Cross-site scripting (XSS) vulnerabilities are significant threats to web applications. The number of XSS vulnerabilities reported has increased annually for the past three years, posing a considerable challenge to web application maintainers. Black-box scanners are mainstream tools for security engineers to perform penetration testing and detect XSS vulnerabilities. Unfortunately, black-box scanners rely on crawlers to find input points of web applications and cannot guarantee all input points are tested. To this end, we propose a grey-box fuzzing method based on reinforcement learning, which can detect reflected and stored XSS vulnerabilities for Java web applications. We first use static analysis to identify potential input points from c...
International audienceIn this technological era, many of the applications are taking the utilization...
Workshop website: http://www.spacios.eu/sectest2012/International audienceWe present an approach to ...
Web applications support many of our daily activities, but they of-ten have security problems, and t...
International audienceWe present a black-box based smart fuzzing approach to detect cross-site scrip...
Testing is a viable approach for detecting implementation bugs which have a security impact, a.k.a. ...
Web application vulnerabilities are an ongoing problem that current black-box techniques and scanner...
Context Cross site scripting (XSS) vulnerability is among the top web application vulnerabilities...
Testing is a viable approach for detecting implementation bugswhich have a security impact, a.k.a. v...
Poster - http://www.syssec-project.eu/events/2nd-syssec-workshop/information/Poster presented at Sys...
Cross-Site Scripting (XSS) vulnerabilities are among the most common and most serious security vulne...
Part 6: Software VulnerabilitiesInternational audienceBlack-box vulnerability scanners can miss a no...
exists in most web sites. The main reason is the lack of effective validation and filtering mechanis...
Most of the people in the industrial world are using several web applications every day. Many of tho...
Cross Site Scripting (XSS) is a vulnerability of a Web Application that is essentially caused by the...
Software security vulnerabilities have led to many successful attacks on applications, especially we...
International audienceIn this technological era, many of the applications are taking the utilization...
Workshop website: http://www.spacios.eu/sectest2012/International audienceWe present an approach to ...
Web applications support many of our daily activities, but they of-ten have security problems, and t...
International audienceWe present a black-box based smart fuzzing approach to detect cross-site scrip...
Testing is a viable approach for detecting implementation bugs which have a security impact, a.k.a. ...
Web application vulnerabilities are an ongoing problem that current black-box techniques and scanner...
Context Cross site scripting (XSS) vulnerability is among the top web application vulnerabilities...
Testing is a viable approach for detecting implementation bugswhich have a security impact, a.k.a. v...
Poster - http://www.syssec-project.eu/events/2nd-syssec-workshop/information/Poster presented at Sys...
Cross-Site Scripting (XSS) vulnerabilities are among the most common and most serious security vulne...
Part 6: Software VulnerabilitiesInternational audienceBlack-box vulnerability scanners can miss a no...
exists in most web sites. The main reason is the lack of effective validation and filtering mechanis...
Most of the people in the industrial world are using several web applications every day. Many of tho...
Cross Site Scripting (XSS) is a vulnerability of a Web Application that is essentially caused by the...
Software security vulnerabilities have led to many successful attacks on applications, especially we...
International audienceIn this technological era, many of the applications are taking the utilization...
Workshop website: http://www.spacios.eu/sectest2012/International audienceWe present an approach to ...
Web applications support many of our daily activities, but they of-ten have security problems, and t...