Collected research
State of the Art: Automated Black-Box Web Application Vulnerability Testing
Eight commercial black-box web scanners were run against Drupal, phpBB2 and WordPress builds with known bugs and against a purpose-built testbed of ~90 verified vulnerabilities. Reflected XSS was found at over 60%, but stored XSS reached only 15% and no scanner found any second-order SQL injection or planted malware. Scanners also failed to follow links inside Java, Flash and Silverlight.
Record
- Researcher
- Jason Bau, Elie Bursztein, Divij Gupta and John Mitchell
- Published by
- web.stanford.edu
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jason Bau, Elie Bursztein, Divij Gupta and John Mitchell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .