Collected research
NoTamper: Automatic Blackbox Detection of Parameter Tampering Opportunities in Web Applications
NoTamper extracts the constraints a page's HTML and JavaScript impose on form input, using concrete-symbolic evaluation, then solves them to build benign and hostile inputs. It ranks hostile inputs by how closely the server's reply resembles a benign one. Across 8 open-source apps and 5 live sites it found 169 opportunities and 9 confirmed exploits, including arbitrary bank transfers.
Record
- Researcher
- Prithvi Bisht, Timothy Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz and V.N. Venkatakrishnan
- Published by
- cs.uic.edu
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Prithvi Bisht, Timothy Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz and V.N. Venkatakrishnan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .