Web Hack List

Collected research

Automatic Generation of XSS and SQL Injection Attacks with Goal-Directed Model Checking

QED compiles a PQL taint specification into a static analysis that prunes candidate URL sequences, then hands the survivors to the Java PathFinder model checker, which returns a concrete multi-request attack plus an execution trace and no false positives. Session data-flow dependence and non-repetition cut the space. Found 10 SQL injections and 13 XSS bugs in 130k lines of Struts apps.

Record

Researcher
Michael Martin and Monica S. Lam
Published by
usenix.org
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Michael Martin and Monica S. Lam, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .