SCANTRAP: Protecting Content Management Systems from Vulnerability Scanners with Cyber Deception and Obfuscation

01/25/2023
by   Daniel Reti, et al.
0

Every attack begins with gathering information about the target. The entry point for network breaches are often vulnerabilities in internet facing websites, which often rely on an off-the-shelf Content Management System (CMS). Bot networks and human attackers alike rely on automated scanners to gather information about the CMS software installed and potential vulnerabilities. To increase the security of websites using a CMS, it is desirable to make the use of CMS scanners less reliable. The aim of this work is to extend the current knowledge about cyber deception in regard to CMS. To demonstrate this, a WordPress Plugin called 'SCANTRAP' was created, which uses simulation and dissimulation in regards to plugins, themes, versions, and users. We found that the resulting plugin is capable of obfuscating real information and to a certain extent inject false information to the output of one of the most popular WordPress scanners, WPScan, without limiting the legitimate functionality of the WordPress installation.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/27/2019

A Sweet Recipe for Consolidated Vulnerabilities: Attacking a Live Website by Harnessing a Killer Combination of Vulnerabilities

The recent emergence of new vulnerabilities is an epoch-making problem i...
research
12/15/2018

A Survey of Privacy Infrastructures and Their Vulnerabilities

Over the last two decades, the scale and complexity of Anonymous network...
research
05/23/2023

Understanding the Country-Level Security of Free Content Websites and their Hosting Infrastructure

This paper examines free content websites (FCWs) and premium content web...
research
12/16/2020

Investigating the Ecosystem of Offensive Information Security Tools

The internet landscape is growing and at the same time becoming more het...
research
12/13/2018

A Demand-Side Viewpoint to Software Vulnerabilities in WordPress Plugins

WordPress has long been the most popular content management system (CMS)...
research
02/28/2020

Supporting Early and Scalable Discovery of Disinformation Websites

Online disinformation is a serious and growing sociotechnical problem th...
research
05/18/2022

ExploitWP2Docker: a Platform for Automating the Generation of Vulnerable WordPress Environments for Cyber Ranges

A cyber range is a realistic simulation of an organization's network inf...

Please sign up or login with your details

Forgot password? Click here to reset