WAPTT - Web Application Penetration Testing Tool

被引:3
|
作者
Duric, Zoran [1 ]
机构
[1] Univ Banja Luka, Fac Elect Engn, Banja Luka 78000, Bosnia & Herceg
关键词
databases; security; vulnerabilities; web sites; web applications;
D O I
10.4316/AECE.2014.01015
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Web applications vulnerabilities allow attackers to perform malicious actions that range from gaining unauthorized account access to obtaining sensitive data. The number of reported web application vulnerabilities in last decade is increasing dramatically. The most of vulnerabilities result from improper input validation and sanitization. The most important of these vulnerabilities based on improper input validation and sanitization are: SQL injection (SQLI), Cross-Site Scripting (XSS) and Buffer Overflow (BOF). In order to address these vulnerabilities we designed and developed the WAPTT (Web Application Penetration Testing Tool) tool - web application penetration testing tool. Unlike other web application penetration testing tools, this tool is modular, and can be easily extended by end-user. In order to improve efficiency of SQLI vulnerability detection, WAPTT uses an efficient algorithm for page similarity detection. The proposed tool showed promising results as compared to six well-known web application scanners in detecting various web application vulnerabilities.
引用
收藏
页码:93 / 102
页数:10
相关论文
共 50 条
  • [1] A Survey on Web Application Penetration Testing
    Altulaihan, Esra Abdullatif
    Alismail, Abrar
    Frikha, Mounir
    ELECTRONICS, 2023, 12 (05)
  • [2] Vulnerability Assessment and Penetration Testing of Web Application
    Nagpure, Sangeeta
    Kurkure, Sonal
    2017 INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, CONTROL AND AUTOMATION (ICCUBEA), 2017,
  • [3] Penetration Testing in Application Using TestNG Tool
    Sharma, Bhawna
    Johari, Rahul
    Lecture Notes in Networks and Systems, 2023, 572 : 1 - 11
  • [4] Smoke Testing of Web Application Based on ALM Tool
    Khan, Rijwan
    Amjad, Mohd
    2016 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2016, : 862 - 866
  • [5] A tool to support automated testing for web application scenario
    Cheng-Hui Huang
    Huo Yan Chen
    2006 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS, VOLS 1-6, PROCEEDINGS, 2006, : 2179 - +
  • [6] Research and Realization on the Performance Testing Tool of Web Application
    Wu, Huarui
    Zhu, Huaji
    COMPUTER AND COMPUTING TECHNOLOGIES IN AGRICULTURE XI, PT I, 2019, 545 : 375 - 383
  • [7] A Cross-browser Web Application Testing Tool
    Choudhary, Shauvik Roy
    Versee, Husayn
    Orso, Alessandro
    2010 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE, 2010,
  • [8] Work in Progress - Web Penetration Testing: Effectiveness of Student Learning in Web Application Security
    Kam, Hwee-Joo
    Pauli, Joshua J.
    2011 FRONTIERS IN EDUCATION CONFERENCE (FIE), 2011,
  • [9] Penetration Testing for Web Services
    Antunes, Nuno
    Vieira, Marco
    COMPUTER, 2014, 47 (02) : 30 - 36
  • [10] WebGuardia - An Integrated Penetration Testing System to Detect Web Application Vulnerabilities
    Vithanage, Nisal Madhushan
    Jeyamohan, Neera
    PROCEEDINGS OF THE 2016 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET), 2016, : 221 - 227