New debugging method found undetected security flaws in popular web apps
news.mit.edu
news.mit.edu
* Did they find a kind of security flaw that is particularly difficult to detect? Like, reliable generic authorization bypass detection result would be novel.
* Did they find 23 flaws in popular and important Rails apps? Those applications have probably been tested extensively already, and new results are interesting. Random e-commerce applications buried in Github, less so.
* How severe were the flaws? Security flaws range from remote code execution on the very damaging side to version information disclosure on the marginal side.
The thesis isn't linked on the site but I found it here [0] http://www.cs.berkeley.edu/~jnear/ [1] https://dspace.mit.edu/handle/1721.1/99841
Definitely worth a skim in my opinion.
Based on the paper, he performed two separate experiments.
For one of them, he chose the 50 most popular Rails projects on Github. Of these, 30 of them used a permission model that could be handled by his tools. The 23 flaws reported were among these 30 apps, with Diaspora being notable among those.
He also worked with a professor to test student submissions for an access-control assignment in a web development course at MIT. He uncovered security vulnerabilities in "over half of these projects" and "about half of those bugs were missed during manual grading."
http://www.cs.berkeley.edu/~jnear/derailer/
"Derailer uses an automatic static analysis to produce a visual representation of the information flows within a Ruby on Rails web application. The visualization organizes the results of the analysis in a tree, with the goal of helping the user to quickly find the most sensitive information flows, and also allows the user to filter the set of flows based on the conditions under which they occur."
http://www.cs.berkeley.edu/~jnear/rubicon/
"Rubicon is a library for Ruby, Rails, and RSpec that lets you write formal specifications of the behavior of your web apps. In addition to the standard RSpec language, Rubicon gives you the quantifiers of first-order logic, so your specifications cover all possible objects of the given type, and mock objects are no longer needed. "
http://www.cs.berkeley.edu/~jnear/space/
"SPACE is a specification-free tool for finding missing security checks in Ruby on Rails web applications using a catalog of access control patterns in which each pattern models a common access control use case. SPACE checks that for every kind of data exposure allowed by an application's code, some security pattern in our catalog also allows the exposure. The user provides a mapping from application types to the types of our catalog, and then SPACE identifies security bugs automatically."
The paper referenced:
https://dspace.mit.edu/bitstream/handle/1721.1/99841/9274107...
Rails?
Such a tool might have been useful ten years ago but today?
Derailer's last commit is from Jan 29 2014 so it's another dead project. Too bad because it could be interesting. However, did anybody understand what to do with its output? Example: how do I use http://people.csail.mit.edu/jnear/derailer/example1/ to assess the security of the application?
Ruby on Rails — or Rails, as it’s called for short — has the peculiarity of defining even its most basic operations in libraries. Every addition, every assignment of a particular value to a variable, imports code from a library.
Tool link: https://overseer.fallible.co (I doubt people will be okay with installing our certificate, but just in case someone wants to use a hosted version)
Injection vulnerabilities (XSS, SQLI etc.) are out of the scope of this document/toolset, it's heavily designed for detect ACL issues in web applications.
Come on, MIT, you can do better!