Understanding and Detecting Abused Image Hosting Modules as Malicious Services
Geng Hong, Mengying Wu, Pei Chen, Xiaojing Liao, Guoyi Ye, Min Yang
摘要
As a new type of underground ecosystem, the exploitation of Abused IHMs as MalIcious sErvices (AIMIEs) is becoming increasingly prevalent among miscreants to host illegal images and propagate harmful content. However, there has been little effort to understand this new menace, in terms of its magnitude, impact, and techniques, not to mention any serious effort to detect vulnerable image hosting modules on a large scale. To fulfill this gap, this paper presents the first measurement study of AIMIEs. By collecting and analyzing 89 open-sourced AIMIEs, we reveal the landscape of AIMIEs, report the evolution and evasiveness of abused image hosting APIs from reputable companies such as Alibaba, Tencent, and Bytedance, and identify real-world abused images uploaded through those AIMIEs. In addition, we propose a tool, called Viola, to detect vulnerable image hosting modules (IHMs) in the wild. We find 477 vulnerable IHM upload APIs associated with 338 web services, which integrated vulnerable IHMs, and 207 victim FQDNs. The highest-ranked domain with vulnerable web service is baidu.com, followed by bilibili.com and 163.com. We have reported abused and vulnerable IHM upload APIs and received acknowledgments from 69 of them by the time of paper submission. CCS CONCEPTS • Security and privacy → Web application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper10
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- A Lustrum of Malware Network Communication: Evolution and InsightsChaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero 等S&P 2017 · 被引用 86 次
- Black Widow: Blackbox Data-driven Web ScanningBenjamin Eriksson, Giancarlo Pellegrino, Andrei SabelfeldS&P 2021 · 被引用 65 次
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
- Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On DeploymentsMohammad Ghasemisharif, Chris Kanich, Jason PolakisS&P 2022 · 被引用 25 次
相关 Paper
- Exploring and Exploiting Security Vulnerabilities in Self-Hosted LLM ServicesZhihuang Liu, Ling Hu, Yonghao Tang, Tongqing Zhou 等WWW 2026
- Malla: Demystifying Real-world Large Language Model Integrated Malicious ServicesZilong Lin, Jian Cui, Xiaojing Liao, XiaoFeng WangUSENIX Security 2024 · 被引用 49 次
- Into the Dark: Unveiling Internal Site Search Abused for Black Hat SEOYunyi Zhang, Mingxuan Liu, Baojun Liu, Yiming Zhang 等USENIX Security 2024 · 被引用 1 次
- Exposing the Hidden Layer: Software Repositories in the Service of Seo ManipulationMengying Wu, Geng Hong, Wuyuao Mai, Xinyi Wu 等ICSE 2025 · 被引用 1 次
- File Hijacking Vulnerability: The Elephant in the RoomChendong Yu, Yang Xiao, Jie Lu, Yuekang Li 等NDSS 2024
