A Bad IDEa: Weaponizing uncontrolled online-IDEs in availability attacks

Shreyas Srinivasa, Dimitrios Georgoulias, Jens Myrup Pedersen, Emmanouil Vasilomanolakis

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

357 Downloads (Pure)

Abstract

Botnets are an ongoing threat to the cyber world and can be utilized to carry out DDoS attacks of high magnitude. From the botmaster's perspective, there is a constant need for deploying more effective botnets and discovering new ways to bolster their bot ranks. Integrated Development Environments (IDEs) have been essential for software developers to write and compile source code. The increasing need for remote work and collaborative workspaces have led to the IDE-as-a-service paradigm that offers online code editing and compilation with multiple language support. In this paper, we show that a multitude of online IDEs do not run control checks on the user code and can be therefore lever-aged by a botnet. We examine the concept of uncontrolled execution environments and present a proof of concept to show how uncontrolled online-IDEs can be weaponized to perform large-scale attacks by a botnet. Overall, we detect a total of 719 online-IDEs with uncontrolled execution environments and limited sandboxing. Lastly, as ethical disclosure, we inform the IDE developers and service providers of the vulnerabilities and propose countermeasures.
OriginalsprogEngelsk
TitelIEEE European Symposium on Security and Privacy, Workshop on Attackers and Cyber-Crime Operations
Antal sider11
ForlagIEEE
Publikationsdatomar. 2022
Sider82-92
Artikelnummer9799405
ISBN (Trykt)978-1-6654-9561-5
ISBN (Elektronisk)978-1-6654-9560-8
DOI
StatusUdgivet - mar. 2022
Begivenhed2022 IEEE European Symposium on Security and Privacy Workshops - Genoa, Italien
Varighed: 6 jun. 202210 jun. 2022

Konference

Konference2022 IEEE European Symposium on Security and Privacy Workshops
Land/OmrådeItalien
ByGenoa
Periode06/06/202210/06/2022
NavnIEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
ISSN2768-0657

Fingeraftryk

Dyk ned i forskningsemnerne om 'A Bad IDEa: Weaponizing uncontrolled online-IDEs in availability attacks'. Sammen danner de et unikt fingeraftryk.

Citationsformater