The invention provides a method and a
system for detecting a login request forgery
vulnerability after third-party
verification based on
data flow analysis, and belongs to the technical field of
network security vulnerability detection. And performing large-scale collection on the applets, constructing a to-be-tested applet
data set, performing automatic decryption and unpacking on the wxapkg encrypted packet at the front end of the to-be-tested applet by using an applet front-end code decompilation tool, and obtaining a front-end
source code file of the to-be-tested applet. The method comprises the following steps: performing
data flow analysis on a front-end
source code of each to-be-tested applet by adopting an AST-based
data flow analysis method, identifying an API parameter used in a third-party
verification login process as a
data source, analyzing data flow, modeling
client-
server interaction to obtain an applet
client-
server interaction process diagram, and performing data flow analysis on the applet
client-
server interaction process diagram. And finally, after third-party
verification, the login request forgery
vulnerability is carried out. According to the method, the login request counterfeiting vulnerability after third-party verification in the applet
ecology can be effectively detected.