Web Hack List

Collected research

Enemy of the State: A State-Aware Black-Box Web Vulnerability Scanner

Black-box scanners miss vulnerabilities because they ignore server-side state. The authors infer a web application's state machine from the outside by navigating it, comparing output differences and incrementally building a model. They drive a crawler and fuzzer from that model, reaching more application code and finding flaws other scanners miss.

Record

Researcher
Adam Doupé, Ludovico Cavedon, Christopher Kruegel and Giovanni Vigna
Published by
usenix.org
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Doupé, Ludovico Cavedon, Christopher Kruegel and Giovanni Vigna, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .