Method and system for detecting login request forgery vulnerability after third-party verification based on data flow analysis
The mini program client source code is obtained through data flow analysis method, the API parameters are identified and the interactive process diagram is constructed, which solves the problem of detecting vulnerabilities forging after login request in the existing technology, and realizes accurate vulnerability detection.
Patent Information
- Application Number
- CN202510756444.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-09
AI Technical Summary
The existing technology cannot effectively detect the vulnerability of login request forgery in the mini program after third-party verification, especially in static analysis of javascript code, it is difficult to deal with problems such as callback functions, client-server interaction modeling, webpack packaging and inter-process calls.
Using a method based on data flow analysis, the mini program client source code is obtained, the KillWxapkg tool is used to decrypt and unpack, and it is converted into an abstract syntax tree (AST), the API parameters and data flow are identified, the client server interaction process diagram is constructed, and vulnerability detection is performed.
It realizes accurate callback function analysis, inter-process call analysis and server-side interaction modeling of the javascript code of the applet client, and can effectively detect the login request forgery vulnerabilities after third-party verification.
Smart Images

Figure CN120281578A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security vulnerability detection, and in particular relates to a method and system for detecting a forged post-third-party-verification login request vulnerability based on data flow analysis. Background Art
[0002] With the popularization of this new type of Web application, the mini-program, in major super applications, the number of WeChat mini-programs has exceeded 4 million, and the number of mini-programs across the network has exceeded 10 million. While bringing great convenience to users, mini-programs store or transmit a large amount of private and sensitive information of users, and most mini-programs also provide online recharge and shopping consumption services. Once a security problem occurs in a mini-program, it will cause serious harm.
[0003] However, research has found that there is a vulnerability of forged post-third-party-verification login requests in the mini-program ecosystem, and the vulnerability occurs in the super-application authorization login scenario of mini-programs. The normal third-party verification login process is as Figure 1 shown. After a mini-program clicks a button similar to "One-click Login with WeChat Mobile Phone Number", the mini-program calls the getPhoneNumber API provided by WeChat to obtain the ciphertext of the mobile phone number bound to the user by WeChat, and then sends this ciphertext to the mini-program server. The mini-program server applies to WeChat for a key to decrypt the ciphertext, obtains the plaintext of the mobile phone number, queries the user status according to the plaintext of the mobile phone number, and returns the token corresponding to the mobile phone number to the mini-program client. However, a large number of developers have weak security awareness and use incorrect processes, resulting in a vulnerability of forged post-third-party-verification login requests. The login process with this vulnerability is as Figure 2 shown. After the mini-program server decrypts to obtain the plaintext, it wrongly returns the mobile phone number to the client, and wrongly uses the mobile phone number returned to the client to send a login request. Since an attacker can tamper with and forge the post-third-party-verification login request, forge a request to be sent with the mobile phone number of the victim, obtain the user token of the victim, and finally log in to the victim's account.
[0004] One of the prior arts first retrieves the to-be-tested mini-program according to the name of the to-be-tested mini-program and its APPID, obtains the static matching source code, extracts the key string code segments, and performs a security risk assessment on the key string code segments. Then, a simulated click operation is performed on the mini-program, and a vulnerability scanner is started to perform vulnerability scanning. However, this method does not support callback function processing and client-server interaction modeling. Another prior art converts the front-end source code of the mini-program into a code property graph, and then queries and matches the code segments containing known vulnerability features in the code property graph to detect vulnerabilities. A third prior art obtains the mini-program link by injecting a proxy Agent into the host program, and calls the tool android-detection-tools to perform security detection according to the obtained mini-program link. It is difficult to perform high-coverage testing on the mini-program only based on the obtained link. A fourth prior art requires manual in-depth reverse analysis of the host programs (WeChat, Alipay), selects effective positions for hooking, and solves the problems of difficult information acquisition and control of mini-program page jump navigation during the testing process. However, the encryption and obfuscation algorithms of application programs such as WeChat and Alipay are becoming more and more complex, and it is very complicated to perform reverse analysis on them manually. None of the above prior arts can detect the forged vulnerability of the login request after third-party verification. A fifth prior art proposes a cross-page request forgery vulnerability of a mini-program, a cross-page request forgery vulnerability based on CodeQl. However, since CodeQl does not support the inter-procedural call analysis of mini-program javascript, it cannot detect the forged vulnerability of the login request after third-party verification.
[0005] It can be seen that the existing methods cannot solve the problems in the static analysis of mini-program javascript code, such as callback function processing, client-server interaction modeling, webpack packaged code analysis, and inter-procedural calls, and face great challenges in detecting the forged vulnerability of the login request after third-party verification. Summary of the Invention
[0006] The present invention is directed to the authorization login scenario of the mini-program ecosystem, and discloses a detection scheme for the forged vulnerability of the login request after third-party verification based on data flow analysis, aiming to solve the technical problems that the existing mini-program vulnerability detection methods are difficult to model the inclusion of javascript files, callback functions, webpack packaging, inter-procedural calls, and the interaction process between the mini-program client and the server, resulting in the inability to accurately detect the forged vulnerability of the login request after third-party verification of the mini-program.
[0007] In the first aspect of the present invention, a detection method for the forged vulnerability of the login request after third-party verification based on data flow analysis is proposed. The method includes: Step S1, call the first module, and the first module is configured to execute: obtain the client source code of the to-be-tested mini-program; specifically including: Collect various mini-programs to construct a mini-program dataset to be tested; use a mini-program front-end code decompilation tool to automatically decrypt and unpack the wxapkg encrypted package of the front-end of the mini-program to be tested, so as to obtain the front-end source code file of the mini-program to be tested; Step S2: Invoke the second module, where the second module is configured to execute: Detect the vulnerability of forging a third-party verified login request based on data flow analysis according to the source code of the mini-program client to be tested; specifically including: Perform data flow analysis on the front-end source code file of each mini-program to be tested by using an AST-based data flow analysis method; identify the API parameters used in the third-party verification login process as data sources and analyze the data flow therein; perform interactive modeling on the client and server of the mini-program to be tested to obtain an interactive process diagram between the client and server of the mini-program to be tested, and perform detection of the vulnerability of forging a third-party verified login request.
[0008] According to the method of the first aspect of the present invention, in step S1, the first module obtains the source code of the mini-program client to be tested; wherein: The source code of the mini-program client to be tested is encrypted and stored in a specific directory of the client computer. Invoke the KillWxapkg[] tool to decrypt, unpack and decompile the wxapkg encrypted package of the front-end of each mini-program in the mini-program dataset to be tested, so as to obtain the front-end source code file of the mini-program to be tested as the source code of the mini-program client to be tested; send the client source code of each mini-program to be tested to the second module to perform subsequent vulnerability detection.
[0009] According to the method of the first aspect of the present invention, in step S2, the second module detects the vulnerability of forging a third-party verified login request; wherein, perform data flow analysis on the front-end source code file of each mini-program to be tested by using an AST-based data flow analysis method to identify the API parameters used in the third-party verification login process as data sources; specifically including: Perform data source identification and positioning through collaborative analysis of the logic layer and the rendering layer, and convert the javascript code and wxml file of the mini-program to be tested into an abstract syntax tree AST; Extract the function with the function name getPhoneNumber from the abstract syntax tree AST of the javascript code; if the extraction is successful, identify the API parameters of the corresponding function as the data source; if the extraction is unsuccessful, extract the event function name that binds the getPhoneNumber API from the abstract syntax tree AST of the wxml file, and extract the function with the corresponding function name from the abstract syntax tree AST of the javascript code according to the event function name, and identify its API parameters as the data source.
[0010] According to the method of the first aspect of the present invention, in step S2, the second module detects the vulnerability of forged login requests after third-party verification; wherein, the data flow is analyzed; specifically including: Construct corresponding file contexts, object contexts, and function contexts for files, objects, and functions in JavaScript respectively; Take each JavaScript file included by the require function in the JavaScript language as a sub-file context, extract all the functions defined therein and save them in a function table; When analyzing a function call, determine whether there is a function declaration with the same name in the function table; if so, enter the corresponding function declaration part and perform inter-procedural call analysis, and determine the variables to be traced in the function declaration part according to the parameter positions of the traced variables in the function call; When analyzing a variable assignment, if the right side is a traced variable, add the variable assigned on the left side to the traced variable set; When analyzing that a traced variable is assigned to a corresponding property, keep the assigned object property in the traced variable set.
[0011] According to the method of the first aspect of the present invention, in step S2, the second module detects the vulnerability of forged login requests after third-party verification; wherein, an interaction model is built for the client and server of the to-be-tested applet to obtain an interaction process diagram between the client and server of the to-be-tested applet; specifically including: According to the characteristics of the HTTP request functions in the applet JavaScript code, analyze the function call expressions in the data flow, identify the HTTP request processing functions and callback functions, extract the HTTP request parameters, request responses, and operations performed on the request responses, so as to build an interaction process diagram between the client and server.
[0012] According to the method of the first aspect of the present invention, in step S2, the second module detects the vulnerability of forged login requests after third-party verification; wherein, the detection of the vulnerability of forged login requests after third-party verification is performed; specifically including: Based on the interaction process diagram, determine whether there is a situation where the HTTP request for verifying the mobile phone number returns the plaintext mobile phone number, and whether there is a situation where a subsequent request uses the response of the previous request as a parameter to send a login request. If at least one of the above two situations exists, there is a vulnerability of forged login requests after third-party verification, and output the interaction process diagram and the data flow analysis result to the analysis report.
[0013] The second aspect of the present invention proposes a system for detecting vulnerabilities of forged login requests after third-party verification based on data flow analysis. The system includes a first module and a second module; wherein: The first module is configured to perform: obtaining the source code of the mini-program client to be tested; specifically including: collecting various mini-programs to construct a data set of mini-programs to be tested; using a mini-program front-end code decompilation tool to automatically decrypt and unpack the wxapkg encrypted package of the front-end of the mini-program to be tested, so as to obtain the front-end source code file of the mini-program to be tested; The second module is configured to perform: detecting the vulnerability of forged third-party verification post-login requests based on data flow analysis according to the source code of the mini-program client to be tested; specifically including: performing data flow analysis on the front-end source code file of each mini-program to be tested by using a data flow analysis method based on AST; identifying the API parameters used in the third-party verification login process as data sources and analyzing the data flow therein; performing interaction modeling on the client and server of the mini-program to be tested to obtain an interaction process diagram between the client and server of the mini-program to be tested, and performing detection of the vulnerability of forged third-party verification post-login requests.
[0014] According to the system of the second aspect of the present invention, the source code of the mini-program client to be tested is obtained by the first module; wherein: The source code of the mini-program client to be tested is encrypted and stored in a specific directory of the client computer. The KillWxapkg[] tool is called to decrypt, unpack and decompile the wxapkg encrypted package of the front-end of each mini-program in the data set of mini-programs to be tested, so as to obtain the front-end source code file of the mini-program to be tested as the source code of the mini-program client to be tested; the source code of the client of each mini-program to be tested is sent to the second module to perform subsequent vulnerability detection.
[0015] A third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor. When the processor executes the computer program stored in the memory, the method for detecting the vulnerability of forged third-party verification post-login requests based on data flow analysis according to the first aspect of the present disclosure is implemented.
[0016] A fourth aspect of the present invention discloses a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the method for detecting the vulnerability of forged third-party verification post-login requests based on data flow analysis according to the first aspect of the present disclosure is implemented.
[0017] The technical effects brought by the present invention include: (1) the callback functions in the mini-program client javascript code can be accurately analyzed; (2) accurate inter-procedural call analysis can be performed on the mini-program client javascript code; (3) the interaction process between the mini-program client and server can be modeled; (4) the source code of the mini-program client packaged by webpack can be statically analyzed; (5) the vulnerability of forged third-party verification post-login requests in the mini-program ecosystem can be effectively detected. Description of the Drawings
[0018] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0019] Figure 1 It is a schematic diagram of a normal third-party verification login process.
[0020] Figure 2 It is a schematic diagram of a login process with vulnerabilities.
[0021] Figure 3 It is a flowchart for detecting vulnerabilities in forged login requests after third-party verification of applets according to an embodiment of the present invention.
[0022] Figure 4 It is a schematic diagram for detecting vulnerabilities in forged login requests after third-party verification based on data flow analysis according to an embodiment of the present invention.
[0023] Figure 5 It is a schematic diagram of the interaction process between the applet client and the server according to an embodiment of the present invention. Specific Embodiments
[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0025] The present invention proposes a detection scheme for vulnerabilities in forged login requests after third-party verification of applets based on data flow analysis. As Figure 3 shown, it mainly includes two modules for obtaining the source code of the applet client to be tested and detecting vulnerabilities in forged login requests after third-party verification based on data flow analysis (the first module and the second module respectively).
[0026] In the above solution, first, a large number of mini-programs are collected to construct a dataset of mini-programs to be tested. Then, an automated decryption and unpacking tool for the wxapkg encrypted package of the front-end of the mini-program to be tested is used to obtain the front-end source code file of the mini-program to be tested. Then, a data flow analysis method based on AST is used to perform data flow analysis on the front-end source code of each mini-program to be tested. Since it is for detecting the vulnerability of forged login requests after third-party verification, it is necessary to first identify the API (getPhoneNumber) parameters used in the third-party verification login process as the data source, and then analyze the flow of this data, model the client-server interaction, obtain the client-server interaction process diagram of the mini-program, and finally perform the detection of the vulnerability of forged login requests after third-party verification.
[0027] 1. Obtaining the source code of the client of the mini-program to be tested The module for obtaining the source code of the client of the mini-program to be tested (the first module) proposed by the present invention is used to construct a dataset of mini-programs to be tested and collect the source code of the client of the mini-program to be tested. The client source code of the WeChat mini-program is encrypted and stored in a specific directory of the client computer. After decrypting and decompiling the wxapkg encrypted file of each mini-program in the dataset of mini-programs to be tested by using the KillWxapkg[] tool, the source code of the mini-program to be tested can be obtained. The client source code of each mini-program is provided to the module for detecting the vulnerability of forged login requests after third-party verification based on data flow analysis for vulnerability detection.
[0028] 2. Detection of the vulnerability of forged login requests after third-party verification based on data flow analysis The module for detecting the vulnerability of forged login requests after third-party verification based on data flow analysis (the second module) statically detects whether there is a vulnerability of forged login requests after third-party verification in the mini-program to be tested through steps such as data source identification and location, data flow analysis, client-server interaction modeling, and vulnerability detection, as Figure 4 shown.
[0029] First, data source identification and location are performed through collaborative analysis of the logic layer and the rendering layer. The javascript code and wxml file of the mini-program are converted into an abstract syntax tree (AST) for analysis. First, extract the function with the function name getPhoneNumber in the abstract syntax tree of the javascript code. If there is, identify the parameters of the corresponding function as the data source; if not, extract the name of the event function that binds the getPhoneNumber API in the abstract syntax tree of the wxml file, and extract the function with the corresponding function name in the abstract syntax tree of the javascript code according to the event function name, and identify its parameters as the data source.
[0030] After that, use the context-based data flow analysis method to analyze the data flow. For files, objects, and functions in JavaScript, construct corresponding file contexts, object contexts, and function contexts respectively. Process the file inclusion feature of functions such as require in the JavaScript language, take each included JavaScript file as a sub-file context, and extract all defined functions and save them in the function table. When analyzing a function call, determine whether there is a function declaration with the same name in the function table. If so, enter the declaration part of the corresponding function for inter-procedural call analysis, and decide which variables to trace in the function declaration part according to the parameter positions of the traced variables in the function call. When analyzing a variable assignment, if the right side is a traced variable, add the variable assigned on the left side to the traced variable set as well. When analyzing that a traced variable is assigned to a corresponding property, and when making a method call on the object, keep the assigned object property in the traced variable set.
[0031] Then, perform mini-program client-server interaction modeling. By analyzing and processing the HTTP request function, model the client-server interaction process diagram. According to the characteristics of the HTTP request function in the mini-program JavaScript code, analyze the function call expressions in the obtained data flow, identify the HTTP request handling function and its callback function, extract the HTTP request parameters and request responses, and the operations performed on the request responses. Construct the client-server interaction process diagram, as Figure 5 shown.
[0032] Finally, perform third-party verification and then detect the vulnerability of forged login requests in the post-login request forgery detection module. By judging through the generated mini-program client-server interaction process diagram, check whether there is an HTTP request for verifying the mobile phone number that returns the plaintext mobile phone number, and whether there is a subsequent request that uses the response of the previous request as a parameter to send a login request. If so, there may be a vulnerability of forged post-login requests after third-party verification. Output the mini-program client-server interaction process diagram and the data flow analysis results to the analysis report.
[0033] It can be seen that the present invention can model the callback functions, file inclusion (require), webpack-packaged code, inter-procedural calls, and mini-program client-server interaction processes of mini-program JavaScript client code, and thus effectively detect the vulnerability of forged post-login requests after third-party verification in the third-party authorization login scenario in the mini-program ecosystem.
[0034] In some embodiments, the data source location based on the collaborative analysis of the logic layer and the rendering layer includes: converting the JavaScript code and wxml files of the applet into an Abstract Syntax Tree (AST) for analysis. First, extract the function with the function name getPhoneNumber from the abstract syntax tree of the JavaScript code. If any, identify the parameters of the corresponding function as the data source; if not, extract the event function name that binds the getPhoneNumber API from the abstract syntax tree of the wxml file, and extract the function with the corresponding function name from the abstract syntax tree of the JavaScript code according to the event function name, and identify its parameters as the data source.
[0035] In some embodiments, the context-based data flow analysis includes: constructing corresponding contexts for files, objects, and functions in JavaScript respectively. For the file inclusion feature of functions such as require, each included JavaScript file is used as a sub-file context, and all defined functions are extracted and saved in a function table. When analyzing a function call, if there is a function declaration with the same name in the function table, enter the declaration part of the function for inter-procedural call analysis. Determine which variables to trace in the function declaration part according to the parameter positions of the traced variables in the function call. When analyzing a variable assignment, if the right side is a traced variable, add the variable assigned on the left side to the set of traced variables. When analyzing that a traced variable is assigned to a corresponding property, when making a method call on an object, keep the assigned object property in the set of traced variables.
[0036] In some embodiments, the client-server interaction modeling includes: identifying the HTTP request functions in the analyzed data flow according to the characteristics of the HTTP request functions in the applet, and processing the callback functions, extracting the HTTP request parameters and responses, and the operations of the client on the HTTP response, and constructing a client-server interaction process diagram according to the timing. The process diagram can accurately model the interaction process between the client and the server, accurately depict the client-server interaction process, and can effectively determine whether there is a vulnerability of forged third-party verification login request in the applet to be tested according to the interaction process diagram.
[0037] In summary, the technical solution disclosed by the present invention solves the technical problems that it is difficult to model the inclusion (require) of JavaScript language files, callback functions, webpack packaging, inter-procedural calls, and the interaction process between the applet client and the server in the existing applet static detection method. The present invention can effectively detect the vulnerability of forged login requests after third-party verification in the applet ecosystem. The specific technical effects include: (1) accurately analyzing the callback functions in the applet client JavaScript code; (2) accurately performing inter-procedural call analysis on the applet client JavaScript code; (3) modeling the interaction process between the applet client and the server; (4) statically analyzing the applet client source code packaged with webpack; (5) effectively detecting the vulnerability of forged login requests after third-party verification in the applet ecosystem.
[0038] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification. The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A method for detecting the vulnerability of forged third-party verified login requests based on data flow analysis, characterized in that The method includes: Step S1: Invoke the first module, which is configured to execute: Obtain the source code of the client of the mini program to be tested; specifically including: Collect various mini programs to construct a dataset of mini programs to be tested; Use a mini program front-end code decompilation tool to automatically decrypt and unpack the wxapkg encrypted package of the front-end of the mini program to be tested, so as to obtain the front-end source code file of the mini program to be tested; Step S2: Invoke the second module, which is configured to execute: Detect the vulnerability of forging a post-third-party-verification login request based on data flow analysis according to the source code of the client of the mini program to be tested; specifically including: Perform data flow analysis on the front-end source code file of each mini program to be tested by using the AST-based data flow analysis method; Identify the API parameters used in the third-party verification login process as data sources and analyze the data flow therein; Build an interaction model between the client and the server of the mini program to be tested to obtain an interaction process diagram between the client and the server of the mini program to be tested, and perform the detection of the vulnerability of forging a post-third-party-verification login request.
2. The method for detecting the vulnerability of forged third-party verified login requests based on data flow analysis according to claim 1, characterized in that, In step S1, the first module obtains the source code of the client of the mini program to be tested; wherein: The source code of the client of the mini program to be tested is encrypted and stored in a specific directory of the client computer. Invoke the KillWxapkg[] tool to decrypt, unpack and decompile the wxapkg encrypted package of the front-end of each mini program in the dataset of mini programs to be tested, so as to obtain the front-end source code file of the mini program to be tested, which is used as the source code of the client of the mini program to be tested; Send the source code of the client of each mini program to be tested to the second module to perform subsequent vulnerability detection.
3. The method for detecting the vulnerability of forged third-party verified login requests based on data flow analysis according to claim 2, wherein, In step S2, the second module detects the vulnerability of forging a post-third-party-verification login request; wherein, perform data flow analysis on the front-end source code file of each mini program to be tested by using the AST-based data flow analysis method to identify the API parameters used in the third-party verification login process as data sources; specifically including: Locate the data source through collaborative analysis of the logic layer and the rendering layer, and convert the javascript code and wxml file of the mini program to be tested into an abstract syntax tree AST; Extract the function with the function name getPhoneNumber from the abstract syntax tree AST of the javascript code; If the extraction is successful, identify the API parameters of the corresponding function as the data source; If the extraction is unsuccessful, extract the event function name that binds the getPhoneNumber API from the abstract syntax tree AST of the wxml file, and extract the function with the corresponding function name from the abstract syntax tree AST of the javascript code according to the event function name, and identify its API parameters as the data source.
4. A method for detecting a vulnerability of forged third-party verified login requests based on data flow analysis according to claim 3, characterized in that, In step S2, the second module detects the vulnerability of forging a post-third-party-verification login request; wherein, analyze the data flow; specifically including: Construct corresponding file contexts, object contexts, and function contexts for files, objects, and functions in javascript respectively; Take each JavaScript file included by the require function in the JavaScript language as a sub-file context, extract all the functions defined in it, and save them in a function table; When a function call is analyzed, determine whether there is a function declaration with the same name in the function table; if it exists, enter the corresponding function declaration part and perform inter-procedural call analysis, and determine the variables to be traced in the function declaration part according to the parameter positions of the traced variables in the function call; When a variable assignment is analyzed, if the right side is a traced variable, add the variable assigned on the left side to the traced variable set; When a traced variable is assigned to a corresponding property, keep the assigned object property in the traced variable set.
5. A method for detecting a vulnerability of forged third-party verified login requests based on data flow analysis according to claim 4, characterized in that, In step S2, the second module detects the vulnerability of forged login requests after third-party verification; specifically, model the interaction between the client and the server of the to-be-tested applet to obtain the interaction process diagram between the client and the server of the to-be-tested applet; specifically include: According to the characteristics of the HTTP request function in the applet JavaScript code, analyze the function call expressions in the data stream, identify the HTTP request handling function and the callback function, extract the HTTP request parameters, request responses, and operations performed on the request responses, so as to construct the interaction process diagram between the client and the server.
6. A method for detecting a vulnerability of forged post-authentication login requests based on data flow analysis according to claim 5, characterized in that, In step S2, the second module detects the vulnerability of forged login requests after third-party verification; specifically, perform the detection of the vulnerability of forged login requests after third-party verification; specifically include: Based on the interaction process diagram, determine whether there is a situation where the HTTP request for verifying the mobile phone number returns the plaintext mobile phone number, and whether there is a situation where the subsequent request uses the response of the previous request as a parameter to send a login request. If at least one of the above two situations exists, there is a vulnerability of forged login requests after third-party verification, and output the interaction process diagram and the data flow analysis results to the analysis report.
7. A third-party verified login request forgery vulnerability detection system based on data flow analysis, characterized in that, The system includes a first module and a second module; wherein: The first module is configured to execute: obtain the source code of the client of the to-be-tested applet; specifically include: collect various applets to construct a data set of to-be-tested applets; use the applet front-end code decompilation tool to automatically decrypt and unpack the wxapkg encrypted package of the front-end of the to-be-tested applet to obtain the front-end source code file of the to-be-tested applet; The second module is configured to execute: based on the source code of the client of the to-be-tested applet, detect the vulnerability of forged login requests after third-party verification based on data flow analysis; specifically include: perform data flow analysis on the front-end source code file of each to-be-tested applet by using the data flow analysis method based on AST; identify the API parameters used in the third-party verification login process as data sources, and analyze the data flow therein; model the interaction between the client and the server of the to-be-tested applet to obtain the interaction process diagram between the client and the server of the to-be-tested applet, and perform the detection of the vulnerability of forged login requests after third-party verification.
8. A third-party verified post-login request forgery vulnerability detection system based on data flow analysis according to claim 7, characterized in that, The first module obtains the source code of the client of the to-be-tested applet; wherein: The source code of the mini-program under test is encrypted and stored in a specific directory of the client computer. The KillWxapkg[] tool is called to decrypt, unpack, and decompile the wxapkg encrypted package of the front-end of each mini-program in the mini-program dataset under test, so as to obtain the front-end source code file of the mini-program under test, which serves as the source code of the mini-program client under test. The source code of the client of each mini-program under test is sent to the second module to perform subsequent vulnerability detection.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, it implements a method for detecting third-party verification post-login request forgery vulnerabilities based on data flow analysis according to any one of claims 1-6.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, it implements a method for detecting third-party verification post-login request forgery vulnerabilities based on data flow analysis according to any one of claims 1-6.
Citation Information
Patent Citations
MIPS architecture vulnerability mining method based on control flow and data flow analysis
CN113497809A
Application software security evaluation method and device based on OTT and IPTV platforms
CN114936367A
Application security test method and system integrated with black, white and grey security detection technology
CN115952503A
LLM Agent-based Web application vulnerability dynamic detection method and system
CN118761060A
Semantic enhanced embedded firmware static analysis method and device
CN118862068A
Cited By
GUI (Graphical User Interface) agent-based applet vulnerability detection method and device, electronic equipment and storage medium
CN122027257A
Method, apparatus, electronic device and storage medium for detecting vulnerabilities in mini-programs based on GUI intelligent agents.
CN122027257B