Skip to content
PatentGenius

United States Patent

US Patent 8239952: Method and system for detection of remote file…

US 8239952  ·  granted 2012-08-07

Abstract

A method for detecting remote file inclusion vulnerabilities in a web application includes altering of extracted resource references from a web application, submission of altered references as HTTP requests to the web application, inspection of corresponding HTTP responses, and diagnosis of vulnerability. A system of invention implements the method.

Patent Number 8239952
Title Method and system for detection of remote file inclusion vulnerabilities
Filed 2008-02-01
Granted 2012-08-07
Inventor(s) Oliphant; Brett, Tyler; Ben, Pack; Gabriel Richard, Hardin; Brett
Assignee McAfee, Inc.
CPC Classification G06F 11/36, G06F 12/14, G08B 23/00
Number of Claims 28

Abstract

A method for detecting remote file inclusion vulnerabilities in a web application includes altering of extracted resource references from a web application, submission of altered references as HTTP requests to the web application, inspection of corresponding HTTP responses, and diagnosis of vulnerability. A system of invention implements the method.

Claim 1

A method for identifying a vulnerability of a web application, comprising: extracting a resource reference from a web application; altering the extracted reference bysupplying a uniform resource locator (URL) that references one of a plurality of entries in a repository; sending the altered reference to the web application; providing executable code for remote file inclusion within each of the plurality of entriesin the repository, wherein the executable code within each of the plurality of entries instructs an interpreter of a different programming language to generate a signature; and inspecting a response from the web application for presence of the signatureto determine whether the web application executed the executable code, wherein the signature is unique for a given programming language.

Claims

28 total

A method for identifying a vulnerability of a web application, comprising: extracting a resource reference from a web application; altering the extracted reference bysupplying a uniform resource locator (URL) that references one of a plurality of entries in a repository; sending the altered reference to the web application; providing executable code for remote file inclusion within each of the plurality of entriesin the repository, wherein the executable code within each of the plurality of entries instructs an interpreter of a different programming language to generate a signature; and inspecting a response from the web application for presence of the signatureto determine whether the web application executed the executable code, wherein the signature is unique for a given programming language.