Web Hack List

Collected research

Toward Black-Box Detection of Logic Flaws in Web Applications

A black-box method that infers a behavioural model of a web application from recorded HTTP traces, abstracts requests into resources, then generates test cases that replay, reorder or skip steps to break the intended workflow. It exposes logic flaws in e-commerce software that allow shopping for free and hijacking another user's session.

Record

Researcher
Giancarlo Pellegrino and Davide Balzarotti
Published by
NDSS Symposium
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Giancarlo Pellegrino and Davide Balzarotti, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .