Toward Exploiting Access Control Vulnerabilities within MongoDB Backend Web Applications
Shuo Wen, Yuan Xue, Jing Xu, Hongji Yang, Xiaohong Li, Wenli Song, Guannan Si · 2016
Access control is an extremely important and error-prone practice during web application. The emergence of NoSQL databases and the flexible data models they bring impose new challenges on the implementation of access control within web applications. This paper presents Scout, a novel methodology for discovering access control vulnerabilities in existing web applications. Meanwhile (1) features of NoSQL database can be addressed and (2) neither application source code nor server-side session information from the developers is required. This paper implements a prototype of Scout, which targets MongoDB backend web applications. By automatically discovering the protocol layer in the web application stack, Scout introduces a data access operation model precisely representing the MongoDB actions performed in the web application, as well as inferring the access control policies. The prototype is shown to be able to identify comprehensive access control vulnerabilities in MongoDB backend web applications, and generate detailed report as the facilitator to manually fix the identified vulnerabilities.