectors. Finally, in this paper, we also evaluate the robustness of the existing countermeasures, such as HTML sanitizers and Content Security Policy, against DOM Clobbering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious ConsequencesZhengyu Liu, Kecheng An, Yinzhi CaoS&P 2024 · 被引用 17 次
- The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the WebSoheil Khodayari, Thomas Barber, Giancarlo PellegrinoS&P 2024 · 被引用 12 次
- Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint AnalysisYuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang 等OOPSLA 2025 · 被引用 9 次
- Unveiling the Invisible: Detection and Evaluation of Prototype Pollution Gadgets with Dynamic Taint AnalysisMikhail Shcherbakov, Paul Moosbrugger, Musard BalliuWWW 2024 · 被引用 8 次
- To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security LandscapeJannis Rautenstrauch, Metodi Mitkov, Thomas Helbrecht, Lorenz Hetterich 等S&P 2024 · 被引用 6 次
它引用的顶会 Paper9
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns 等USENIX Security 2016 · 被引用 130 次
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 被引用 125 次
- Code-Reuse Attacks for the Web: Breaking Cross-Site Scripting Mitigations via Script GadgetsSebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava 等CCS 2017 · 被引用 62 次
相关 Paper
- The DOMino Effect: Detecting and Exploiting DOM Clobbering Gadgets via Concolic Execution with Symbolic DOMZhengyu Liu, Theo Lee, Jianjia Yu, Zifeng Kang 等USENIX Security 2025
- In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the WebJan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein 等CCS 2025
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer 等NDSS 2018 · 被引用 84 次
- Finding All Cross-Site Needles in the DOM Stack: A Comprehensive Methodology for the Automatic XS-Leak Detection in Web BrowsersDominik Trevor Noß, Lukas Knittel, Christian Mainka, Marcus Niemietz 等CCS 2023
- JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative TraversalsSoheil Khodayari, Giancarlo PellegrinoUSENIX Security 2021 · 被引用 51 次
