Lune

S&P2026顶会

Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web Applications

Rui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu, Yinzhi Cao

2026年份
1被引次数

摘要

Host Name Poisoning (HNP) allows an adversary to craft malicious host names at the client side to hijack server-side web application's functionality. Prior works have studied potential consequences of HNP, such as password resetting, cache poisoning, and origin confusion, but they largely ignored other consequences, such as open redirects, OAuth link hijacking, server-side request forgery (SSRF), and authentication bypasses. A study of HNP and its consequences is challenging due to the multi-layer architecture of server-side web applications. In this paper, we design a novel measurement framework, called HALO, to understand why HNP exists and detect HNP vulnerabilities in real-world, open-source web applications. HALO breaks down the multi-layer structure into individual components and analyzes them using a combination of dynamic testing and static analysis to detect vulnerabilities. Our evaluation of 9,860 open-source applications uncovers 82 zeroday HNP vulnerabilities. We have responsibly disclosed all of them to their developers: So far, we have received 52 Common Vulnerabilities and Exposures (CVEs) and 20 confirmed fixes.

  1. To simplify terminologies, we use a broader definition of web servers in the paper, which may include a reverse proxy.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper6

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖