Web Application Vulnerabilities - The Hacker's Treasure

K. Nirmal, B. Janet, R. Kumar · 2018 International Conference on Inventive Research in Computing Applications (ICIRCA) · 2018

In today's online era, a web application is an integral part of every business. A web application may be a single page HTML website or a large web portal that offers various services on a web browser. There are many tools and methodologies that are relied upon to develop a web application. The development methodologies incorporate specialized frameworks, libraries in order to have the application more standardized and have it developed at a rapid pace to meet market demands. Web applications (web app) are hardened to mitigate security issues which are commonly referred as web application vulnerabilities. A web app security vulnerability is any kind of loop hole that allows an attacker to break into the web application to perform undesired actions on the target website. This may range from a cross site scripting (XSS) to vulnerabilities like Server Side Request Forger (SSRF) and its implications like XML External Entity (XXE). Though web applications are hardened to mitigate vulnerabilities, large scale web applications are still vulnerable post release in most cases. As a part of security research, critical vulnerabilities on large scale web applications were identified and the same were reported to the concerned security research team. The reporting was acknowledged and mitigated through appropriate channels. Common Vulnerabilities and Exposures (CVEs) were filed on Microsoft and CISCO products and the same were logged in National Vulnerability Database (NVD). Insights and tenets regarding web application and its vulnerabilities are highlighted in this manuscript.

Read the paper · More papers on PaperTik