Web Hack List

Collected research

Automated Discovery of Parameter Pollution Vulnerabilities in Web Applications

PAPAS, a Firefox-driven black-box scanner, injects an encoded query delimiter into each existing parameter and checks whether it reappears inside the page's links and form actions. A 13-day crawl of 5,016 popular sites found about 30% with injectable parameters and confirmed 46.8% of those exploitable, including Google, PayPal, Symantec and Microsoft.

Record

Researcher
Marco Balduzzi, Carmen Torrano Gimenez, Davide Balzarotti and Engin Kirda
Published by
NDSS Symposium
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Marco Balduzzi, Carmen Torrano Gimenez, Davide Balzarotti and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .