BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Dharmaadi, I Putu Arya, Alhanahnah, Mohannad, Pham, Van-Thuan, Mohsen, Fadi, Turkmen, Fatih
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866918101119926272
author Dharmaadi, I Putu Arya
Alhanahnah, Mohannad
Pham, Van-Thuan
Mohsen, Fadi
Turkmen, Fatih
author_facet Dharmaadi, I Putu Arya
Alhanahnah, Mohannad
Pham, Van-Thuan
Mohsen, Fadi
Turkmen, Fatih
contents Broken Access Control (BAC) remains one of the most critical and widespread vulnerabilities in web applications, allowing attackers to access unauthorized resources or perform privileged actions. Despite its severity, BAC is underexplored in automated testing due to key challenges: the lack of reliable oracles and the difficulty of generating semantically valid attack requests. We introduce BACFuzz, the first gray-box fuzzing framework specifically designed to uncover BAC vulnerabilities, including Broken Object-Level Authorization (BOLA) and Broken Function-Level Authorization (BFLA) in PHP-based web applications. BACFuzz combines LLM-guided parameter selection with runtime feedback and SQL-based oracle checking to detect silent authorization flaws. It employs lightweight instrumentation to capture runtime information that guides test generation, and analyzes backend SQL queries to verify whether unauthorized inputs flow into protected operations. Evaluated on 20 real-world web applications, including 15 CVE cases and 2 known benchmarks, BACFuzz detects 16 of 17 known issues and uncovers 26 previously unknown BAC vulnerabilities with low false positive rates. All identified issues have been responsibly disclosed, and artifacts will be publicly released.
format Preprint
id arxiv_https___arxiv_org_abs_2507_15984
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
Dharmaadi, I Putu Arya
Alhanahnah, Mohannad
Pham, Van-Thuan
Mohsen, Fadi
Turkmen, Fatih
Cryptography and Security
Software Engineering
Broken Access Control (BAC) remains one of the most critical and widespread vulnerabilities in web applications, allowing attackers to access unauthorized resources or perform privileged actions. Despite its severity, BAC is underexplored in automated testing due to key challenges: the lack of reliable oracles and the difficulty of generating semantically valid attack requests. We introduce BACFuzz, the first gray-box fuzzing framework specifically designed to uncover BAC vulnerabilities, including Broken Object-Level Authorization (BOLA) and Broken Function-Level Authorization (BFLA) in PHP-based web applications. BACFuzz combines LLM-guided parameter selection with runtime feedback and SQL-based oracle checking to detect silent authorization flaws. It employs lightweight instrumentation to capture runtime information that guides test generation, and analyzes backend SQL queries to verify whether unauthorized inputs flow into protected operations. Evaluated on 20 real-world web applications, including 15 CVE cases and 2 known benchmarks, BACFuzz detects 16 of 17 known issues and uncovers 26 previously unknown BAC vulnerabilities with low false positive rates. All identified issues have been responsibly disclosed, and artifacts will be publicly released.
title BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2507.15984