EDBT 2026 Demo / reviewers in the wild / expert
Chuhan Wang 0001
dblp:210/1379-1
· DBLP profile ↗
10ranked-venue papers
3as first author
10since 2021 · last 2025
0000-0003-4715-4667ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 10 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this Vulnerability
Chuhan Wang 0001, Chenkai Wang 0001, Songyi Yang, Sophia Liu, Jianjun Chen 0005, Hai-Xin Duan, Gang Wang 0011 |
USENIX Security Symposium | 1 |
| 2024 | Inbox Invasion: Exploiting MIME Ambiguities to Evade Email Attachment DetectorsabstractEmail attachments have become a favored delivery vector for malware campaigns. In response, email attachment detectors are widely deployed to safeguard email security. However, an emerging threat arises when adversaries exploit parsing discrepancies between email detectors and clients to evade detection. Currently, uncovering these vulnerabilities still depends on manual, ad hoc methods. In this paper, we perform the first systematic evaluation of email attachment detection against parsing ambiguity vulnerabilities. We propose a novel testing methodology, MIMEminer, to systematically discover evasion vulnerabilities in email systems. We evaluated our methodology against 16 content detectors of popular email services like Gmail and iCloud, and 7 popular email clients like Outlook and Thunderbird. In total, we discovered 19 new evasion methods affecting all tested email services and clients. We further analyzed these vulnerabilities and identified three primary categories of malware evasions. We have responsibly reported those identified vulnerabilities to the affected providers to help with the remediation of such vulnerabilities and received acknowledgments from Google Gmail, Apple iCloud, Coremail, Tencent, Amavis and Perl MIME-tools. Jianjun Chen 0005, Qi Wang 0094, Chuhan Wang 0001, Jianwei Zhuge, Hai-Xin Duan |
CCS | 5 |
| 2024 | BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet
Chuhan Wang 0001, Yasuhiro Kuranaga, Mingming Zhang 0010, Linkai Zheng, Xiang Li 0108, Jianjun Chen 0005, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan |
NDSS | 1 |
| 2024 | ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based Fuzzing
Linkai Zheng, Xiang Li 0108, Chuhan Wang 0001, Run Guo, Hai-Xin Duan, Jianjun Chen 0005, Chao Zhang 0008, Kaiwen Shen |
NDSS | 3 |
| 2024 | TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsabstractDNS can be compared to a game of chess in that its rules are simple, yet the possibilities it presents are endless. While the fundamental rules of DNS are straightforward, DNS implementations can be extremely complex. In this study, we intend to explore the complexities and vulnerabilities in DNS response pre-processing by systematically analyzing DNS RFCs and DNS software implementations. We present the discovery of three new types of logic vulnerabilities, leading to the proposal of three novel attacks, namely the TuDoor attack. These attacks involve the use of malformed DNS response packets to carry out DNS cache poisoning, denial- of-service, and resource consuming attacks. By performing comprehensive experiments, we demonstrate the attack’s feasibility and significant real-world impacts of TUDOOR. In total, 24 mainstream DNS software, including BIND, PowerDNS, and Microsoft DNS, are affected by TuDoor. Attackers can instigate cache poisoning and denial-of-service attacks against vulnerable resolvers using a handful of crafted packets within 1 second or circumvent the query limit to deplete resolution resources (e.g., CPU). Besides, to determine the vulnerable resolver population in the wild, we collect and evaluate 16 popular Wi-Fi routers, 6 prevalent router OSes, 42 public DNS services, and around 1.8M open DNS resolvers. Our measurement results indicate that TUDOOR could exploit 7 routers (OSes), 18 public DNS services, and 424,652 (23.1%) open DNS resolvers. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors, and 18 of them, including BIND, Chrome, Cloudflare, and Microsoft, have acknowledged our findings and discussed mitigation solutions with us. Furthermore, 33 CVE IDs are assigned to our discovered vulnerabilities, and we provide an online detection tool as one of the mitigation measures. Our research highlights the urgent need for standardization of DNS response pre-processing logic to enhance the security of DNS. Xiang Li 0108, Wei Xu 0064, Baojun Liu 0002, Mingming Zhang 0010, Zhou Li 0001, Jia Zhang 0004, Deliang Chang, Chuhan Wang 0001, Jianjun Chen 0005, Hai-Xin Duan, Qi Li 0002 |
SP | 9 |
| 2024 | Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsabstractServer-Side Request Forgery (SSRF) vulnerability poses significant security risks to web applications, enabling adversaries to exploit web applications as stepping stones for unauthorized access of internal-only services or even performing arbitrary commands. Despite its recent emergence as a distinct category in the 2021 OWASP Top 10 web security risks and its increasing prevalence in modern web applications, there remains a lack of effective approaches to detect SSRF vulnerabilities systematically.We present a novel methodology, SSRFuzz, to effectively identify SSRF vulnerability in PHP web applications. Our methodology consists of three phases. In the initial phase, we designed an SSRF oracle to examine functions in PHP manuals and identify sinks that provide server-side request capabilities. This process yielded a total of 86 sensitive PHP sinks out of 2101 PHP functions. The second stage involves dynamic taint inference and the utilization of the identified sinks to examine the source code of target web applications, pinpointing all feasible input points that could trigger these sinks. The final phase employs fuzzing techniques. We generate testing HTTP requests with SSRF payloads, send them to the previously identified input points within the target web applications, and detect if an SSRF vulnerability is triggered. We implemented a prototype of SSRFuzz and evaluated it on 27 real-world applications, including Joomla and WordPress. In total, we discovered 28 SSRF vulnerabilities, 25 of which were previously unreported. We reported all the vulnerabilities to the affected vendors, and 16 new CVE IDs were assigned. Enze Wang, Jianjun Chen 0005, Wei Xie 0007, Chuhan Wang 0001, Hai-Xin Duan, Yang Liu 0003 |
SP | 4 |
| 2024 | Uncovering Security Vulnerabilities in Real-world Implementation and Deployment of 5G Messaging Servicesabstract5G messaging services, based on Global System for Mobile Communications Association (GSMA) Rich Communication Service (RCS) and 3rd Generation Partnership Project (3GPP) IP Multimedia Subsystem (IMS), have been deployed globally by more than 90 mobile operators serving over 421 million monthly active users via 1.2 billion devices. Despite the widespread use, security research of 5G messaging remains sparse. In this paper, we present a comprehensive security analysis and measurement of 5G messaging services, assisted by a semi-automated testing tool we developed. We considered both carrier-side deployment and phone-side software implementations by testing against three large operators, each with hundreds of millions of subscribers, and six popular 5G messaging-enabled devices. We uncovered 4 categories of vulnerabilities, allowing for a wide range of attacks, including Man-In-The-Middle (MITM) attacks, zero-click remote information leakage, phone storage exhaustion and mobile data consumption, and Denial-of-Services (DoS) attacks. Our study underscores the need for further security enhancements in security specifications, implementation, and deployment of 5G messaging services. Yiming Zhang 0009, Tao Wan 0004, Chuhan Wang 0001, Hai-Xin Duan, Jianjun Chen 0005, Yishen Li |
WISEC | 4 |
| 2023 | Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the WildabstractCryptocurrency mining is a crucial operation in blockchains, and miners often join mining pools to increase their chances of earning rewards. However, the energy-intensive nature of PoW cryptocurrency mining has led to its ban in New York State of the United States, China, and India. As a result, mining pools, serving as a central hub for mining activities, have become prime targets for regulatory enforcement. Furthermore, cryptojacking malware refers to self-owned stealthy mining pools to evade detection techniques and conceal profit wallet addresses. However, no systematic research has been conducted to analyze it, largely due to a lack of full understanding of the protocol implementation, usage, and port distribution of the stealth mining pool. Zhenrui Zhang, Geng Hong, Xiang Li 0108, Zhuoqun Fu, Jia Zhang 0004, Mingxuan Liu 0006, Chuhan Wang 0001, Jianjun Chen 0005, Baojun Liu 0002, Hai-Xin Duan, Chao Zhang 0008, Min Yang 0002 |
CCS | 7 |
| 2022 | A Large-scale and Longitudinal Measurement Study of DKIM Deployment
Chuhan Wang 0001, Kaiwen Shen, Minglei Guo, Mingming Zhang 0010, Jianjun Chen 0005, Baojun Liu 0002, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan |
USENIX Security Symposium | 1 |
| 2021 | Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
Kaiwen Shen, Chuhan Wang 0001, Minglei Guo, Chaoyi Lu, Baojun Liu 0002, Shuang Hao 0001, Hai-Xin Duan, Qingfeng Pan, Min Yang 0002 |
USENIX Security Symposium | 2 |