A systematic map** study of web application testing

V Garousi, A Mesbah, A Betin-Can… - Information and Software …, 2013 - Elsevier
CONTEXT: The Web has had a significant impact on all aspects of our society. As our
society relies more and more on the Web, the dependability of web applications has become …

Two decades of Web application testing—A survey of recent advances

YF Li, PK Das, DL Dowe - Information Systems, 2014 - Elsevier
Since its inception of just over two decades ago, the World Wide Web has become a truly
ubiquitous and transformative force in our life, with millions of Web applications serving …

A symbolic execution framework for javascript

P Saxena, D Akhawe, S Hanna, F Mao… - … IEEE Symposium on …, 2010 - ieeexplore.ieee.org
As AJAX applications gain popularity, client-side JavaScript code is becoming increasingly
complex. However, few automated vulnerability analysis tools for JavaScript exist. In this …

Automatic creation of SQL injection and cross-site scripting attacks

A Kieyzun, PJ Guo, K Jayaraman… - 2009 IEEE 31st …, 2009 - ieeexplore.ieee.org
We present a technique for finding security vulnerabilities in Web applications. SQL Injection
(SQLI) and cross-site scripting (XSS) attacks are widespread forms of attack in which the …

[PDF][PDF] SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE. JS.

CA Staicu, M Pradel, B Livshits - NDSS, 2018 - staicu.org
Synode: Understanding and Automatically Preventing Injection Attacks on Node.js Page 1
Synode: Understanding and Automatically Preventing Injection Attacks on Node.js Cristian-Alexandru …

Rozzle: De-cloaking internet malware

C Kolbitsch, B Livshits, B Zorn… - 2012 IEEE Symposium …, 2012 - ieeexplore.ieee.org
JavaScript-based malware attacks have increased in recent years and currently represent a
signicant threat to the use of desktop computers, smartphones, and tablets. While static and …

A survey of new trends in symbolic execution for software testing and analysis

CS Păsăreanu, W Visser - International journal on software tools for …, 2009 - Springer
Symbolic execution is a well-known program analysis technique which represents program
inputs with symbolic values instead of concrete, initialized, data and executes the program …

HAMPI: a solver for string constraints

A Kiezun, V Ganesh, PJ Guo, P Hooimeijer… - Proceedings of the …, 2009 - dl.acm.org
Many automatic testing, analysis, and verification techniques for programs can be effectively
reduced to a constraint generation phase followed by a constraint-solving phase. This …

Fast and precise sanitizer analysis with {BEK}

P Hooimeijer, B Livshits, D Molnar, P Saxena… - 20th USENIX Security …, 2011 - usenix.org
Web applications often use special string-manipulating sanitizers on untrusted user data, but
it is difficult to reason manually about the behavior of these functions, leading to errors. For …

Finding bugs in web applications using dynamic test generation and explicit-state model checking

S Artzi, A Kiezun, J Dolby, F Tip, D Dig… - IEEE Transactions …, 2010 - ieeexplore.ieee.org
Web script crashes and malformed dynamically generated webpages are common errors,
and they seriously impact the usability of Web applications. Current tools for webpage …