User Tools

Site Tools


provenance:security:web_vulnerabilities

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
provenance:security:web_vulnerabilities [2026/08/27 13:45] – Log focused-review empty findings (3x gpt-5.6-luna-medium). Authored by Claude. karel.kubicek.claudeprovenance:security:web_vulnerabilities [2026/08/27 13:50] (current) – Log four review passes (3 focused empty, generic accepted); refresh report. Authored by Claude. karel.kubicek.claude
Line 1: Line 1:
 ====== Provenance: Security:Web vulnerabilities ====== ====== Provenance: Security:Web vulnerabilities ======
  
-Back to [[security:web_vulnerabilities|Web vulnerabilities]]. Corpus-wide selection and extraction notes are on [[literature:corpus]]. Citations use the shared [[literature:bibliography]]; this page adds no keys of its own. No ''~~DISCUSSION~~'' — comments belong on the content page.+Back to [[security:web_vulnerabilities|Web vulnerabilities]]. Corpus-wide selection and extraction notes are on [[literature:corpus]]. Citations use the shared [[literature:bibliography]]; this page adds no keys of its own. No discussion block on this page — comments belong on the content page.
  
 ===== Run record ===== ===== Run record =====
Line 41: Line 41:
 | … used + offline-only | 880 | **260 (29.5%)** | | … used + offline-only | 880 | **260 (29.5%)** |
 | ROLE = wild among the 99 | 99; 1,120 crawled | **30 (30.3% of 99; 2.7% of crawled)** — page population for in-the-wild figures | | ROLE = wild among the 99 | 99; 1,120 crawled | **30 (30.3% of 99; 2.7% of crawled)** — page population for in-the-wild figures |
 +| … of which archive-surface (Lerner rewriting-history; Stock Wayback {[stock2017web]}) | 30 | **2** |
 +| … of which crawled then-live sites | 30 | **28** |
 +| wild classification method: dynamic-analysis / heuristic-rules / manual-labelling | 30, multi | **14 (46.7%) / 12 (40.0%) / 8 (26.7%)** |
 | ROLE = lab | 99 | **27 (27.3%)** | | ROLE = lab | 99 | **27 (27.3%)** |
 | ROLE = cve | 99 | **8 (8.1%)** | | ROLE = cve | 99 | **8 (8.1%)** |
Line 73: Line 76:
   * **ROLE** (''scripts/vuln_fold.mjs''): one label per paper of the 99. Deciding sentence inline, quote-checked against ''paper.cols.txt''. The report throws if a key of the 99 is missing from ROLE or ROLE contains a key that is not in the 99.   * **ROLE** (''scripts/vuln_fold.mjs''): one label per paper of the 99. Deciding sentence inline, quote-checked against ''paper.cols.txt''. The report throws if a key of the 99 is missing from ROLE or ROLE contains a key that is not in the 99.
   * **Kind fold**: ordered regex families over title, slug and vulnerability tuples; multi-label. Residue **62 of 99** is printed in full in the report block below. Clickjacking as a primary study is essentially absent from this schema slice (1 of 99, 0 wild).   * **Kind fold**: ordered regex families over title, slug and vulnerability tuples; multi-label. Residue **62 of 99** is printed in full in the report block below. Clickjacking as a primary study is essentially absent from this schema slice (1 of 99, 0 wild).
-  * Borderline calls a different reader might flip:+  * **Archive-surface split** (added after generic review)two keys, not a regex — CCS/2017/rewriting-history and USENIX/2017/how-the-web-tangled-itself. White Rabbit also reports archived redirects as a second experiment; it stays in the 28 because the crawl was then-live. The report throws if the two sets do not partition the 30.
     * USENIX/2010/searching-the-searchers-with-searchaudit → **wild** (SQL error oracle on live search engines), not lab.     * USENIX/2010/searching-the-searchers-with-searchaudit → **wild** (SQL error oracle on live search engines), not lab.
     * PETS/2023/comparing-large-scale-privacy-and-security-notifications → **wild** (they notified live operators about findings from a crawl), not offtopic.     * PETS/2023/comparing-large-scale-privacy-and-security-notifications → **wild** (they notified live operators about findings from a crawl), not offtopic.
Line 197: Line 200:
 | 3. External currency | GPT 5.6 Luna medium | none | **Accepted as empty.** Re-fetched OWASP 2025, Chrome 78/80, ZAP Checkmarx blog, ''zaproxy/zaproxy'' licence Apache-2.0, nuclei not archived. | | 3. External currency | GPT 5.6 Luna medium | none | **Accepted as empty.** Re-fetched OWASP 2025, Chrome 78/80, ZAP Checkmarx blog, ''zaproxy/zaproxy'' licence Apache-2.0, nuclei not archived. |
  
-Generic pass (no checklist) runs after this log is on the provenance page.+Generic pass (no checklist) ran after the focused log was on this page. Content was not edited while it ran. 
 + 
 +^ Pass ^ Model ^ Finding ^ Disposition ^ 
 +| 4. Generic | GPT 5.6 Luna medium | 1. Wild 30 mixes live and archived; no live-only count. | **Accepted.** Hand-split **2** archive-surface / **28** then-live; named in WRAP and the role table. Not a regex. | 
 +| 4. Generic | GPT 5.6 Luna medium | 2. Method distribution is for the 99, not the 30. | **Accepted.** Report now prints H2 on the 30: dynamic-analysis **14 (46.7%)**, heuristic-rules **12 (40.0%)**, manual-labelling **8 (26.7%)**. Page leads with that; 99 kept as the flipped conjunction summary. | 
 +| 4. Generic | GPT 5.6 Luna medium | 3. "2024–2026 specialised browsers still do" overgroups Foxhound / PanoptiChrome / Sabino. | **Accepted.** Scoped: Foxhound is the pipeline; PanoptiChrome is the same family; Sabino adds interaction fuzzing on top of a taint pass. | 
 +| 4. Generic | GPT 5.6 Luna medium | 4. Provenance ''No DISCUSSION token'' rendered as broken italics. | **Accepted.** Reworded without nesting the discussion token. | 
 +| 4. Generic (re-run) | GPT 5.6 Luna medium | Called the 28 a count of sites, not papers. | **Accepted.** "28 papers" / "2 papers" in WRAP and the role table. | 
 +| 4. Generic (re-run) | GPT 5.6 Luna medium | Report H2 labelled "live-measurement" while including the 2 archive-surface papers. | **Accepted.** Relabelled "wild-role method distribution". | 
 + 
 +No GENERIC_REVIEW placeholder.
  
 ===== Report output (unedited) ===== ===== Report output (unedited) =====
Line 417: Line 430:
 PUBLISHED_WILD_SUBPAGES_STATED 10 PUBLISHED_WILD_SUBPAGES_STATED 10
 shallow (landing-page-only + single-target-page) among wild: 7 / 30 = 23.3% shallow (landing-page-only + single-target-page) among wild: 7 / 30 = 23.3%
 +PUBLISHED_WILD_ARCHIVE_SURFACE 2
 +PUBLISHED_WILD_THEN_LIVE 28
 +  archive-surface CCS/2017/rewriting-history-changing-the-archived-web-from-the-present Rewriting History: Changing the Archived Web from the Present.
 +  archive-surface USENIX/2017/how-the-web-tangled-itself-uncovering-the-history-of-client-side-web-in-security How the Web Tangled Itself: Uncovering the History of Client-Side Web (In)Security
  
 ========================================================================== ==========================================================================
-H. CLASSIFICATION METHOD among the 99 (vuln tuples, sentinels skipped)+H. CLASSIFICATION METHOD (vuln tuples, sentinels skipped)
 ========================================================================== ==========================================================================
 +
 +── H1. conjunction of 99 ──
 method               Papers of 99  Share method               Papers of 99  Share
 -------------------  ------------  ----- -------------------  ------------  -----
Line 434: Line 453:
 other                1             1.0% other                1             1.0%
 blocklist            1             1.0% blocklist            1             1.0%
 +
 +── H2. wild only (the wild-role method distribution; includes the 2 archive-surface papers) ──
 +method              Papers of 30 wild  Share
 +------------------  -----------------  -----
 +dynamic-analysis    14                 46.7%
 +heuristic-rules     12                 40.0%
 +manual-labelling    8                  26.7%
 +static-analysis                      13.3%
 +graph-analysis      2                  6.7%
 +supervised-ml                        3.3%
 +regex-or-signature  1                  3.3%
  
 ========================================================================== ==========================================================================
provenance/security/web_vulnerabilities.1787838355.txt.gz · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki