DSpace Repository

Design and Develop Automated Detection of Three Common Broken Authentication Vulnerabilities

Show simple item record

dc.contributor.author Islam, S.M. Towhidul
dc.date.accessioned 2022-12-28T07:27:35Z
dc.date.available 2022-12-28T07:27:35Z
dc.date.issued 22-11-07
dc.identifier.uri http://dspace.daffodilvarsity.edu.bd:8080/handle/123456789/9281
dc.description.abstract The purpose of this thesis is to present a new tool for detecting common web attacks that lead to web application information disclosure, primarily through improper authentication and session management. It provides a flexible URL search engine that scans HTTP requests and responses during web page delivery and records the necessary data without impacting web server performance. New tools can detect attacks using HTTP responses such as Post and Get methods. And by investigating all factors, we are looking for satisfactory results. The new tools are highly extensible, allowing for future work. Web applications are consistently used on a consistent schedule. Web applications are experiencing security risks and breaches these days. Security analysts, companies, and organizations are working together to stop, or at least mitigate, these attacks and dangers. The Open Web Application Security Project (OWASP) is a non-profit security association that discovered and ordered ten attacks against vulnerabilities affecting her web applications today. Suspended reviews and executive weakness attacks are the next top attacks in the report listed in OWASP. This white thesis describes flawed authentication and session management exploits and their detection process. We also propose an automated system to detect vulnerability attacks such as brute force, session ID rotation after successful login, and session ID disclosure in URLs by exposing all the facts. Keywords: Broken Authentication, Brute force, Session ID, Rotation, Log in, Exposes URL. en_US
dc.language.iso en_US en_US
dc.publisher Daffodil International University en_US
dc.subject Web applications en_US
dc.subject Web page en_US
dc.subject Web sites en_US
dc.subject Web server en_US
dc.title Design and Develop Automated Detection of Three Common Broken Authentication Vulnerabilities en_US
dc.type Other en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Browse

My Account

Statistics