Безопасность информационных технологий (Feb 2013)

Determining Data Entry Points For Javascript-rich Web applications

  • George Maksimovich Noseevich,
  • Andrey Aleksandrovich Petukhov

Journal volume & issue
Vol. 20, no. 1
pp. 13 – 20

Abstract

Read online

The paper is devoted the task of automatic crawling of javascript-rich web applications for data entry points. A new technique is proposed, which combines dynamic and static javascript code analysis. Testing the proposed technique on real world web applications such as Twitter, Youtube and Reddit has confirmed its applicability for analysis of modern web applications.

Keywords