Security Study of Service Worker Cross-Site Scripting.

Security Study of Service Worker Cross-Site Scripting.
复制标题

Service Worker 跨站点脚本的安全研究。

DOI:
10.1145/3427228.3427290
复制
发表时间:
2020
期刊:
Proc. of 2020 Annual Computer Security Applications Conference (ACSAC’20
影响因子:
--
通讯作者:
Gu, Guofei
Gu, Guofei
中科院分区:
--
文献类型:
--
作者:
Chinprutthiwong, Phakpoom;Vardhan, Raj;Yang, GuangLiang;Gu, Guofei

文献摘要

参考文献

被引文献

相似文献

如今,现代网站正在利用 Service Worker 为用户提供类似应用程序的功能,例如离线模式和推送通知。为了处理这些功能,Service Worker 配备了特殊权限,包括 HTTP 流量操作。因此,它的设计以安全性为优先考虑。然而,我们发现许多网站引入了一种有问题的做法,可能会危及 Service Worker 的安全。在这项工作中,我们演示了这种做法如何导致 Service Worker 内部发生跨站脚本 (XSS) 攻击,从而允许攻击者获取并利用 Service Worker 权限。由于这些权限的独特性,与典型的 XSS 攻击相比,此类攻击可能会导致更严重的后果。我们将此类漏洞称为基于 Service Worker 的跨站脚本 (SW-XSS)。为了评估现实世界的安全影响,我们开发了一种名为 SW-Scanner 的工具,并用它来分析野外的顶级网站。我们的研究结果揭示了一个令人担忧的趋势。我们总共发现 40 个网站易受此攻击,其中包括几个受欢迎的高排名网站。最后,我们讨论缓解 SW-XSS 漏洞的潜在防御解决方案。
Nowadays, modern websites are utilizing service workers to provide users with app-like functionalities such as offline mode and push notifications. To handle such features, the service worker is equipped with special privileges including HTTP traffic manipulation. Thus, it is designed with security as a priority. However, we find that many websites introduce a questionable practice that can jeopardize the security of a service worker.In this work, we demonstrate how this practice can result in a cross-site scripting (XSS) attack inside a service worker, allowing an attacker to obtain and leverage service worker privileges. Due to the uniqueness of these privileges, such attacks can lead to more severe consequences compared to a typical XSS attack. We term this type of vulnerability as Service Worker based Cross-Site Scripting (SW-XSS). To assess the real-world security impact, we develop a tool called SW-Scanner and use it to analyze top websites in the wild. Our findings reveal a worrisome trend. In total, we find 40 websites vulnerable to this attack including several popular and high ranking websites. Finally, we discuss potential defense solutions to mitigate the SW-XSS vulnerability.
DOI: 10.1109/sp.2018.00039
发表时间: 2018-04
期刊: 2018 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者:
Abner Mendoza;G. Gu
通讯作者: Abner Mendoza;G. Gu
DOI: 10.14722/ndss.2018.23309
发表时间: 2018
期刊: Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security
影响因子: --
作者:
William Melicher;Anupam Das;Mahmood Sharif;Lujo Bauer;Limin Jia
通讯作者: William Melicher;Anupam Das;Mahmood Sharif;Lujo Bauer;Limin Jia
VisibleV8:浏览器内 JavaScript 监控
DOI: 10.1145/3355369.3355599
发表时间: 2019
期刊: Proceedings of the Internet Measurement Conference
影响因子: --
作者:
Jueckstock, Jordan;Kapravelos, Alexandros
通讯作者: Kapravelos, Alexandros
第 26 届年度网络与分布式系统安全研讨会,NDSS 2019,美国加利福尼亚州圣地亚哥,2019 年 2 月 24-27 日
DOI: --
发表时间: 2019
期刊: Network and Distributed System Security Symposium
影响因子: --
作者:
N. K. Hayles
通讯作者: N. K. Hayles
Web 如何纠缠自身:揭开客户端 Web(内)安全的历史
DOI: --
发表时间: 2017
期刊: USENIX Security Symposium
影响因子: --
作者:
Ben Stock;Martin Johns;Marius Steffens;M. Backes
通讯作者: M. Backes