Web Hack List

Collected research

NoTamper: Automatic Blackbox Detection of Parameter Tampering Opportunities in Web Applications

NoTamper extracts the constraints a page's HTML and JavaScript impose on form input, using concrete-symbolic evaluation, then solves them to build benign and hostile inputs. It ranks hostile inputs by how closely the server's reply resembles a benign one. Across 8 open-source apps and 5 live sites it found 169 opportunities and 9 confirmed exploits, including arbitrary bank transfers.

Record

Researcher
Prithvi Bisht, Timothy Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz and V.N. Venkatakrishnan
Published by
cs.uic.edu
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Prithvi Bisht, Timothy Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz and V.N. Venkatakrishnan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .