论文标题
罗宾:网络安全工具
Robin: A Web Security Tool
论文作者
论文摘要
得益于技术的进步,各种应用程序变得越来越完整,能够执行复杂的任务,从而节省我们的大部分时间。但是要执行这些任务,应用程序要求共享某些个人信息,例如信用卡,银行帐户,电子邮件地址等。所有这些数据都必须在最终用户和机构申请之间安全地传输。尽管如此,几种应用程序可能包含犯罪分子可能探索的残留缺陷,以窃取用户数据。因此,为了帮助信息安全专业人员和开发人员在Web应用程序上执行渗透测试(Pentests),本文介绍了Robin:Web安全工具。该工具还应用于实际案例研究,其中发现了非常危险的漏洞。本文还描述了这种漏洞。
Thanks to the advance of technology, all kinds of applications are becoming more complete and capable of performing complex tasks that save much of our time. But to perform these tasks, applications require that some personal information are shared, for example credit card, bank accounts, email addresses, etc. All these data must be transferred securely between the final user and the institution application. Nonetheless, several applications might contain residual flaws that may be explored by criminals in order to steal users data. Hence, to help information security professionals and developers to perform penetration tests (pentests) on web applications, this paper presents Robin: A Web Security Tool. The tool is also applied to a real case study in which a very dangerous vulnerability was found. This vulnerability is also described in this paper.