Exploration of the Attacking Web Vectors

Tea Osmëni, Maaruf Ali · 2021

Most people in the industrial world use a wide variety of web applications daily with the majority being insecure and vulnerable. This gives hackers the opportunity to steal data from the user’s web application, which may contain sensitive information. Vulnerability detection may be conducted by a rigorous penetration test. A penetration tester’s duty is to define and exploit the web applications’ vulnerabilities.This paper describes a technique for automatic vulnerable web application generation application. Firstly, the prepared web application is sent to the tool to create the vulnerable web application version. This tool does this by the injection of Cross Site Request Forgery (CSRF) and Cross Site Scripting (XSS) into the web application. Different variant vulnerabilities may be injected too, so different methods are needed, in order to exploit vulnerabilities dependent on the variant. One of the tool’s tasks is to produce web applications, which will be used to train the penetration testers.

Read the paper · More papers on PaperTik