...
首页> 外文期刊>International Journal of Information Technology and Computer Science >Web Vulnerability Finder (WVF): Automated Black- Box Web Vulnerability Scanner
【24h】

Web Vulnerability Finder (WVF): Automated Black- Box Web Vulnerability Scanner

机译:Web漏洞发现器(WVF):自动黑盒Web漏洞扫描仪

获取原文
           

摘要

Today the internet has become primary source of communication among people because it holds limitless space and pool of various web applications and resources. The internet allows us to communicate in a fraction of second with another people who is sitting in the other part of the world. At present, the internet has become part of our daily life and its usage is increasing exponentially, therefore it accumulates a number of web applications on daily basis on Web podium. Most of the web applications exist with few weaknesses and that weaknesses give room to several bad buys (hackers) to interrupt that weak part of code in web applications. Recently, SQL Injection, Cross Site Scripting (XSS) and Cross Site Request Forgery (CSRF) seriously threaten the most of the web applications. In this study, we have proposed a black box testing method to detect different web vulnerabilities such as SQL Injection, XSS and CSRF and developed a detection tool i.e. Web Vulnerabilities Finder (WVF) for most of these vulnerabilities. Our proposed method can automatically analyze websites with the aim of finding web vulnerabilities. By applying the tool to some websites, we have found 45 exploitable XSS, SQL Injection 45, Directory Discloser 38 and Local/remote file inclusion 40 vulnerabilities. The experimental results show that our tool can efficiently detect XSS, SQL Injection, Directory Discloser and LFI/RFI vulnerabilities.
机译:今天,互联网已成为人们之间的主要沟通来源,因为它拥有无限的空间和各种Web应用程序和资源的池。互联网使我们能够与另一个坐在世界其他地方的人的一小部分中沟通。目前,互联网已成为我们日常生活的一部分,它的使用量正在呈指数增长,因此它在Web讲台上每天累积了许多Web应用程序。大多数Web应用程序都存在少量弱点,并且缺点为几个错误的购买(黑客)提供了几个错误的购买(黑客),以中断Web应用程序中的代码部分弱部分。最近,SQL注入,横向站点脚本(XSS)和跨站点请求伪造(CSRF)严重威胁到大多数Web应用程序。在这项研究中,我们提出了一种黑匣子测试方法,用于检测不同的Web漏洞,如SQL注入,XS和CSRF,并为大多数这些漏洞开发了一个检测工具I.E.Web漏洞查找器(WVF)。我们所提出的方法可以自动分析网站,目的是找到网站漏洞。通过将工具应用于某些网站,我们发现了45个可利用的XSS,SQL注入45,目录披露者38和本地/远程文件包含40漏洞。实验结果表明,我们的工具可以有效地检测XSS,SQL注入,目录披露者和LFI / RFI漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号