A Comprehensive Approach to Abusing Locality in Shared Web Hosting Servers

11/02/2018
by   Seyed Ali Mirheidari, et al.
0

With the growing of network technology along with the need of human for social interaction, using websites nowadays becomes critically important which leads in the increasing number of websites and servers. One popular solution for managing these large numbers of websites is using shared web hosting servers in order to decrease the overall cost of server maintenance. Despite affordability, this solution is insecure and risky according to high amount of reported defaces and attacks during recent years. In this paper, we introduce top ten most common attacks in shared web hosting servers which can occur because of the nature and bad configuration in these servers. Moreover, we present several simple scenarios that are capable of penetrating these kinds of servers even with the existence of several securing mechanisms. Finally, we provide a comprehensive secure configuration for confronting these attacks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/02/2018

Two Novel Server-Side Attacks against Log File in Shared Web Hosting Servers

Shared Web Hosting service enables hosting multitude of websites on a si...
research
11/01/2021

An Empirical Analysis of HTTPS Configuration Security

It is notoriously difficult to securely configure HTTPS, and poor server...
research
11/21/2022

A Tale of Frozen Clouds: Quantifying the Impact of Algorithmic Complexity Vulnerabilities in Popular Web Servers

Algorithmic complexity vulnerabilities are a class of security problems ...
research
08/09/2022

LinGBM: A Performance Benchmark for Approaches to Build GraphQL Servers (Extended Version)

GraphQL is a popular new approach to build Web APIs that enable clients ...
research
05/11/2019

HSTS Preloading is Ineffective as a Long-Term, Wide-Scale MITM-Prevention Solution: Results from Analyzing the 2013 - 2017 HSTS Preload List

HSTS (HTTP Strict Transport Security) serves to protect websites from ce...
research
03/13/2019

Preventing the attempts of abusing cheap-hosting Web-servers for monetization attacks

Over the past decades, the web is always one of the most popular targets...
research
06/15/2021

Snail Mail Beats Email Any Day: On Effective Operator Security Notifications in the Internet

In the era of large-scale internet scanning, misconfigured websites are ...

Please sign up or login with your details

Forgot password? Click here to reset