arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.23042cs.CR

幸存于一切的秘密:生产环境 Web 应用中的运行时凭据暴露

Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications

  • Independent Security Researcher(独立安全研究员)

机构由 AI 辅助整理,请以论文原文为准。

Hemanth Gorijala

AI总结:

本研究揭示生产环境 Web 应用中的运行时凭据暴露问题,提出分层运行时检测方法,发现现有扫描器存在结构性盲点,覆盖率仅达86.1%。

AI中文摘要:

部署前的秘密扫描仅作用于源代码,而从不检查生产应用实际提供的内容。我们记录了两条利用链,其中来自生产环境 JavaScript 捆绑包中的 Azure AD 客户端凭据和 APIM 订阅密钥导致了账户接管和大规模数据暴露。一次授权评估覆盖了一个组织中约 2,000 个企业 Web 资产;其中 113 个(5.65%)提供了实时凭据。为量化右移差距,我们通过 Claude Opus 4.7 提取和人工分析师审查构建了一个独立的 Ground Truth(GT-194),包含 194 个秘密级凭据,247 个 LLM 提取的候选结果由 GPT-5.5 独立验证(Brennan-Prediger kappa = 0.676)。主要发现是结构性的:GT-194 中的 13.9%(194 个中的 27 个)仅通过人工分析浮出水面,而九个被评估的生产扫描器均未恢复,这是一个与工具无关的盲点,地面真值模型也未能捕捉。CryptoJS 加密配置单独击败了所有静态扫描器:凭据仅在与同处一地的密钥解密后存在,只能通过运行时感知检测才能触及。组合覆盖率稳定在 86.1%。在九个扫描器中,最佳静态扫描器恢复了 36.6%,最佳运行时感知扫描器恢复了 77.8%(F1 = 0.818,McNemar p < 0.001);地面真值模型作为参考比较器单独报告,而非被评估的检测器。在 86 个秘密暴露应用中的 63 个(73.3%)上,完整的 Azure AD 令牌铸造链共处于一个捆绑包中,可从浏览器代码访问。我们描述了凭据未被检测地进入生产环境的五条路径,并提出了一种分层运行时检测方法和修复框架。召回范围限定于单一组织的 Azure 重度语料库。

英文摘要:

Pre-deployment secret scanning operates only on source code, never on what a production application serves. We document two exploitation chains in which Azure AD client credentials and APIM subscription keys from production JavaScript bundles enabled account takeover and mass data exposure. An authorized engagement covered approximately 2,000 enterprise web assets in one organization; 113 (5.65%) served live credentials. To quantify the shift-right gap, we built an independent Ground Truth (GT-194) of 194 secret-grade credentials through Claude Opus 4.7 extraction and manual analyst review, with the 247 LLM-extracted candidates independently validated by GPT-5.5 (Brennan-Prediger kappa = 0.676). The principal finding is structural: 13.9% of GT-194 (27 of 194) is surfaced only by manual analysis and recovered by none of the nine evaluated production scanners, a tool-agnostic blind spot the ground-truth model also misses. CryptoJS encrypted configuration separately defeats every static scanner: the credential exists only after decryption with a co-located key, reached only by runtime-aware detection. Combined coverage plateaus at 86.1%. Among the nine scanners, the best static scanner recovers 36.6% and the best runtime-aware scanner 77.8% (F1 = 0.818, McNemar p < 0.001); the ground-truth model is reported separately as a reference comparator, not an evaluated detector. On 63 of 86 secret-exposed applications (73.3%), the full Azure AD token-mint chain is co-located in one bundle, reachable from browser code. We characterize five paths by which credentials reach production undetected and present a layered runtime detection methodology and remediation framework. Recall is scoped to a single-organization Azure-heavy corpus.

补充信息

↑