System and method for providing application penetration testing

A system and method provide application penetration testing. The system contains logic configured to find at least one vulnerability in the application so as to gain access to data associated with the application, logic configured to confirm the vulnerability and determine if the application can be...

Full description

Saved in:
Bibliographic Details
Main Authors WAISSBEIN ARIEL, MANRIQUE HECTOR ADRIAN, RUSS FERNANDO FEDERICO, FUTORANSKY ARIEL, CUFRE SEBASTIAN PABLO, BRZOSTOWSKI AXEL ELIAN, TISCORNIA DIEGO BARTOLOME, DE ACHA CAMPOS JAVIER RICARDO, ARIAS EDUARDO, RICHARTE GERARDO GABRIEL, SOLINO TESTA ALBERTO GUSTAVO, KELYACOUBIAN DIEGO MARTIN
Format Patent
LanguageEnglish
Published 09.07.2013
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:A system and method provide application penetration testing. The system contains logic configured to find at least one vulnerability in the application so as to gain access to data associated with the application, logic configured to confirm the vulnerability and determine if the application can be compromised, and logic configured to compromise and analyze the application by extracting or manipulating data from a database associated with the application. In addition, the method provides for penetration testing of a target by: receiving at least one confirmed vulnerability of the target; receiving a method for compromising the confirmed vulnerability of the target; installing a network agent on the target in accordance with the method, wherein the network agent allows a penetration tester to execute arbitrary operating system commands on the target; and executing the arbitrary operating system commands on the target to analyze risk to which the target may be exposed.
Bibliography:Application Number: US20080043673