Web Hack List

Collected research

On Race Vulnerabilities in Web Applications

DIMVA 2008 paper on race conditions in web applications, arising because programmers treat scripts as sequential while the server runs many instances against one shared database. It gives a dynamic detection method that replays interleaved request pairs and compares database state, with SQL annotations to suppress benign reports. Real races were found in Joomla, phpBB, WordPress and Zen Cart.

Record

Researcher
Roberto Paleari, Davide Marrone, Danilo Bruschi and Mattia Monga
Published by
roberto.greyhats.it
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Roberto Paleari, Davide Marrone, Danilo Bruschi and Mattia Monga, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .