Talk With an Expert

Testing Web Application Security Scanners against a Web 2.0 Vulnerable Web Application

Testing Web Application Security Scanners against a Web 2.0 Vulnerable Web Application (PDF, 2.16MB)Published: 11 Oct, 2018
Created by
Edmund Foster

Web application security scanners are used to perform proactive security testing of web applications. Their effectiveness is far from certain, and few studies have tested them against modern 'Web 2.0' technologies which present significant challenges to scanners. In this study three web application security scanners are tested in 'point-and-shoot' mode against a Web 2.0 vulnerable web application with AJAX and HTML use cases. Significant variations in performance were observed and almost three-quarters of vulnerabilities went undetected. The web application security scanners did not identify Stored XSS, OS Command, Remote File Inclusion, and Integer Overflow vulnerabilities. This study supports the recommendation to combine multiple web application security scanners and use them in conjunction with a specific scanning strategy.