WAPTT - Web Application Penetration Testing Tool

被引:3
|
作者
Duric, Zoran [1 ]
机构
[1] Univ Banja Luka, Fac Elect Engn, Banja Luka 78000, Bosnia & Herceg
关键词
databases; security; vulnerabilities; web sites; web applications;
D O I
10.4316/AECE.2014.01015
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Web applications vulnerabilities allow attackers to perform malicious actions that range from gaining unauthorized account access to obtaining sensitive data. The number of reported web application vulnerabilities in last decade is increasing dramatically. The most of vulnerabilities result from improper input validation and sanitization. The most important of these vulnerabilities based on improper input validation and sanitization are: SQL injection (SQLI), Cross-Site Scripting (XSS) and Buffer Overflow (BOF). In order to address these vulnerabilities we designed and developed the WAPTT (Web Application Penetration Testing Tool) tool - web application penetration testing tool. Unlike other web application penetration testing tools, this tool is modular, and can be easily extended by end-user. In order to improve efficiency of SQLI vulnerability detection, WAPTT uses an efficient algorithm for page similarity detection. The proposed tool showed promising results as compared to six well-known web application scanners in detecting various web application vulnerabilities.
引用
收藏
页码:93 / 102
页数:10
相关论文
共 50 条
  • [21] Customizable landscape visualizations. Implementation, application and testing of a web-based tool
    Morrison, K.W.
    Purves, R.S.
    Computers, Environment and Urban Systems, 26 (2-3): : 163 - 183
  • [22] Web application bypass testing
    Offutt, J
    Wu, Y
    Du, XC
    Huang, H
    PROCEEDINGS OF THE 28TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATION CONFERENCE, WORKSHOP AND FAST ABSTRACTS, 2004, : 106 - 109
  • [23] Web Application Fuzz Testing
    Andrianto, Ivan
    Liem, M. M. Inggriani
    Asnar, Yudistira Dwi Wardhana
    PROCEEDINGS OF 2017 INTERNATIONAL CONFERENCE ON DATA AND SOFTWARE ENGINEERING (ICODSE), 2017,
  • [24] Web application bypass testing
    Information and Software Engineering, George Mason University, Fairfax, VA 22030, United States
    1600, 106-109 (2004):
  • [25] A Comparative Study of Web Application Testing and Mobile Application Testing
    Ahmed, Maryam
    Ibrahim, Rosziati
    ADVANCED COMPUTER AND COMMUNICATION ENGINEERING TECHNOLOGY, 2015, 315 : 491 - 500
  • [26] PENTOS: Penetration Testing Tool for Internet of Thing Devices
    Visoottiviseth, Vasaka
    Akarasiriwong, Phuripat
    Chaiyasart, Siravitch
    Chotivatunyu, Siravit
    TENCON 2017 - 2017 IEEE REGION 10 CONFERENCE, 2017, : 2279 - 2284
  • [27] Tool Based Implementation of SQL Injection for Penetration Testing
    Nagpal, Bharti
    Chauhan, Naresh
    Singh, Nanhay
    Panesar, Angel
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION & AUTOMATION (ICCCA), 2015, : 746 - 749
  • [28] Uzilla: A new tool for Web usability testing
    Edmonds, A
    BEHAVIOR RESEARCH METHODS INSTRUMENTS & COMPUTERS, 2003, 35 (02): : 194 - 201
  • [29] Uzilla: A new tool for Web usability testing
    Andy Edmonds
    Behavior Research Methods, Instruments, & Computers, 2003, 35 : 194 - 201
  • [30] WebMark: A tool for testing Web server performance
    Zhang, Guang-Yan
    Zheng, Ming-Yang
    Ju, Jiu-Bin
    Ruan Jian Xue Bao/Journal of Software, 2003, 14 (07): : 1318 - 1323