Claims
- 1. A method for detecting security vulnerabilities in a web application executing on a web server or web application server, the method comprising:
actuating the application in order to discover pre-defined elements of the application's interface with external clients; generating client requests having unauthorized values for said elements in order to generate exploits unique to the application; attacking the application using the exploits; and evaluating the results of the attack.
CROSS REFERENCE TO RELATED APPLICATIONS
[0001] This is a continuation of application Ser. No. 09/800,090, filed Mar. 5, 2001, now pending.
[0002] This application is related to U.S. Pat. No. 6,311,978, entitled Method and System for Extracting Application Protocol Characteristics, issued Oct. 30, 2001, which application is hereby incorporated herein by reference in its entity.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60186892 |
Mar 2000 |
US |
Continuations (1)
|
Number |
Date |
Country |
Parent |
09800090 |
Mar 2001 |
US |
Child |
10393497 |
Mar 2003 |
US |