Static detection of second-order vulnerabilities in web applications
Johannes Dahse, Thorsten Holz · 2014
Web applications evolved in the last decades from sim-ple scripts to multi-functional applications. Such com-plex web applications are prone to different types of se-curity vulnerabilities that lead to data leakage or a com-promise of the underlying web server. So called second-order vulnerabilities occur when an attack payload is first stored by the application on the web server and then later on used in a security-critical operation. In this paper, we introduce the first automated static code analysis approach to detect second-order vulnera-bilities and related multi-step exploits in web applica-tions. By analyzing reads and writes to memory loca-tions of the web server, we are able to identify unsani-tized data flows by connecting input and output points of data in persistent data stores such as databases or ses-sion data. As a result, we identified 159 second-order vulnerabilities in six popular web applications such as the conference management systems HotCRP and Open-Conf. Moreover, the analysis of web applications eval-uated in related work revealed that we are able to detect several critical vulnerabilities previously missed. 1