首页>
外国专利>
Testing web applications for file upload vulnerabilities
Testing web applications for file upload vulnerabilities
展开▼
机译:测试Web应用程序的文件上传漏洞
展开▼
页面导航
摘要
著录项
相似文献
摘要
A system for detecting file upload vulnerabilities in web applications is provided. The system may include a black-box tester configured to upload, via a file upload interface exposed by a web application, a file together with a signature associated with the file. An execution monitor may be configured to receive information provided by instrumentation instructions within the web application during the execution of the web application. The execution monitor may be configured to recognize the signature of the uploaded file as indicating that the uploaded file was uploaded by the black-box tester. The execution monitor may also be configured to use any of the information to make at least one predefined determination assessing the vulnerability of the web application to a file upload exploit.
展开▼