메뉴 건너뛰기




Volumn , Issue , 2011, Pages 251-261

Fear the EAR: Discovering and mitigating execution after redirect vulnerabilities

Author keywords

Execution after redirect; Static analysis; Web applications

Indexed keywords

CAPTURE THE FLAG; COMPREHENSIVE STUDIES; CROSS SITE SCRIPTING; EXECUTION AFTER REDIRECT; INFORMATION LEAKAGE; INPUT VALIDATION; OPEN-SOURCE; RUBY ON RAILS; SECURITY IMPLICATIONS; SECURITY VULNERABILITIES; SQL INJECTION; WEB APPLICATION; WEB APPLICATION VULNERABILITY;

EID: 80755187811     PISSN: 15437221     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2046707.2046736     Document Type: Conference Paper
Times cited : (45)

References (36)
  • 1
    • 80755145196 scopus 로고    scopus 로고
    • ASP.NET MVC. http://www.asp.net/mvc.
  • 8
    • 0004285392 scopus 로고
    • 1st ed. Prentice Hall PTR, Upper Saddle River, NJ, USA
    • BOEHM, B. W. Software Engineering Economics, 1st ed. Prentice Hall PTR, Upper Saddle River, NJ, USA, 1981.
    • (1981) Software Engineering Economics
    • Boehm, B.W.1
  • 9
    • 80755144146 scopus 로고    scopus 로고
    • https://trac.cakephp.org/ticket/1076, August
    • Include exit with a redirect call, http://replay.web.archive.org/ 20061011152124/ https://trac.cakephp.org/ticket/1076, August 2006.
    • (2006) Include Exit with a Redirect Call
  • 10
  • 11
    • 80755160322 scopus 로고    scopus 로고
    • CAKE SOFTWARE FOUNDATION, INC. The CakePHP 1.3 Book. http://book.cakephp. org/view/982/redirect, 2011.
    • (2011) The CakePHP 1.3 Book
  • 15
    • 80755145193 scopus 로고    scopus 로고
    • DJANGO SOFTWARE FOUNDATION. Django shortcut functions. http://docs.djangoproject.com/en/dev/topics/http/shortcuts/#django.shortcuts. redirect, 2011.
    • (2011) Django Shortcut Functions
  • 16
    • 80755145190 scopus 로고    scopus 로고
    • ELLISLAB, INC.
    • ELLISLAB, INC. Codelgniter User Guide Version 2.0.2. http://codeigniter. com/user-guide/helpers/url-helper.html, 2011.
    • (2011) Codelgniter User Guide Version 2.0.2
  • 19
    • 80755188428 scopus 로고    scopus 로고
    • GitHub. http://github.com.
  • 20
    • 80755145192 scopus 로고    scopus 로고
    • Indictment in U.S. v. Albert Gonzalez August
    • Indictment in U.S. v. Albert Gonzalez. http://www.justice.gov/usao/ma/ news/IDTheft/Gonzalez,720Albert720-720Indictment720080508.pdf, August 2008.
    • (2008)
  • 21
    • 77954470294 scopus 로고    scopus 로고
    • September
    • HANSEN, R. Clickjacking. http://ha.ckers.org/blog/20080915/clickjacking/, September 2008.
    • (2008) Clickjacking
    • Hansen, R.1
  • 25
    • 33751027156 scopus 로고    scopus 로고
    • Pixy: A static analysis tool for detecting web application vulnerabilities (Short paper)
    • DOI 10.1109/SP.2006.29, 1624016, Proceedings - 2006 IEEE Symposium on Security and Privacy, S+P 2006
    • JOVANOVIC, N., KRUEGEL, C, AND KIRDA, E. Pixy: A static analysis tool for detecting web application vulnerabilities (short paper). In IN 2006 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (2006), pp. 258-263. (Pubitemid 44753727)
    • (2006) Proceedings - IEEE Symposium on Security and Privacy , vol.2006 , pp. 258-263
    • Jovanovic, N.1    Kruegel, C.2    Kirda, E.3
  • 28
    • 84923564816 scopus 로고    scopus 로고
    • Finding security vulnerabilities in java applications with static analysis
    • Berkeley, CA, USA USENIX Association
    • LIVSHITS, V. B., AND LAM, M. S. Finding security vulnerabilities in Java applications with static analysis. In Proceedings of the 14th conference on USENIX Security Symposium - Volume 14 (Berkeley, CA, USA, 2005), USENIX Association, pp. 18-18.
    • (2005) Proceedings of the 14th Conference on USENIX Security Symposium , vol.14 , pp. 18-18
    • Livshits, V.B.1    Lam, M.S.2
  • 29
    • 84877838219 scopus 로고    scopus 로고
    • OPEN WEB APPLICATION SECURITY PROJECT (OWASP). OWASP Top Ten Project. http://www.owasp.org/index.php/Top-10, 2010.
    • (2010) OWASP Top Ten Project
  • 30
    • 80755145189 scopus 로고    scopus 로고
    • Outcome of sentencing in U.S. v. Albert Gonzalez March
    • ORTIZ, C. Outcome of sentencing in U.S. v. Albert Gonzalez. http://www.justice.gov/usao/ma/news/IDTheft/09-CR-10382/ G0NZALEZ%20website%20info%205-11-10.pdf, March 2010.
    • (2010)
    • Ortiz, C.1
  • 34
    • 80755144144 scopus 로고    scopus 로고
    • SPRINGSOURCE
    • SPRINGSOURCE. Contollers - Redirects. http://www.grails.org/Controllers+- +Redirects, 2010.
    • (2010) Contollers - Redirects


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.