发明申请
US20130055397A1 DETECTING STORED CROSS-SITE SCRIPTING VULNERABILITIES IN WEB APPLICATIONS
有权
在WEB应用程序中检测存储的跨站点脚本的漏洞
- 专利标题: DETECTING STORED CROSS-SITE SCRIPTING VULNERABILITIES IN WEB APPLICATIONS
- 专利标题(中): 在WEB应用程序中检测存储的跨站点脚本的漏洞
-
申请号: US13217418申请日: 2011-08-25
-
公开(公告)号: US20130055397A1公开(公告)日: 2013-02-28
- 发明人: YAIR AMIT , ALEXANDER LANDA , OMER TRIPP
- 申请人: YAIR AMIT , ALEXANDER LANDA , OMER TRIPP
- 申请人地址: US NY ARMONK
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY ARMONK
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A system for detecting security vulnerabilities in web applications, the system including, a black-box tester configured to provide a payload to a web application during a first interaction with the web application at a computer server, where the payload includes a payload instruction and an identifier, and an execution engine configured to detect the identifier within the payload received during an interaction with the web application subsequent to the first interaction, and determine, responsive to detecting the identifier within the payload, whether the payload instruction underwent a security check prior to execution of the payload instruction.
公开/授权文献
信息查询