In the web security field, data dumping activities are often related to a malicious exploitation. In this paper, we focus on data dumping activities executed legitimately by scraping/storing data shown on the browser. We evaluate such operation by proposing Cookidump, a tool able to dump all recipes available on the Cookidoo© website portal. While such scenario is not relevant, in terms of security and privacy, we discuss the impact of such kind of activity for other scenarios including web applications hosting sensitive information.

Web security and data dumping: The Cookidump case

Enrico Cambiaso
Primo
;
Maurizio Aiello
Ultimo
2022

Abstract

In the web security field, data dumping activities are often related to a malicious exploitation. In this paper, we focus on data dumping activities executed legitimately by scraping/storing data shown on the browser. We evaluate such operation by proposing Cookidump, a tool able to dump all recipes available on the Cookidoo© website portal. While such scenario is not relevant, in terms of security and privacy, we discuss the impact of such kind of activity for other scenarios including web applications hosting sensitive information.
2022
Istituto di Elettronica e di Ingegneria dell'Informazione e delle Telecomunicazioni - IEIIT
cybersecurity
data dump
database security
browser automation
File in questo prodotto:
File Dimensione Formato  
prod_471929-doc_191880.pdf

solo utenti autorizzati

Descrizione: Versione early access
Tipologia: Versione Editoriale (PDF)
Licenza: Nessuna licenza dichiarata (non attribuibile a prodotti successivi al 2023)
Dimensione 664.11 kB
Formato Adobe PDF
664.11 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
prod_471929-doc_191881.pdf

accesso aperto

Descrizione: Web security and data dumping: The Cookidump case
Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 491.58 kB
Formato Adobe PDF
491.58 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/414456
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 0
social impact