Race Condition Vulnerabilities in WordPress Plug-ins

被引:0
|
作者
Miyachi, Rin [1 ]
Nagashima, Konan [1 ]
Saito, Taiichi [1 ]
机构
[1] Tokyo Denki Univ, Senju Asahicho, Adachiku 1208551, Japan
关键词
Race Condition; TOCTOU; WordPress; Web Security;
D O I
10.1007/978-981-97-7737-2_10
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
WordPress is the world's most popular content management system, developed as an open-source software with many plugins. However, since these plugins are developed and released by anyone, they may have security problems. Web applications need to be designed and developed in consideration of possible race conditions that may occur when multiple processes access shared resources at the same time, but race conditions aren't paid much attention by developers and may result in vulnerability. This vulnerability is known to cause problems such as unauthorized data access, database inconsistency, and file content corruption by an attacker who intentionally creates a race condition. It is also considered that this vulnerability is not as well-known as XSS and SQLi. In this paper, we investigate the race condition vulnerabilities in WordPress plugins. Based on the results of this survey, we discuss the trends and causes of these vulnerabilities, as well as countermeasures for them.
引用
收藏
页码:179 / 194
页数:16
相关论文
共 50 条
  • [31] Plug-ins: Use 'em or lose 'em
    Abernathy, DJ
    TRAINING & DEVELOPMENT, 1998, 52 (07): : 20 - 21
  • [32] 3D plug-ins proliferate
    Forcade, T
    COMPUTER GRAPHICS WORLD, 1997, 20 (02) : 32 - &
  • [33] Software Plug-ins for Flexible Test Cell Automation
    Forster, Nathan D.
    Downing, Walter D.
    2015 IEEE AUTOTESTCON, 2015, : 103 - 107
  • [34] SAR processing system based on plug-ins architecture
    Wei, Liu
    Hai, Li
    ICEMI 2007: PROCEEDINGS OF 2007 8TH INTERNATIONAL CONFERENCE ON ELECTRONIC MEASUREMENT & INSTRUMENTS, VOL III, 2007, : 927 - +
  • [35] Plug-ins for critical media literacy: A collaborative program
    Robinson, A
    Nelson, E
    ONLINE, 2002, 26 (04): : 29 - 32
  • [36] PLUG-INS CUT NETWORKING COSTS FOR IBM PC
    SPADARO, JJ
    ELECTRONIC PRODUCTS MAGAZINE, 1986, 28 (22): : 17 - &
  • [37] MOODLE PLUG-INS FOR DESIGN AND DEVELOPMENT OF GAMIFIED COURSES
    Gachkova, Maria
    Somova, Elena
    14TH INTERNATIONAL TECHNOLOGY, EDUCATION AND DEVELOPMENT CONFERENCE (INTED2020), 2020, : 2187 - 2195
  • [38] A NEW SERIES OF PROGRAMMABLE SWEEP OSCILLATOR PLUG-INS
    HOLMLUND, GW
    ELMORE, GE
    WOOD, DC
    HEWLETT-PACKARD JOURNAL, 1982, 33 (02): : 11 - &
  • [39] Machine Learning Plug-ins for GNU Radio Companion
    Anil, R.
    Danymol, R.
    Gawande, Harsha
    Gandhiraj, R.
    2014 INTERNATIONAL CONFERENCE ON GREEN COMPUTING COMMUNICATION AND ELECTRICAL ENGINEERING (ICGCCEE), 2014,
  • [40] Generating Eclipse Editor Plug-Ins Using Tiger
    Biermann, Enrico
    Ehrig, Karsten
    Ermel, Claudia
    Taentzer, Gabriele
    APPLICATIONS OF GRAPH TRANSFORMATIONS WITH INDUSTRIAL RELEVANCE, 2008, 5088 : 583 - +