Software vulnerabilities in widely deployed, Internet-exposed applications pose a significant threat, but they are only exploited at scale when attackers have a practical way to discover vulnerable instances. One factor that makes such a discovery easier may be Certificate Transparency (CT) logs: although designed to improve trust in digital certificates, they also expose information that attackers could leverage. In this work, we investigate the misuse of CT logs for large-scale reconnaissance of self-hosted web applications. By filtering a single day of CT logs with keywords from 27 popular web applications, we identify over 96000 candidate domains. Crawling these domains reveals a median match rate of 10.9%, with some instances exceeding 20%. Our findings highlight that CT logs can provide attackers with an effective and timely method to identify potentially vulnerable instances of web applications, raising new considerations for Internet-scale security and privacy.

Poster—Reconnaissance via Certificate Transparency Logs: Exposing Self-Hosted Web Applications / Ravalico, D., Trevisan, M., Drago, I.. - (2025), pp. 34-35. (21st International Conference on Emerging Networking EXperiments and Technologies, CoNEXT 2025 hkg 2025) [10.1145/3765515.3771748].

Poster—Reconnaissance via Certificate Transparency Logs: Exposing Self-Hosted Web Applications

Ravalico, Damiano
Primo
Methodology
;
Trevisan, Martino
Secondo
Writing – Review & Editing
;
2025-01-01

Abstract

Software vulnerabilities in widely deployed, Internet-exposed applications pose a significant threat, but they are only exploited at scale when attackers have a practical way to discover vulnerable instances. One factor that makes such a discovery easier may be Certificate Transparency (CT) logs: although designed to improve trust in digital certificates, they also expose information that attackers could leverage. In this work, we investigate the misuse of CT logs for large-scale reconnaissance of self-hosted web applications. By filtering a single day of CT logs with keywords from 27 popular web applications, we identify over 96000 candidate domains. Crawling these domains reveals a median match rate of 10.9%, with some instances exceeding 20%. Our findings highlight that CT logs can provide attackers with an effective and timely method to identify potentially vulnerable instances of web applications, raising new considerations for Internet-scale security and privacy.
File in questo prodotto:
Non ci sono file associati a questo prodotto.
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11368/3145718
 Avviso

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact