Collected research
Enemy of the State: A State-Aware Black-Box Web Vulnerability Scanner
Black-box scanners miss vulnerabilities because they ignore server-side state. The authors infer a web application's state machine from the outside by navigating it, comparing output differences and incrementally building a model. They drive a crawler and fuzzer from that model, reaching more application code and finding flaws other scanners miss.
Record
- Researcher
- Adam Doupé, Ludovico Cavedon, Christopher Kruegel and Giovanni Vigna
- Published by
- usenix.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Doupé, Ludovico Cavedon, Christopher Kruegel and Giovanni Vigna, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .