Web Hack List

Collected research

Revealer: Detecting and Exploiting Regular Expression Denial-of-Service Vulnerabilities

Revealer: Detecting and exploiting regular expression denial-of-service vulnerabilities

Regular expression denial of service exploits regexes whose matching time blows up on crafted input. Revealer models the vulnerable structures of regexes that use extended features, locates them statically, verifies them dynamically by triggering recursive backtracking, and generates attack strings, finding 213 vulnerabilities beyond existing tools.

Record

Document
Revealer: Detecting and exploiting regular expression denial-of-service vulnerabilities
Published by
The Chinese University of Hong Kong
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of The Chinese University of Hong Kong, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .