Jump to content
Nytro

HackMiami Web Application Scanner 2013 PwnOff

Recommended Posts

Posted

HackMiami Web Application Scanner 2013 PwnOff

An Analysis of Automated Web Application Scanning Suites

James Ball, Alexander Heid, Rod Soto

Hack Miami –

Overview

Web application scanning suites have become commonplace within the information security

industry. There are many open-source and free scanning suites available, as well as a wide

array of commercially licensed scanning suites. Often these suites are marketed as automated

and simple to use. The notion is that a user can point the tool at a URL and the software will rip

the site apart, seeking out vulnerabilities such as SQL injections, Cross Site Scripting (XSS),

and other common web application security issues.

Successful exploitation of vulnerabilities such as SQLi and XSS can lead to the compromise of

data. The impact of the compromise can be minimal to catastrophic. Even the reputational

impact of minimal breaches can still be significant to an organization.

This document is an analysis of the performance of five common web application scanners,

which were put against three different types of web applications. The document will provide as

an evaluation of the web application scanner suites from installation to the completion of the

scan, and will rate the suites on multiple criteria.

The Web Application PwnOff was a live event that took place at the HackMiami 2013 Hackers

Conference in Miami Beach Florida. There were three target web applications, one PHP based,

one JSP based and one .NET based. The scans consisted of a single pre-authentication scan,

and a single post-authentication scan against each user level. Rating scores will be on a scale

of 1 (lowest) to 5 (highest).

Download:

http://hackmiami.org/whitepapers/HackMiami2013PwnOff.pdf

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...