IP Library Granted Patent US 8,239,952
Granted Patent B1
US 8,239,952 · App. 12/024,935 · Granted Aug 7, 2012

Method and system for detection of remote file inclusion vulnerabilities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,239,952
App. No.
12/024,935
Granted
Aug 7, 2012
Kind
B1
Abstract

A method for detecting remote file inclusion vulnerabilities in a web application includes altering of extracted resource references from a web application, submission of altered references as HTTP requests to the web application, inspection of corresponding HTTP responses, and diagnosis of vulnerability. A system of invention implements the method.

Claims (20)

1. A method for identifying a vulnerability of a web application, comprising:

extracting a resource reference from a web application;

altering the extracted reference by supplying a uniform resource locator (URL) that references one of a plurality of entries in a repository;

sending the altered reference to the web application;

providing executable code for remote file inclusion within each of the plurality of entries in the repository, wherein the executable code within each of the plurality of entries instructs an interpreter of a different programming language to generate a signature; and

inspecting a response from the web application for presence of the signature to determine whether the web application executed the executable code, wherein the signature is unique for a given programming language.

2. A method according to claim 1 , wherein presence of the unique signature indicates that the web application employs an interpreter for a programming language corresponding to the unique signature.

3. A method according to claim 1 , further comprising identifying an injection point of the web application to be utilized in the act of sending the altered reference to the web application.

4. A method according to claim 3 , wherein the act of sending the altered reference to the web application comprises constructing an HTTP request based on the identified injection point having the altered reference.

5. A method according to claim 1 , wherein the act of sending the altered reference to the web application comprises constructing an HTTP request having the altered reference.

6. A method according to claim 1 , wherein the acts of altering the extracted reference and sending the altered reference to the web application are repeated for each of the plurality of entries in the repository.

7. A method according to claim 6 , wherein presence of the signature that is unique for a given programming language in the response indicates that the web application employs an interpreter for the given programming language.

8. A system for identifying a vulnerability of a web application, comprising:

a vulnerability detector that is adapted to extract a resource reference from the web application, alter the extracted reference, and send the altered reference to the web application;

a repository that stores executable code within a plurality of entries that are capable of being referenced by a uniform resource locator (URL) supplied as part of the altered reference, wherein the executable code within each of the plurality of entries instructs an interpreter of a different programming language to generate a signature,

wherein the vulnerability detector is further adapted to inspect a response from the web application for presence of the signature to determine whether the web application executed the executable code, wherein the signature is unique for a given programming language.

9. A system according to claim 8 , wherein presence of the unique signature indicates that the web application employs an interpreter for a programming language corresponding to the unique signature.

10. A system according to claim 8 , wherein the vulnerability detector is further adapted to identify an injection point of the web application to be utilized to send the altered reference to the web application.

11. A system according to claim 10 , wherein sending the altered reference to the web application comprises constructing an HTTP request based on the identified injection point having the altered reference.

12. A system according to claim 8 , wherein sending the altered reference to the web application comprises constructing an HTTP request having the altered reference.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →