US2023259637A1PendingUtilityA1

Detecting Injection Vulnerabilities of Client-Side Templating Systems

Assignee: GOOGLE LLCPriority: May 4, 2018Filed: Apr 19, 2023Published: Aug 17, 2023
Est. expiryMay 4, 2038(~11.8 yrs left)· nominal 20-yr term from priority
G06F 21/577G06F 9/547H04L 63/1433H04L 63/1466G06F 2221/033
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for detecting an injection vulnerability of a client-side templating system includes receiving a web page, determining that the web page implements an interpreted programming language framework with client-side templating, and extracting a version of the interpreted programming language framework and an interpolation sign from the web page. The method also includes generating an attack payload for at least one injection vulnerability context of the web page based on the version of the interpreted programming language framework and the interpolation sign, instrumenting the web page to inject the attack payload into the at least one injection vulnerability context of the web page, and executing the instrumented web page.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method executed by data processing hardware that causes the data processing hardware to perform operations comprising:
 receiving a web page;   extracting, from the web page, a client-side expression that implements client-side templating;   generating an attack payload for at least one injection vulnerability context of the web page based on the client-side expression;   instrumenting the web page to inject the attack payload into the at least one injection vulnerability context of the web page;   executing the instrumented web page;   determining an exception generated during execution of the instrumented web page; and   in response to determining the exception generated during execution of the instrumented web page, identifying a vulnerability of the web page.   
     
     
         2 . The method of  claim 1 , wherein receiving the web page comprises:
 receiving a web page request for the web page; and   retrieving the requested web page.   
     
     
         3 . The method of  claim 1 , wherein instrumenting the web page comprises injecting the attack payload into one or more possible input vectors associated with the at least one injection vulnerability context. 
     
     
         4 . The method of  claim 1 , wherein determining the exception generated during execution of the instrumented web page comprises catching a thrown exception triggered by the attack payload during execution of the instrumented web page. 
     
     
         5 . The method of  claim 1 , wherein the operations further comprise, modifying an exception handler of an interpreted programming language framework to intercept the exception. 
     
     
         6 . The method of  claim 1 , wherein the exception comprises a syntax exception. 
     
     
         7 . The method of  claim 1 , wherein the attack payload comprises a validation function configured to validate execution of the validation function. 
     
     
         8 . The method of  claim 7 , wherein the operations further comprise:
 catching a response of the validation function triggered by the attack payload during execution of the instrumented web page; and   identifying a second vulnerability of the web page based on the response.   
     
     
         9 . The method of  claim 1 , wherein generating the attack payload for the at least one injection vulnerability context of the web page based on the client-side expression comprises extracting a version of an interpreted programming language framework and an interpolation sign from the web page. 
     
     
         10 . The method of  claim 1 , wherein generating the attack payload comprises generating a single attack payload configured for instrumentation into the web page for each of one or more possible input vectors associated with the injection vulnerability context. 
     
     
         11 . A system comprising:
 data processing hardware; and   memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:
 receiving a web page; 
 extracting, from the web page, a client-side expression that implements client-side templating; 
 generating an attack payload for at least one injection vulnerability context of the web page based on the client-side expression; 
 instrumenting the web page to inject the attack payload into the at least one injection vulnerability context of the web page; 
 executing the instrumented web page; 
 determining an exception generated during execution of the instrumented web page; and 
 in response to determining the exception generated during execution of the instrumented web page, identifying a vulnerability of the web page. 
   
     
     
         12 . The system of  claim 11 , wherein receiving the web page comprises:
 receiving a web page request for the web page; and   retrieving the requested web page.   
     
     
         13 . The system of  claim 11 , wherein instrumenting the web page comprises injecting the attack payload into one or more possible input vectors associated with the at least one injection vulnerability context. 
     
     
         14 . The system of  claim 11 , wherein determining the exception generated during execution of the instrumented web page comprises catching a thrown exception triggered by the attack payload during execution of the instrumented web page. 
     
     
         15 . The system of  claim 11 , wherein the operations further comprise, modifying an exception handler of an interpreted programming language framework to intercept the exception. 
     
     
         16 . The system of  claim 11 , wherein the exception comprises a syntax exception. 
     
     
         17 . The system of  claim 11 , wherein the attack payload comprises a validation function configured to validate execution of the validation function. 
     
     
         18 . The system of  claim 17 , wherein the operations further comprise:
 catching a response of the validation function triggered by the attack payload during execution of the instrumented web page; and   identifying a second vulnerability of the web page based on the response.   
     
     
         19 . The system of  claim 11 , wherein generating the attack payload for the at least one injection vulnerability context of the web page based on the client-side expression comprises extracting a version of an interpreted programming language framework and an interpolation sign from the web page. 
     
     
         20 . The system of  claim 11 , wherein generating the attack payload comprises generating a single attack payload configured for instrumentation into the web page for each of one or more possible input vectors associated with the injection vulnerability context.

Join the waitlist — get patent alerts

Track US2023259637A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.