L-WMxD: Lexical based Webmail XSS Discoverer

  • Zhushou Tang*
  • , Haojin Zhu
  • , Zhenfu Cao
  • , Shuai Zhao
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

11 Scopus citations

Abstract

XSS (Cross-Site Scripting) is a major security threat for web applications. Due to lack of source code of web application, fuzz technique has become a popular approach to discover XSS in web application except Webmail. This paper proposes a Webmail XSS fuzzer called L-WMxD (Lexical based Webmail XSS Discoverer). L-WMxD , which works on a lexical based mutation engine, is an active defense system to discover XSS before the Webmail application is online for service. The engine is initialized by normal JavaScript code called seed. Then, rules are applied to the sensitive strings in the seed which are picked out through a lexical parser. After that, the mutation engine issues multiple test cases. Newly-generated test cases are used for XSS test. Two prototype tools are realized by us to send the newly-generated test cases to various Webmail servers to discover XSS vulnerability. Experimental results of L-WMxD are quite encouraging. We have run L-WMxD over 26 real-world Webmail applications and found vulnerabilities in 21 Webmail services, including some of the most widely used Yahoo!Mail, Mirapoint Webmail and ORACLE' Collaboration Suite Mail.

Original languageEnglish
Title of host publication2011 IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2011
Pages976-981
Number of pages6
DOIs
StatePublished - 2011
Externally publishedYes
Event2011 IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2011 - Shanghai, China
Duration: 10 Apr 201115 Apr 2011

Publication series

Name2011 IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2011

Conference

Conference2011 IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2011
Country/TerritoryChina
CityShanghai
Period10/04/1115/04/11

Keywords

  • L-WMxD
  • Webmail
  • XSS
  • fuzzer

Fingerprint

Dive into the research topics of 'L-WMxD: Lexical based Webmail XSS Discoverer'. Together they form a unique fingerprint.

Cite this