详细信息

Harvesting File Download Exploits in the Web: A Hacker's View  ( SCI-EXPANDED收录 EI收录)  

文献类型:期刊文献

英文题名:Harvesting File Download Exploits in the Web: A Hacker's View

作者:Zhou, Peng[1];Gu, Xiaojing[2];Chang, Rocky K. C.[3]

机构:[1]Shanghai Univ, Sch Mechatron Engn & Automat, Shanghai, Peoples R China;[2]E China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai 200237, Peoples R China;[3]Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China

年份:2016

卷号:59

期号:4

起止页码:522

外文期刊名:COMPUTER JOURNAL

收录:;EI(收录号:20163602764762);WOS:【SCI-EXPANDED(收录号:WOS:000374477700006)】;

基金:The work was partially supported by National Natural Science Foundation of China under Grant No. 61502293 and No. 61205017, and the Fundamental Research Funds for the Central Universities. This work is supported by Shanghai Key Laboratory of Power Station Automation Technology.

语种:英文

外文关键词:web security; file download exploits; Security-Enhanced script engine

摘要:File download vulnerability, which exposes web servers' local filesystem to the public, is among the most serious security threats in the web. Exploiting this vulnerability will cause disastrous consequences such as, but not limited to, system intrusion, database intrusion and even the leakage of massive confidential documents. Although the file download vulnerability has been known in the literature for a long time, a comprehensive study of its exploitability in the wild is still lacked. In this paper, we survey the landscape of file download vulnerabilities across different countries and domains, and more importantly, examines their exploitability from a hacker's perspective. We have successfully revealed the weak protection of this vulnerability in today's web, as well as confirmed its wide exploitability. To demonstrate the serious consequences, we present two real-world intrusion case studies. One is a system intrusion against a Chinese government website, and the other is a database intrusion targeted to a Chinese industrial service. Our intrusion cases have been confirmed as severe security events by CNCERT (an official security agency in China). At the end, we explore the root cause of this weak protection by analyzing the perils and pitfalls of existing defending solutions, and thereby propose a new enhancement. The basic idea is to deploy a mandatory access control mechanism in the server-side script engine kernel, so as to isolate the files managed by the web server from the local filesystem. We have implemented security-enhanced PHP (i.e. SEPHP), a prototype of our new solution by modifying the source code of PHP5 script engine, and also evaluated the performance overhead induced by SEPHP in a real-world web setting.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心