Detecting Injection Vulnerabilities of Client-Side Templating Systems
Abstract
A method for detecting an injection vulnerability of a client-side templating system includes receiving a web page, determining that the web page implements an interpreted programming language framework with client-side templating, and extracting a version of the interpreted programming language framework and an interpolation sign from the web page. The method also includes generating an attack payload for at least one injection vulnerability context of the web page based on the version of the interpreted programming language framework and the interpolation sign, instrumenting the web page to inject the attack payload into the at least one injection vulnerability context of the web page, and executing the instrumented web page.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method executed by data processing hardware that causes the data processing hardware to perform operations comprising:
receiving a web page; extracting, from the web page, a client-side expression that implements client-side templating; generating an attack payload for at least one injection vulnerability context of the web page based on the client-side expression; instrumenting the web page to inject the attack payload into the at least one injection vulnerability context of the web page; executing the instrumented web page; determining an exception generated during execution of the instrumented web page; and in response to determining the exception generated during execution of the instrumented web page, identifying a vulnerability of the web page.
2 . The method of claim 1 , wherein receiving the web page comprises:
receiving a web page request for the web page; and retrieving the requested web page.
3 . The method of claim 1 , wherein instrumenting the web page comprises injecting the attack payload into one or more possible input vectors associated with the at least one injection vulnerability context.
4 . The method of claim 1 , wherein determining the exception generated during execution of the instrumented web page comprises catching a thrown exception triggered by the attack payload during execution of the instrumented web page.
5 . The method of claim 1 , wherein the operations further comprise, modifying an exception handler of an interpreted programming language framework to intercept the exception.
6 . The method of claim 1 , wherein the exception comprises a syntax exception.
7 . The method of claim 1 , wherein the attack payload comprises a validation function configured to validate execution of the validation function.
8 . The method of claim 7 , wherein the operations further comprise:
catching a response of the validation function triggered by the attack payload during execution of the instrumented web page; and identifying a second vulnerability of the web page based on the response.
9 . The method of claim 1 , wherein generating the attack payload for the at least one injection vulnerability context of the web page based on the client-side expression comprises extracting a version of an interpreted programming language framework and an interpolation sign from the web page.
10 . The method of claim 1 , wherein generating the attack payload comprises generating a single attack payload configured for instrumentation into the web page for each of one or more possible input vectors associated with the injection vulnerability context.
11 . A system comprising:
data processing hardware; and memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:
receiving a web page;
extracting, from the web page, a client-side expression that implements client-side templating;
generating an attack payload for at least one injection vulnerability context of the web page based on the client-side expression;
instrumenting the web page to inject the attack payload into the at least one injection vulnerability context of the web page;
executing the instrumented web page;
determining an exception generated during execution of the instrumented web page; and
in response to determining the exception generated during execution of the instrumented web page, identifying a vulnerability of the web page.
12 . The system of claim 11 , wherein receiving the web page comprises:
receiving a web page request for the web page; and retrieving the requested web page.
13 . The system of claim 11 , wherein instrumenting the web page comprises injecting the attack payload into one or more possible input vectors associated with the at least one injection vulnerability context.
14 . The system of claim 11 , wherein determining the exception generated during execution of the instrumented web page comprises catching a thrown exception triggered by the attack payload during execution of the instrumented web page.
15 . The system of claim 11 , wherein the operations further comprise, modifying an exception handler of an interpreted programming language framework to intercept the exception.
16 . The system of claim 11 , wherein the exception comprises a syntax exception.
17 . The system of claim 11 , wherein the attack payload comprises a validation function configured to validate execution of the validation function.
18 . The system of claim 17 , wherein the operations further comprise:
catching a response of the validation function triggered by the attack payload during execution of the instrumented web page; and identifying a second vulnerability of the web page based on the response.
19 . The system of claim 11 , wherein generating the attack payload for the at least one injection vulnerability context of the web page based on the client-side expression comprises extracting a version of an interpreted programming language framework and an interpolation sign from the web page.
20 . The system of claim 11 , wherein generating the attack payload comprises generating a single attack payload configured for instrumentation into the web page for each of one or more possible input vectors associated with the injection vulnerability context.Join the waitlist — get patent alerts
Track US2023259637A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.