Never Trust Your Victim: Weaponizing Vulnerabilities in Security Scanners

06/17/2020
by   Andrea Valenza, et al.
0

The first step of every attack is reconnaissance, i.e., to acquire information about the target. A common belief is that there is almost no risk in scanning a target from a remote location. In this paper we falsify this belief by showing that scanners are exposed to the same risks as their targets. Our methodology is based on a novel attacker model where the scan author becomes the victim of a counter-strike. We developed a working prototype, called RevOK, and we applied it to 78 scanning systems. Out of them, 36 were found vulnerable to XSS. Remarkably, RevOK also found a severe vulnerability in Metasploit Pro, a mainstream penetration testing tool.

READ FULL TEXT

page 6

page 7

page 8

page 9

page 10

research
01/31/2023

Machine Learning and Port Scans: A Systematic Review

Port scanning is the process of attempting to connect to various network...
research
04/07/2020

Vulnerabilities Mapping based on OWASP-SANS: a Survey for Static Application Security Testing (SAST)

The delivery of a framework in place for secure application development ...
research
01/11/2021

Understanding the Quality of Container Security Vulnerability Detection Tools

Virtualization enables information and communications technology industr...
research
03/20/2023

A Comparative Analysis of Port Scanning Tool Efficacy

Port scanning refers to the systematic exploration of networked computin...
research
02/18/2023

Reproducing Random Forest Efficacy in Detecting Port Scanning

Port scanning is the process of attempting to connect to various network...
research
01/20/2021

Epidemic? The Attack Surface of German Hospitals during the COVID-19 Pandemic

In our paper we analyze the attack surface of German hospitals and healt...
research
12/28/2017

Modelling Noise-Resilient Single-Switch Scanning Systems

Single-switch scanning systems allow nonspeaking individuals with motor ...

Please sign up or login with your details

Forgot password? Click here to reset