Two Novel Server-Side Attacks against Log File in Shared Web Hosting Servers

11/02/2018
by   Seyed Ali Mirheidari, et al.
0

Shared Web Hosting service enables hosting multitude of websites on a single powerful server. It is a well-known solution as many people share the overall cost of server maintenance and also, website owners do not need to deal with administration issues is not necessary for website owners. In this paper, we illustrate how shared web hosting service works and demonstrate the security weaknesses rise due to the lack of proper isolation between different websites, hosted on the same server. We exhibit two new server-side attacks against the log file whose objectives are revealing information of other hosted websites which are considered to be private and arranging other complex attacks. In the absence of isolated log files among websites, an attacker controlling a website can inspect and manipulate contents of the log file. These attacks enable an attacker to disclose file and directory structure of other websites and launch other sorts of attacks. Finally, we propose several countermeasures to secure shared web hosting servers against the two attacks subsequent to the separation of log files for each website.

READ FULL TEXT
research
11/02/2018

A Comprehensive Approach to Abusing Locality in Shared Web Hosting Servers

With the growing of network technology along with the need of human for ...
research
11/02/2018

Performance Evaluation of Shared Hosting Security Methods

Shared hosting is a kind of web hosting in which multiple websites resid...
research
06/14/2022

Random Access Concatenated Libraries and dd enable a short-latency high-content website on an inexpensive shared server

Content-rich websites typically house their images as individual files o...
research
01/18/2021

Leveraging AI to optimize website structure discovery during Penetration Testing

Dirbusting is a technique used to brute force directories and file names...
research
03/13/2019

Preventing the attempts of abusing cheap-hosting Web-servers for monetization attacks

Over the past decades, the web is always one of the most popular targets...
research
11/14/2017

Web Robot Detection in Academic Publishing

Recent industry reports assure the rise of web robots which comprise mor...

Please sign up or login with your details

Forgot password? Click here to reset