{"id":{"repo_id":"cagliari","oai_identifier":"oai:iris.unica.it:11584/475187"},"canonical_url":"https://search.dev.ndltd.org/etd/cagliari/oai:iris.unica.it:11584/475187","repository":{"repo_id":"cagliari","name":"Università di Cagliari","base_url":"https://iris.unica.it/oai/request"},"display":{"title":"Unveiling Emerging Web Application Attack Surfaces","abstract":"The security of modern web applications is continually challenged by both the evolution of development paradigms and the emergence of new attack surfaces. The OWASP Top 10 consistently shows injection attacks and insecure designs among the most prevalent threats. While issues such as XSS and SQLi have been extensively studied, many other vulnerabilities within these categories remain insufficiently explored. This thesis studies emerging web security weaknesses across three domains: template engines, HTTP/3, and concurrency. First, we perform an assessment of Server-Side Template Injection (SSTI) across diverse engines and languages, showing that Remote Code Execution (RCE) remains feasible despite longstanding awareness. We then perform the first large-scale study of Client-Side Template Injection (CSTI), using an automated scanner to reveal significant real‐world exposure to Cross-Site Scripting (XSS) via templating logic and to quantify gaps in current defenses. Turning to protocol evolution, we analyze HTTP/3 proxy behavior and uncover new classes of request smuggling and desynchronization attacks rooted in inconsistencies between specifications and implementations, providing a tool for detecting inconsistencies in proxy behavior. Finally, we present a benchmarking framework and introduce the first tool capable of performing single-datagram race condition attacks over HTTP/3. Our benchmark highlights how factors such as server architecture, language runtime, and database configuration influence the exploitability of concurrency issues. Collectively, these contributions provide measurement methodologies, tooling, and mitigation guidance for securing next-generation web applications.","abstract_html":"The security of modern web applications is continually challenged by both the evolution of development paradigms and the emergence of new attack surfaces. The OWASP Top 10 consistently shows injection attacks and insecure designs among the most prevalent threats. While issues such as XSS and SQLi have been extensively studied, many other vulnerabilities within these categories remain insufficiently explored. This thesis studies emerging web security weaknesses across three domains: template engines, HTTP/3, and concurrency. First, we perform an assessment of Server-Side Template Injection (SSTI) across diverse engines and languages, showing that Remote Code Execution (RCE) remains feasible despite longstanding awareness. We then perform the first large-scale study of Client-Side Template Injection (CSTI), using an automated scanner to reveal significant real‐world exposure to Cross-Site Scripting (XSS) via templating logic and to quantify gaps in current defenses. Turning to protocol evolution, we analyze HTTP/3 proxy behavior and uncover new classes of request smuggling and desynchronization attacks rooted in inconsistencies between specifications and implementations, providing a tool for detecting inconsistencies in proxy behavior. Finally, we present a benchmarking framework and introduce the first tool capable of performing single-datagram race condition attacks over HTTP/3. Our benchmark highlights how factors such as server architecture, language runtime, and database configuration influence the exploitability of concurrency issues. Collectively, these contributions provide measurement methodologies, tooling, and mitigation guidance for securing next-generation web applications.","abstract_has_math":false,"creators":["PISU, LORENZO"],"institution":"Università degli Studi di Cagliari","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["MAIORCA, DAVIDE","GIACINTO, GIORGIO"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2026,"date_issued":"2026-02-27T00:00:00+01:00","date_published":"2026-02-27T00:00:00+01:00","updated_at":"2026-07-24T01:29:57Z","subjects":["Settore IINF-05/A - Sistemi di elaborazione delle informazioni"],"languages":["eng"],"rights":["info:eu-repo/semantics/openAccess"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/11584/475187","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["MAIORCA, DAVIDE","GIACINTO, GIORGIO"]},{"key":"dc:creator","label":"Author","values":["PISU, LORENZO"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2026-02-27T00:00:00+01:00"]},{"key":"dc:publisher","label":"Institution","values":["Università degli Studi di Cagliari"]},{"key":"dc:type","label":"Dc Type","values":["info:eu-repo/semantics/doctoralThesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Settore IINF-05/A - Sistemi di elaborazione delle informazioni"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["info:eu-repo/semantics/openAccess"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/11584/475187"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The security of modern web applications is continually challenged by both the evolution of development paradigms and the emergence of new attack surfaces. The OWASP Top 10 consistently shows injection attacks and insecure designs among the most prevalent threats. While issues such as XSS and SQLi have been extensively studied, many other vulnerabilities within these categories remain insufficiently explored. This thesis studies emerging web security weaknesses across three domains: template engines, HTTP/3, and concurrency. First, we perform an assessment of Server-Side Template Injection (SSTI) across diverse engines and languages, showing that Remote Code Execution (RCE) remains feasible despite longstanding awareness. We then perform the first large-scale study of Client-Side Template Injection (CSTI), using an automated scanner to reveal significant real‐world exposure to Cross-Site Scripting (XSS) via templating logic and to quantify gaps in current defenses. Turning to protocol evolution, we analyze HTTP/3 proxy behavior and uncover new classes of request smuggling and desynchronization attacks rooted in inconsistencies between specifications and implementations, providing a tool for detecting inconsistencies in proxy behavior. Finally, we present a benchmarking framework and introduce the first tool capable of performing single-datagram race condition attacks over HTTP/3. Our benchmark highlights how factors such as server architecture, language runtime, and database configuration influence the exploitability of concurrency issues. Collectively, these contributions provide measurement methodologies, tooling, and mitigation guidance for securing next-generation web applications."]},{"key":"dc:title","label":"Title","values":["Unveiling Emerging Web Application Attack Surfaces"]}]}],"canonical_facts":{"dc:contributor":["MAIORCA, DAVIDE","GIACINTO, GIORGIO"],"dc:creator":["PISU, LORENZO"],"dc:date":["2026-02-27T00:00:00+01:00"],"dc:description":["The security of modern web applications is continually challenged by both the evolution of development paradigms and the emergence of new attack surfaces. The OWASP Top 10 consistently shows injection attacks and insecure designs among the most prevalent threats. While issues such as XSS and SQLi have been extensively studied, many other vulnerabilities within these categories remain insufficiently explored. This thesis studies emerging web security weaknesses across three domains: template engines, HTTP/3, and concurrency. First, we perform an assessment of Server-Side Template Injection (SSTI) across diverse engines and languages, showing that Remote Code Execution (RCE) remains feasible despite longstanding awareness. We then perform the first large-scale study of Client-Side Template Injection (CSTI), using an automated scanner to reveal significant real‐world exposure to Cross-Site Scripting (XSS) via templating logic and to quantify gaps in current defenses. Turning to protocol evolution, we analyze HTTP/3 proxy behavior and uncover new classes of request smuggling and desynchronization attacks rooted in inconsistencies between specifications and implementations, providing a tool for detecting inconsistencies in proxy behavior. Finally, we present a benchmarking framework and introduce the first tool capable of performing single-datagram race condition attacks over HTTP/3. Our benchmark highlights how factors such as server architecture, language runtime, and database configuration influence the exploitability of concurrency issues. Collectively, these contributions provide measurement methodologies, tooling, and mitigation guidance for securing next-generation web applications."],"dc:identifier":["https://hdl.handle.net/11584/475187"],"dc:language":["eng"],"dc:publisher":["Università degli Studi di Cagliari"],"dc:rights":["info:eu-repo/semantics/openAccess"],"dc:subject":["Settore IINF-05/A - Sistemi di elaborazione delle informazioni"],"dc:title":["Unveiling Emerging Web Application Attack Surfaces"],"dc:type":["info:eu-repo/semantics/doctoralThesis"]},"updated_at":"2026-07-24T01:29:57Z"}