provenance:security:web_vulnerabilities
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| provenance:security:web_vulnerabilities [2026/08/27 13:45] – Log focused-review empty findings (3x gpt-5.6-luna-medium). Authored by Claude. karel.kubicek.claude | provenance:security:web_vulnerabilities [2026/08/27 13:50] (current) – Log four review passes (3 focused empty, generic accepted); refresh report. Authored by Claude. karel.kubicek.claude | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Provenance: Security: | ====== Provenance: Security: | ||
| - | Back to [[security: | + | Back to [[security: |
| ===== Run record ===== | ===== Run record ===== | ||
| Line 41: | Line 41: | ||
| | … used + offline-only | 880 | **260 (29.5%)** | | | … used + offline-only | 880 | **260 (29.5%)** | | ||
| | ROLE = wild among the 99 | 99; 1,120 crawled | **30 (30.3% of 99; 2.7% of crawled)** — page population for in-the-wild figures | | | ROLE = wild among the 99 | 99; 1,120 crawled | **30 (30.3% of 99; 2.7% of crawled)** — page population for in-the-wild figures | | ||
| + | | … of which archive-surface (Lerner rewriting-history; | ||
| + | | … of which crawled then-live sites | 30 | **28** | | ||
| + | | wild classification method: dynamic-analysis / heuristic-rules / manual-labelling | 30, multi | **14 (46.7%) / 12 (40.0%) / 8 (26.7%)** | | ||
| | ROLE = lab | 99 | **27 (27.3%)** | | | ROLE = lab | 99 | **27 (27.3%)** | | ||
| | ROLE = cve | 99 | **8 (8.1%)** | | | ROLE = cve | 99 | **8 (8.1%)** | | ||
| Line 73: | Line 76: | ||
| * **ROLE** ('' | * **ROLE** ('' | ||
| * **Kind fold**: ordered regex families over title, slug and vulnerability tuples; multi-label. Residue **62 of 99** is printed in full in the report block below. Clickjacking as a primary study is essentially absent from this schema slice (1 of 99, 0 wild). | * **Kind fold**: ordered regex families over title, slug and vulnerability tuples; multi-label. Residue **62 of 99** is printed in full in the report block below. Clickjacking as a primary study is essentially absent from this schema slice (1 of 99, 0 wild). | ||
| - | * Borderline calls a different reader might flip: | + | * **Archive-surface split** (added after generic review): two keys, not a regex — CCS/ |
| * USENIX/ | * USENIX/ | ||
| * PETS/ | * PETS/ | ||
| Line 197: | Line 200: | ||
| | 3. External currency | GPT 5.6 Luna medium | none | **Accepted as empty.** Re-fetched OWASP 2025, Chrome 78/80, ZAP Checkmarx blog, '' | | 3. External currency | GPT 5.6 Luna medium | none | **Accepted as empty.** Re-fetched OWASP 2025, Chrome 78/80, ZAP Checkmarx blog, '' | ||
| - | Generic pass (no checklist) | + | Generic pass (no checklist) |
| + | |||
| + | ^ Pass ^ Model ^ Finding ^ Disposition ^ | ||
| + | | 4. Generic | GPT 5.6 Luna medium | 1. Wild 30 mixes live and archived; no live-only count. | **Accepted.** Hand-split **2** archive-surface / **28** then-live; named in WRAP and the role table. Not a regex. | | ||
| + | | 4. Generic | GPT 5.6 Luna medium | 2. Method distribution | ||
| + | | 4. Generic | GPT 5.6 Luna medium | 3. " | ||
| + | | 4. Generic | GPT 5.6 Luna medium | 4. Provenance '' | ||
| + | | 4. Generic (re-run) | GPT 5.6 Luna medium | Called the 28 a count of sites, not papers. | **Accepted.** "28 papers" | ||
| + | | 4. Generic (re-run) | GPT 5.6 Luna medium | Report H2 labelled " | ||
| + | |||
| + | No GENERIC_REVIEW placeholder. | ||
| ===== Report output (unedited) ===== | ===== Report output (unedited) ===== | ||
| Line 417: | Line 430: | ||
| PUBLISHED_WILD_SUBPAGES_STATED 10 | PUBLISHED_WILD_SUBPAGES_STATED 10 | ||
| shallow (landing-page-only + single-target-page) among wild: 7 / 30 = 23.3% | shallow (landing-page-only + single-target-page) among wild: 7 / 30 = 23.3% | ||
| + | PUBLISHED_WILD_ARCHIVE_SURFACE 2 | ||
| + | PUBLISHED_WILD_THEN_LIVE 28 | ||
| + | archive-surface CCS/ | ||
| + | archive-surface USENIX/ | ||
| ========================================================================== | ========================================================================== | ||
| - | H. CLASSIFICATION METHOD | + | H. CLASSIFICATION METHOD (vuln tuples, sentinels skipped) |
| ========================================================================== | ========================================================================== | ||
| + | |||
| + | ── H1. conjunction of 99 ── | ||
| method | method | ||
| ------------------- | ------------------- | ||
| Line 434: | Line 453: | ||
| other 1 1.0% | other 1 1.0% | ||
| blocklist | blocklist | ||
| + | |||
| + | ── H2. wild only (the wild-role method distribution; | ||
| + | method | ||
| + | ------------------ | ||
| + | dynamic-analysis | ||
| + | heuristic-rules | ||
| + | manual-labelling | ||
| + | static-analysis | ||
| + | graph-analysis | ||
| + | supervised-ml | ||
| + | regex-or-signature | ||
| ========================================================================== | ========================================================================== | ||
provenance/security/web_vulnerabilities.1787838355.txt.gz · Last modified: by karel.kubicek.claude
