Unlocking User-oriented Pages: Intention-driven Black-box Scanner for Real-world Web Applications
Fuente:
arXiv
Guardado en:
| Autores principales: | Wang, Weizhe, Zhang, Yao, Liang, Kaitai, Xu, Guangquan, Bai, Hongpeng, Yan, Qingyang, Zheng, Xi, Wu, Bin |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
por: Wang, Weizhe, et al.
Publicado: (2025)
por: Wang, Weizhe, et al.
Publicado: (2025)
Unpacking Security Scanners for GitHub Actions Workflows
por: Fares, Madjda, et al.
Publicado: (2026)
por: Fares, Madjda, et al.
Publicado: (2026)
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
por: Rosso, Martin, et al.
Publicado: (2025)
por: Rosso, Martin, et al.
Publicado: (2025)
AndroScanner: Automated Backend Vulnerability Detection for Android Applications
por: Dandu, Harini
Publicado: (2026)
por: Dandu, Harini
Publicado: (2026)
A Survey of Web Application Security Tutorials
por: Chembakottu, Bhagya, et al.
Publicado: (2026)
por: Chembakottu, Bhagya, et al.
Publicado: (2026)
Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
por: Liu, Yi, et al.
Publicado: (2026)
por: Liu, Yi, et al.
Publicado: (2026)
What Makes a Good LLM Agent for Real-world Penetration Testing?
por: Deng, Gelei, et al.
Publicado: (2026)
por: Deng, Gelei, et al.
Publicado: (2026)
Fuzzing Frameworks for Server-side Web Applications: A Survey
por: Dharmaadi, I Putu Arya, et al.
Publicado: (2024)
por: Dharmaadi, I Putu Arya, et al.
Publicado: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
por: Liu, Bin, et al.
Publicado: (2025)
por: Liu, Bin, et al.
Publicado: (2025)
BACFuzz: Exposing the Silence on Broken Access Control Vulnerabilities in Web Applications
por: Dharmaadi, I Putu Arya, et al.
Publicado: (2025)
por: Dharmaadi, I Putu Arya, et al.
Publicado: (2025)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
por: Yang, Guan-Yan, et al.
Publicado: (2025)
por: Yang, Guan-Yan, et al.
Publicado: (2025)
AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications
por: Yang, Ruozhao, et al.
Publicado: (2026)
por: Yang, Ruozhao, et al.
Publicado: (2026)
Closing the Gap: A User Study on the Real-world Usefulness of AI-powered Vulnerability Detection & Repair in the IDE
por: Steenhoek, Benjamin, et al.
Publicado: (2024)
por: Steenhoek, Benjamin, et al.
Publicado: (2024)
Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation
por: Guo, Ziyi, et al.
Publicado: (2024)
por: Guo, Ziyi, et al.
Publicado: (2024)
MobFuzz: Adaptive Multi-objective Optimization in Gray-box Fuzzing
por: Zhang, Gen, et al.
Publicado: (2024)
por: Zhang, Gen, et al.
Publicado: (2024)
An Empirical Study on the Distance Metric in Guiding Directed Grey-box Fuzzing
por: Wen, Tingke, et al.
Publicado: (2024)
por: Wen, Tingke, et al.
Publicado: (2024)
Unity is Strength: Enhancing Precision in Reentrancy Vulnerability Detection of Smart Contract Analysis Tools
por: Wang, Zexu, et al.
Publicado: (2024)
por: Wang, Zexu, et al.
Publicado: (2024)
PrescientFuzz: A more effective exploration approach for grey-box fuzzing
por: Blackwell, Daniel, et al.
Publicado: (2024)
por: Blackwell, Daniel, et al.
Publicado: (2024)
SeeWasm: An Efficient and Fully-Functional Symbolic Execution Engine for WebAssembly Binaries
por: He, Ningyu, et al.
Publicado: (2024)
por: He, Ningyu, et al.
Publicado: (2024)
DogeFuzz: A Simple Yet Efficient Grey-box Fuzzer for Ethereum Smart Contracts
por: Medeiros, Ismael, et al.
Publicado: (2024)
por: Medeiros, Ismael, et al.
Publicado: (2024)
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
por: Hassanshahi, Behnaz, et al.
Publicado: (2025)
por: Hassanshahi, Behnaz, et al.
Publicado: (2025)
Beyond BeautifulSoup: Benchmarking LLM-Powered Web Scraping for Everyday Users
por: Bhardwaj, Arth, et al.
Publicado: (2026)
por: Bhardwaj, Arth, et al.
Publicado: (2026)
VDGraph: A Graph-Theoretic Approach to Unlock Insights from SBOM and SCA Data
por: Xia, Howell, et al.
Publicado: (2025)
por: Xia, Howell, et al.
Publicado: (2025)
Software Supply Chain Security of Web3
por: Monperrus, Martin
Publicado: (2025)
por: Monperrus, Martin
Publicado: (2025)
Testing Access-Control Configuration Changes for Web Applications
por: Xiang, Chengcheng, et al.
Publicado: (2025)
por: Xiang, Chengcheng, et al.
Publicado: (2025)
Leveraging Large Language Models for Command Injection Vulnerability Analysis in Python: An Empirical Study on Popular Open-Source Projects
por: Wang, Yuxuan, et al.
Publicado: (2025)
por: Wang, Yuxuan, et al.
Publicado: (2025)
Understanding the Supply Chain and Risks of Large Language Model Applications
por: Ma, Yujie, et al.
Publicado: (2025)
por: Ma, Yujie, et al.
Publicado: (2025)
ThreatIntel-Andro: Expert-Verified Benchmarking for Robust Android Malware Research
por: Bai, Hongpeng, et al.
Publicado: (2025)
por: Bai, Hongpeng, et al.
Publicado: (2025)
A User-centered Security Evaluation of Copilot
por: Asare, Owura, et al.
Publicado: (2023)
por: Asare, Owura, et al.
Publicado: (2023)
One Signature, Multiple Payments: Demystifying and Detecting Signature Replay Vulnerabilities in Smart Contracts
por: Wang, Zexu, et al.
Publicado: (2025)
por: Wang, Zexu, et al.
Publicado: (2025)
Automated Testing of Broken Authentication Vulnerabilities in Web APIs with AuthREST
por: Corradini, Davide, et al.
Publicado: (2025)
por: Corradini, Davide, et al.
Publicado: (2025)
Building Call Graph of WebAssembly Programs via Abstract Semantics
por: Paccamiccio, Mattia, et al.
Publicado: (2024)
por: Paccamiccio, Mattia, et al.
Publicado: (2024)
Towards a decentralized data privacy protocol for self-sovereignty in the digital world
por: Falcão, Rodrigo, et al.
Publicado: (2024)
por: Falcão, Rodrigo, et al.
Publicado: (2024)
CNT: Safety-oriented Function Reuse across LLMs via Cross-Model Neuron Transfer
por: Zhao, Yue, et al.
Publicado: (2026)
por: Zhao, Yue, et al.
Publicado: (2026)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
por: Huang, Youwei, et al.
Publicado: (2025)
por: Huang, Youwei, et al.
Publicado: (2025)
Do Privacy Policies Match with the Logs? An Empirical Study of Privacy Disclosure in Android Application Logs
por: Chen, Zhiyuan, et al.
Publicado: (2026)
por: Chen, Zhiyuan, et al.
Publicado: (2026)
Hyperfuzzing: black-box security hypertesting with a grey-box fuzzer
por: Blackwell, Daniel, et al.
Publicado: (2023)
por: Blackwell, Daniel, et al.
Publicado: (2023)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
por: Ning, Kaiwen, et al.
Publicado: (2024)
por: Ning, Kaiwen, et al.
Publicado: (2024)
Exploring User Privacy Awareness on GitHub: An Empirical Study
por: Alfieri, Costanza, et al.
Publicado: (2024)
por: Alfieri, Costanza, et al.
Publicado: (2024)
Transparency in App Analytics: Analyzing the Collection of User Interaction Data
por: Tang, Feiyang, et al.
Publicado: (2023)
por: Tang, Feiyang, et al.
Publicado: (2023)
Ejemplares similares
-
VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities
por: Wang, Weizhe, et al.
Publicado: (2025) -
Unpacking Security Scanners for GitHub Actions Workflows
por: Fares, Madjda, et al.
Publicado: (2026) -
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
por: Rosso, Martin, et al.
Publicado: (2025) -
AndroScanner: Automated Backend Vulnerability Detection for Android Applications
por: Dandu, Harini
Publicado: (2026) -
A Survey of Web Application Security Tutorials
por: Chembakottu, Bhagya, et al.
Publicado: (2026)