Black-Box assessment of Web systems security

M. Senesi · Research Repository (Delft University of Technology) · 2012

Many companies rely on Web applications to promote their services to the world. It is a logical step, as the Web offers great advantages such as convenience, low cost and instant reachability from anywhere in the world. Meanwhile Web applications tend to be implemented in an insecure way and the attacker does not even need to be too experienced to break into the companies over the Internet. Black-box penetration testing is very helpful in the assessment of Web systems security as it simulates such an attack. The aim of this thesis is to design and evaluate a structured methodology that any software developer can use to perform a black-box penetration test on Web systems to detect and prevent the most dangerous Web vulnerabilities.

Read the paper · More papers on PaperTik