• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. What All the Phuzz Is About: A Coverage-guided Fuzzer for Finding Vulnerabilities in PHP Web Applications
 
  • Details
  • Full
Options
2024
Conference Paper
Title

What All the Phuzz Is About: A Coverage-guided Fuzzer for Finding Vulnerabilities in PHP Web Applications

Abstract
Coverage-guided fuzz testing has received significant attention from the research community, with a strong focus on binary applications, greatly disregarding other targets, such as web applications. The importance of the World Wide Web in everyone’s life cannot be overstated, and to this day, many web applications are developed in PHP. In this work, we address the challenges of applying coverage-guided fuzzing to PHP web applications and introduce Phuzz, a modular fuzzing framework for PHP web applications. Phuzz uses novel approaches to detect more client-side and server-side vulnerability classes than state-of-the-art related work, including SQL injections, remote command injections, insecure deserialization, path traversal, external entity injection, cross-site scripting, and open redirection. We evaluate Phuzz on a diverse set of artificial and real-world web applications with known and unknown vulnerabilities, and compare it against a variety of state-of-the-art fuzzers. In order to show Phuzz’ effectiveness, we fuzz over 1,000 API endpoints of the 115 most popular WordPress plugins, resulting in over 20 security issues and 2 new CVE-IDs. Finally, we make the framework publicly available to motivate and encourage further research on web application fuzz testing.
Author(s)
Neef, Sebastian
Technische Universität Berlin
Kleissner, Lorenz
Technische Universität Berlin
Seifert, Jean Pierre
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Mainwork
ACM Asiaccs 2024 Proceedings of the 19th ACM Asia Conference on Computer and Communications Security
Conference
19th ACM Asia Conference on Computer and Communications Security, AsiaCCS 2024
DOI
10.1145/3634737.3661137
Additional link
Full text
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Keyword(s)
  • Coverage-guided Fuzzing

  • Cross-Site Scripting

  • Fuzz testing

  • Greybox Fuzzing

  • PHP

  • PHUZZ

  • Remote Command Execution

  • SQL injection

  • Vulnerability Discovery

  • Web Security

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024