Главная
Study mode:
on
1
Introduction
2
Agenda
3
About Me
4
Verizon Data Breach Report
5
Notable Web Breaches
6
Automated Web Application Scanning
7
Why Johnny Cant Pentest
8
Experiment Setup
9
Experiment Overview
10
Key Findings
11
Attack Vectors
12
Stored XSS
13
Solution
14
Known Pitfalls
15
CAPTCHAs
16
Multistep Logins
17
Surf Tokens
18
NonStandard Error Messages
19
NonStandard Protocol
20
Name Level Check
21
Component Security
Description:
Explore an in-depth investigation into the differences between web application scanning tools for detecting XSS and SQL injection vulnerabilities in this AppSecUSA 2017 conference talk. Delve into the challenges faced by automated scanners as web technologies evolve, using the 2015 TalkTalk hack as a case study to highlight the critical importance of secure web applications. Examine how various scanning tools attempt to identify dangerous vulnerabilities and the impact of modern development frameworks on their effectiveness. Learn about the problems scanners encounter with both traditional and contemporary web architectures, including issues like Anti-CSRF tokens, recursive links, and dynamically generated URLs. Gain insights into potential improvements for automated scanning and understand the pitfalls of relying solely on automation without applying intelligence and context. Benefit from the expertise of Robert Feeney, SecOps Lead at Edgescan, as he shares his knowledge on web application security and managed services. Read more

Differences Between Web Application Scanning Tools When Scanning for XSS and SQLi

OWASP Foundation
Add to list
0:00 / 0:00