...
首页> 外文期刊>Advances in Electrical and Computer Engineering >WAPTT - Web Application Penetration Testing Tool
【24h】

WAPTT - Web Application Penetration Testing Tool

机译:WAPTT-Web应用程序渗透测试工具

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Web applications vulnerabilities allow attackers to perform malicious actions that range from gaining unauthorized account access to obtaining sensitive data. The number of reported web application vulnerabilities in last decade is increasing dramatically. The most of vulnerabilities result from improper input validation and sanitization. The most important of these vulnerabilities based on improper input validation and sanitization are: SQL injection (SQLI), Cross-Site Scripting (XSS) and Buffer Overflow (BOF). In order to address these vulnerabilities we designed and developed the WAPTT (Web Application Penetration Testing Tool) tool - web application penetration testing tool. Unlike other web application penetration testing tools, this tool is modular, and can be easily extended by end-user. In order to improve efficiency of SQLI vulnerability detection, WAPTT uses an efficient algorithm for page similarity detection. The proposed tool showed promising results as compared to six well-known web application scanners in detecting various web application vulnerabilities.
机译:Web应用程序漏洞使攻击者可以执行恶意操作,范围从获得未经授权的帐户访问到获取敏感数据。过去十年中报告的Web应用程序漏洞数量急剧增加。大部分漏洞是由不正确的输入验证和清理造成的。这些基于不正确的输入验证和清理而造成的漏洞中最重要的漏洞是:SQL注入(SQLI),跨站点脚本(XSS)和缓冲区溢出(BOF)。为了解决这些漏洞,我们设计和开发了WAPTT(Web应用程序渗透测试工具)工具-Web应用程序渗透测试工具。与其他Web应用程序渗透测试工具不同,此工具是模块化的,并且可由最终用户轻松扩展。为了提高SQLI漏洞检测的效率,WAPTT使用高效的算法进行页面相似性检测。与六种著名的Web应用程序扫描程序相比,该工具在检测各种Web应用程序漏洞方面显示出了可喜的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号