Authors:
Natan Talon
1
;
Valérie Tong
2
;
Gilles Guette
3
;
Yufei Han
4
and
Youssef Laarouchi
1
Affiliations:
1
Hackuity, Lyon, France
;
2
CentraleSupélec, Rennes, France
;
3
Université de Rennes, Rennes, France
;
4
Inria, Rennes, France
Keyword(s):
Pentest Automation, Web Application.
Abstract:
A wide array of techniques and tools can be employed for web application security assessment. Some methods, such as fuzzers and scanners, are partially or fully automated, offering speed and cost-effectiveness. However, these tools often fall short in detecting specific vulnerabilities like broken access control and are prone to generating false positives. On the other hand, manual processes like penetration testing, though more time-consuming and necessitating expertise, provide a more comprehensive risk assessment. To overcome the limitations of automated tools, these techniques are frequently combined. Fuzzers and scanners, despite their ease of use and quick results, require the expertise of penetration testing experts to address their limitations. By integrating these approaches, a more robust and nuanced security assessment can be achieved. This article presents SCWAD, an automated and customizable penetration testing framework designed to assess vulnerabilities in web applicat
ions.
(More)