Evaluation of Open Source Web Application Vulnerability Scanners

Authors

  • Hilmi S. Abdullah Duhok Polytechnic University

Keywords:

Web Application Security, Open Web Application Security Project (OWASP), Vulnerability Scanner, Penetration Testing

Abstract

Nowadays, web applications are essential part of our lives. Web applications are used by people for information gathering, communication, e-commerce and variety of other activities. Since they contain valuable and sensitive information, the attacks against them have increased in order to find vulnerabilities and steal information. For this reason, it is essential to check web application vulnerabilities to ensure that it is secure. However, checking the vulnerabilities manually is a tedious and time-consuming job. Therefore, there is an exigent need for web application vulnerability scanners. In this study, we evaluate two open source web application vulnerability scanners Paros and OWASP Zed Attack Proxy (OWASP ZAP) by testing them against two vulnerable web applications buggy web application (bWAPP) and Damn Vulnerable Web Application (DVWA).

Published

2020-02-17

How to Cite

S. Abdullah, H. (2020). Evaluation of Open Source Web Application Vulnerability Scanners. Academic Journal of Nawroz University (AJNU), 9(1). Retrieved from https://journals.nawroz.edu.krd/files/article/view/879

Issue

Section

Articles