Web Hack List

Collected research

Deemon: Detecting CSRF with Dynamic Analysis and Property Graphs

Deemon records a web application's network traffic, server execution and database queries into a single property graph, then uses graph traversals to find state-changing requests that lack anti-CSRF protection and auto-generates tests to confirm them. It found 14 unknown CSRF flaws allowing account and site takeover.

Record

Researcher
Giancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes and Christian Rossow
Published by
acmccs.github.io
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Giancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes and Christian Rossow, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .