Firing Range: Google’s Open Source Tool for Web App Vulnerability Scanning

Google has recently introduced a new security testing tool called “Firing Range,” designed to enhance the capabilities of automated web application security scanners. This tool addresses the widespread issue of vulnerabilities, particularly focusing on cross-site scripting (XSS), which has been identified as a significant threat in web applications. According to Claudio Criscione, a security engineer at Google, XSS flaws constitute approximately 70 percent of the vulnerabilities reported through Google’s Vulnerability Reward Program.

Firing Range creates a synthetic environment specifically tailored for testing against various web vulnerabilities, with a concentration on XSS. This strategic focus is crucial, considering the frequency with which such vulnerabilities occur in web applications. Beyond XSS, the tool effectively scans for additional vulnerabilities such as reverse clickjacking, Flash injection, mixed content issues, and cross-origin resource sharing vulnerabilities.

Developed in collaboration with security researchers at Politecnico di Milano, Firing Range aims to provide a robust testing ground for automated scanners. Google has utilized this tool not only as an ongoing testing resource but also as a foundation for development, seeking to identify a broad spectrum of bug types, including some that remain undetectable. The distinguishing feature of Firing Range lies in its automation capabilities, which streamline testing processes. Unlike traditional methods that often create realistic test environments for human penetration testers, this tool leverages unique bug patterns derived from real-world vulnerabilities encountered by Google.

Built as a Java application on Google App Engine, Firing Range incorporates a variety of patterns targeting specific vulnerability types, including DOM-based, redirected, reflected, tag-based, escaped, and remote inclusion bugs. During last year’s Google Testing Automation Conference, Criscione elaborated on the challenges of manually detecting XSS vulnerabilities at scale, likening the task to “drinking the ocean.” Firing Range addresses these challenges by automating vulnerability exploitation and detecting the outcomes efficiently.

This tool is not merely a replica of typical web applications. Criscione emphasizes that it intentionally avoids emulating real-world applications or exhaustively testing scanner crawling capabilities. Instead, it serves as a curated collection of unique bug patterns aimed at assessing and enhancing the detection capabilities of security tools.

Firing Range’s development aligns with Google’s broader security initiatives, including its internal web application security scanning tool, “Inquisition,” which is built on cutting-edge Google Chrome and Cloud Platform technologies. This internal tool incorporates the latest HTML5 features and aims for a low false positive rate, further demonstrating Google’s commitment to improving web application security.

For those interested in accessing Firing Range, a public version is available on Google App Engine, with the open-source code accessible on GitHub. Google encourages user feedback to continuously enhance the tool’s functionality.

As businesses increasingly recognize the importance of cybersecurity, tools like Firing Range play a critical role in scouting vulnerabilities. Understanding the tactics and techniques aligned with the MITRE ATT&CK framework, such as initial access, persistence, and privilege escalation, can help organizations appreciate the potential threats and mitigations involved in securing their web applications against evolving cyber risks.

Source link