Please use this identifier to cite or link to this item: https://www.um.edu.mt/library/oar/handle/123456789/94684
Full metadata record
DC FieldValueLanguage
dc.date.accessioned2022-04-29T10:32:36Z-
dc.date.available2022-04-29T10:32:36Z-
dc.date.issued2009-
dc.identifier.citationDesira, M. (2009). An open source vulnerability scanner for e-commerce web applications (Bachelor's dissertation).en_GB
dc.identifier.urihttps://www.um.edu.mt/library/oar/handle/123456789/94684-
dc.descriptionB.Sc. IT (Hons)(Melit.)en_GB
dc.description.abstractIt is essential for businesses to be online for world wide web users to purchase services and products. In such cases, the interface between the client and the enterprise is an e-commerce web application. Security-wise, such applications do fail due to bugs, incorrect logic and human error, resulting in unacceptable losses. The key to these failures present in such applications is security analysis. This process is made up of several components such as vulnerability scanning in which a number of web pages are automatically scanned for security issues such as authentication bypass. Such scanners are faced with the false positives side effect. A false positive is the report of a non-existent vulnerability. Scanners can employ certain techniques such as automatic exploitation as proposed by several authors to reduce the mentioned side effect. Commercial scanners do have features to reduce false positives however the techniques used are closed and therefore not available to the research community. Consequently the result behind this study is to implement an open source vulnerability scanner with an investigation on techniques to reduce false positives. The produced artefact consists of five NASL scripts which check for the following vulnerabilities: SQL Injection, Hidden Fields, Cross Site Scripting, Buffer Overflow and Fail Open Authentication. These are implemented and evaluated using the open source Nessus environment. Results presented in the evaluation suggest that the technique employed in the design and implemented in the artefact work.en_GB
dc.language.isoenen_GB
dc.rightsinfo:eu-repo/semantics/restrictedAccessen_GB
dc.subjectComputer softwareen_GB
dc.subjectElectronic commerceen_GB
dc.subjectApplication software -- Developmenten_GB
dc.titleAn open source vulnerability scanner for e-commerce web applicationsen_GB
dc.typebachelorThesisen_GB
dc.rights.holderThe copyright of this work belongs to the author(s)/publisher. The rights of this work are as defined by the appropriate Copyright Legislation or as modified by any successive legislation. Users may access this work and can make use of the information contained in accordance with the Copyright Legislation provided that the author must be properly acknowledged. Further distribution or reproduction in any format is prohibited without the prior permission of the copyright holder.en_GB
dc.publisher.institutionUniversity of Maltaen_GB
dc.publisher.departmentFaculty of Information and Communication Technology. Department of Computer Scienceen_GB
dc.description.reviewedN/Aen_GB
dc.contributor.creatorDesira, Mark (2009)-
Appears in Collections:Dissertations - FacICT - 1999-2009
Dissertations - FacICTCS - 2009

Files in This Item:
File Description SizeFormat 
BSC(HONS)IT_Desira_Mark_2009.pdf
  Restricted Access
5.5 MBAdobe PDFView/Open Request a copy


Items in OAR@UM are protected by copyright, with all rights reserved, unless otherwise indicated.