首页> 外国专利> Testing web applications for file upload vulnerabilities

Testing web applications for file upload vulnerabilities

机译:测试Web应用程序的文件上传漏洞

摘要

A system for detecting file upload vulnerabilities in web applications is provided. The system may include a black-box tester configured to upload, via a file upload interface exposed by a web application, a file together with a signature associated with the file. An execution monitor may be configured to receive information provided by instrumentation instructions within the web application during the execution of the web application. The execution monitor may be configured to recognize the signature of the uploaded file as indicating that the uploaded file was uploaded by the black-box tester. The execution monitor may also be configured to use any of the information to make at least one predefined determination assessing the vulnerability of the web application to a file upload exploit.
机译:提供了一种用于检测Web应用程序中的文件上传漏洞的系统。该系统可以包括黑匣子测试器,该黑匣子测试器被配置为经由网络应用公开的文件上传接口来上传文件以及与该文件相关联的签名。执行监视器可以被配置为在网络应用的执行期间接收由网络应用内的仪器指令提供的信息。执行监视器可以被配置为识别上载文件的签名,以指示该上载文件是由黑盒测试器上载的。执行监控器还可以配置为使用任何信息来做出至少一个预定义确定,以评估Web应用程序对文件上传漏洞的脆弱性。

著录项

  • 公开/公告号US9009841B2

    专利类型

  • 公开/公告日2015-04-14

    原文格式PDF

  • 申请/专利权人 YAIR AMIT;ROEE HAY;ROI SALTZMAN;

    申请/专利号US201213435361

  • 发明设计人 ROI SALTZMAN;YAIR AMIT;ROEE HAY;

    申请日2012-03-30

  • 分类号G06F21/00;H04L29/06;G06F21/57;G06F21/60;

  • 国家 US

  • 入库时间 2022-08-21 15:19:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号