Keys on Doormats: Exposed API Credentials on the Web
Nurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir Durumeric
摘要
API (Application Programming Interface) keys allow applications to authenticate themselves to third-party services. Inadvertent public exposure of these credentials can pose significant consequences, as adversaries can use them to gain privileged access to other services. In this paper, we measure API credential exposure on the web by analyzing 10M rendered websites. Our findings reveal that API credential exposure on the web is widespread, affecting organizations such as global banks and core infrastructure providers. We identify 1,748 credentials for accessing 14 providers (e.g., cloud and payment services). Crucially, we demonstrate that these exposures are largely missed by static analysis. By characterizing web-specific exposure vectors and root causes, we find that 62% of JavaScript-based exposures manifest exclusively within compiled deployment bundles, while 16% propagate dynamically through third-party resource inclusions. Moreover, our longitudinal analysis shows these credentials often persist for months to years. We conclude by discussing our responsible disclosure efforts and outlining mitigations to secure web deployment pipelines in the future.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 被引用 130 次
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns 等USENIX Security 2016 · 被引用 130 次
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 被引用 123 次
相关 Paper
- KeyChaser: Unveiling API Keys in Browser ExtensionsShijin Chen, Willy Susilo, Yudi Zhang, Fuchun GuoS&P 2026 · 被引用 1 次
- The File That Contained the Keys Has Been Removed: An Empirical Analysis of Secret Leaks in Cloud Buckets and Responsible Disclosure OutcomesSoufian El Yadmani, Olga Gadyatskaya, Yury ZhauniarovichS&P 2025
- Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS AppsDavid Schmidt, Sebastian Schrittwieser, Edgar R. WeipplCCS 2025
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- A First Look at Security and Privacy Risks in the RapidAPI EcosystemSong Liao, Long Cheng, Xiapu Luo, Zheng Song 等CCS 2024 · 被引用 3 次
