首页> 外国专利> METHOD FOR AUTOMATICALLY TESTING HORIZONTAL OVER-PERMISSION VULNERABILITIES AND RELATED DEVICE

METHOD FOR AUTOMATICALLY TESTING HORIZONTAL OVER-PERMISSION VULNERABILITIES AND RELATED DEVICE

机译:自动测试水平超权限漏洞的方法及相关设备

摘要

Disclosed are a method for automatically testing horizontal over-permission vulnerabilities and a related device, relating to the field of comparison testing. The method comprises: creating a first account and a second account with the same account operation permission list, wherein the account operation permission list shows all account operation permissions owned by a corresponding account (S100); using the first account to execute a reference test request for each of the account operation permissions, so as to obtain a corresponding reference test request URL (S110); based on the reference test request URL, using the second account to execute a contrast test request for each of the account operation permissions, so as to obtain a corresponding contrast test request result (S120); and based on the corresponding contrast test request result, determining whether there are horizontal over-permission vulnerabilities (S130). The method improves the efficiency for testing horizontal unauthorized vulnerabilities.
机译:公开了一种自动测试横向超权限漏洞的方法及相关设备,涉及比较测试领域。该方法包括:创建具有相同账户操作权限列表的第一账户和第二账户,其中账户操作权限列表显示相应账户拥有的所有账户操作权限(S100);使用第一账户对每个账户操作权限执行参考测试请求,以获得对应的参考测试请求URL(S110);基于参考测试请求URL,使用第二账户对每个账户操作权限执行对比测试请求,以获取对应的对比测试请求结果(S120);根据对应的对比测试请求结果,确定是否存在水平超权限漏洞(S130)。该方法提高了测试水平未授权漏洞的效率。

著录项

  • 公开/公告号WO2020181841A1

    专利类型

  • 公开/公告日2020-09-17

    原文格式PDF

  • 申请/专利号WO2019CN122940

  • 发明设计人 TANG XINYU;

    申请日2019-12-04

  • 分类号G06F21/57;

  • 国家 WO

  • 入库时间 2022-08-21 11:09:29

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号