Minimize Web Applications vulnerabilities through the early Detection of CRLF Injection
Carriage return (CR) and line feed (LF), also known as CRLF injection is a type of vulnerability that allows a hacker to enter special characters into a web application, altering its operation or confusing the administrator. Log poisoning and HTTP response splitting are two prominent harmful uses of...
Saved in:
Main Authors | , |
---|---|
Format | Journal Article |
Language | English |
Published |
04.03.2023
|
Subjects | |
Online Access | Get full text |
DOI | 10.48550/arxiv.2303.02567 |
Cover
Summary: | Carriage return (CR) and line feed (LF), also known as CRLF injection is a
type of vulnerability that allows a hacker to enter special characters into a
web application, altering its operation or confusing the administrator. Log
poisoning and HTTP response splitting are two prominent harmful uses of this
technique. Additionally, CRLF injection can be used by an attacker to exploit
other vulnerabilities, such as cross-site scripting (XSS). According to Open
Web Application Security Project (OWASP), CRLF vulnerabilities are among the
top 10 vulnerabilities and are a type of injection attack. Automated testing
can help to quickly identify CRLF vulnerabilities, and is particularly useful
for companies to test their applications before releasing them. However, CRLF
vulnerabilities foster a better approach to mitigate CRLF vulnerabilities in
the early stage and help secure applications against high-risk known
vulnerabilities. There has been less research on CRLF vulnerabilities and how
to detect them with automated testing. There is room for further research to be
done on this subject matter in order to develop creative solutions to problems.
It will also help to reduce false positive alerts by checking the header
response of each request. Security automation is an important issue for
companies trying to protect themselves against security threats. Automated
alerts from security systems can provide a quicker and more accurate
understanding of potential vulnerabilities and can help to reduce false
positive alerts. Despite the extensive research on various types of
vulnerabilities in web applications, CRLF vulnerabilities have only recently
been included in the research. Utilizing automated testing as a recurring task
can assist companies in receiving consistent updates about their systems and
enhance their security. |
---|---|
DOI: | 10.48550/arxiv.2303.02567 |