Web Hack List

Collected research

State of the Art: Automated Black-Box Web Application Vulnerability Testing

Eight commercial black-box web scanners were run against Drupal, phpBB2 and WordPress builds with known bugs and against a purpose-built testbed of ~90 verified vulnerabilities. Reflected XSS was found at over 60%, but stored XSS reached only 15% and no scanner found any second-order SQL injection or planted malware. Scanners also failed to follow links inside Java, Flash and Silverlight.

Record

Researcher
Jason Bau, Elie Bursztein, Divij Gupta and John Mitchell
Published by
web.stanford.edu
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jason Bau, Elie Bursztein, Divij Gupta and John Mitchell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .