A Small Leak Will Sink Many Ships: Vulnerabilities Related to mini-programs Permissions

A Small Leak Will Sink Many Ships: Vulnerabilities Related to mini-programs Permissions
复制标题

DOI:
10.1109/compsac57700.2023.00085
复制
发表时间:
2022-05
期刊:
2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC)
影响因子:
--
通讯作者:
Jianyi Zhang;L. Yang;Yuyang Han;Zhi Sun;Zixiao Xiang
Jianyi Zhang;L. Yang;Yuyang Han;Zhi Sun;Zixiao Xiang
中科院分区:
其他
文献类型:
--
作者:
Jianyi Zhang;L. Yang;Yuyang Han;Zhi Sun;Zixiao Xiang

文献摘要

相似文献

小程序作为一种新的移动的应用形式,在一个更大的应用程序中运行,并使用HTML,CSS和JavaScript Web技术构建,已经成为在中国做几乎所有事情的方式。许多研究者已经对生态系统或发展进行了研究,但对许可问题的研究还很少。在本文中,我们提出了我们的研究权限管理的小程序,并进行了系统的研究,9个流行的移动的主机应用程序生态系统,托管超过700万个小程序。在测试了超过2,580个API之后,我们提取了一个用于小程序权限控制的通用抽象模型,并揭示了由于权限管理不当而导致的六类潜在安全漏洞。令人担忧的是,当前流行的移动的应用生态系统(即,主机应用程序)至少有一个安全漏洞,由于小程序的权限管理不当。我们提出了相应的攻击方法来剖析这些潜在的弱点,进一步利用发现的漏洞。为了证明所揭示的漏洞可能会在实际使用中造成严重后果,我们展示了三种没有特权或破解主机应用程序的攻击。我们已经负责任地披露了新发现的漏洞,并发布了两个CVE。最后,提出了加强小程序规范化建设的系统建议。
As a new format of mobile application, mini-programs, which function within a larger app and are built with HTML, CSS, and JavaScript web technology, have become the way to do almost everything in China. Many researchers have done the ecosystem or developing study, while the permission problem has not been investigated yet. In this paper, we present our studies on the permission management of mini-programs and conduct a systematic study on 9 popular mobile host app ecosystems that host over 7 million mini-programs. After testing over 2,580 APIs, we extracted a common abstract model for mini-programs’ permission control and revealed six categories of potential security vulnerabilities due to improper permission management. It is alarming that the current popular mobile app ecosystems (i.e., host apps) under study have at least one security vulnerability due to the mini-programs’ improper permission management. We present the corresponding attack methods to dissect these potential weaknesses further to exploit the discovered vulnerabilities. To prove that the revealed vulnerabilities may cause severe consequences in real-world use, we show three kinds of attacks without privileges or cracking the host apps. We have responsibly disclosed the newly discovered vulnerabilities, and two CVEs were issued. Finally, we put forward systematic suggestions to strengthen the standardization of mini-programs.