Web Hack List

Collected research

SynthDB: Synthesizing Database via Program Analysis for Security Testing of Web Applications

Dynamic scanners miss vulnerable code in database-backed PHP applications because those paths are only reachable when the database holds the right data. SynthDB uses concolic execution to learn the constraints linking PHP code to its SQL queries and synthesizes a database satisfying them, lifting Burp Suite detection to 76.8 percent and uncovering 33 previously unknown vulnerabilities.

Record

Researcher
An Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon and Kyu Hyung Lee
Published by
NDSS Symposium
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of An Chen, Jiho Lee, Basanta Chaulagain, Yonghwi Kwon and Kyu Hyung Lee, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .