WAPTT - Web Application Penetration Testing Tool

被引:3
|
作者
Duric, Zoran [1 ]
机构
[1] Univ Banja Luka, Fac Elect Engn, Banja Luka 78000, Bosnia & Herceg
关键词
databases; security; vulnerabilities; web sites; web applications;
D O I
10.4316/AECE.2014.01015
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Web applications vulnerabilities allow attackers to perform malicious actions that range from gaining unauthorized account access to obtaining sensitive data. The number of reported web application vulnerabilities in last decade is increasing dramatically. The most of vulnerabilities result from improper input validation and sanitization. The most important of these vulnerabilities based on improper input validation and sanitization are: SQL injection (SQLI), Cross-Site Scripting (XSS) and Buffer Overflow (BOF). In order to address these vulnerabilities we designed and developed the WAPTT (Web Application Penetration Testing Tool) tool - web application penetration testing tool. Unlike other web application penetration testing tools, this tool is modular, and can be easily extended by end-user. In order to improve efficiency of SQLI vulnerability detection, WAPTT uses an efficient algorithm for page similarity detection. The proposed tool showed promising results as compared to six well-known web application scanners in detecting various web application vulnerabilities.
引用
收藏
页码:93 / 102
页数:10
相关论文
共 50 条
  • [41] On the need for teaching Web application testing
    Parveen, Tauhida
    Tilley, Scott
    Gonzalez, George
    WSE 2007: NINTH IEEE INTERNATIONAL SYMPOSIUM ON WEB SITE EVOLUTION, PROCEEDINGS, 2007, : 51 - +
  • [42] Analysis for Cloud Testing of Web Application
    Cai, Jianhua
    Hu, Qingchun
    2014 2ND INTERNATIONAL CONFERENCE ON SYSTEMS AND INFORMATICS (ICSAI), 2014, : 293 - 297
  • [43] Web services testing, the methodology, and the implementation of the automation-testing tool
    Li, Y
    Li, ML
    Yu, JA
    GRID AND COOPERATIVE COMPUTING, PT 1, 2004, 3032 : 940 - 947
  • [44] Using TTCN-3 as a Modeling Language for Web Penetration Testing
    Stepien, Bernard
    Peyton, Liam
    Xiong, Pulei
    2012 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL TECHNOLOGY (ICIT), 2012, : 674 - 681
  • [45] JSON Web Token Penetration Testing on Cookie Storage with CSRF Techniques
    Telkom University, Department of Information System, Bandung, Indonesia
    不详
    Int. Conf. Adv. Data Sci., E-Learn. Inf. Syst., ICADEIS, 2021,
  • [46] Intelligent Web Security Testing with Threat Assessment and Client Server Penetration
    Gohel, Hardik
    Sharma, Priyanka
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON ICT FOR SUSTAINABLE DEVELOPMENT ICT4SD 2015, VOL 2, 2016, 409 : 555 - 568
  • [47] SMRL: A Metamorphic Security Testing Tool for Web Systems
    Mai, Phu X.
    Goknil, Arda
    Pastore, Fabrizio
    Briand, Lionel C.
    2020 ACM/IEEE 42ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS (ICSE-COMPANION 2020), 2020, : 9 - 12
  • [48] Kaleidoscope: A Crowdsourcing Testing Tool for Web Quality of Experience
    Wang, Pengfei
    Varvello, Matteo
    Kuzmanovic, Aleksandar
    2019 39TH IEEE INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2019), 2019, : 1971 - 1982
  • [49] SQLi Penetration Testing of Financial Web Applications: Investigation of Bangladesh Region
    Farah, Tanjila
    Alain, Delwar
    Kabir, Alamgir
    Bhuiyan, Touhid
    2015 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2015, : 146 - 151
  • [50] Penetration Testing of 5G Core Network Web Technologies
    Giambartolomei, Filippo
    Barcelo, Marc
    Brighente, Alessandro
    Urbieta, Aitor
    Conti, Mauro
    ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2024, : 702 - 707