{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T17:14:48Z","timestamp":1725902088689},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319621043"},{"type":"electronic","value":"9783319621050"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-62105-0_13","type":"book-chapter","created":{"date-parts":[[2017,6,23]],"date-time":"2017-06-23T09:13:20Z","timestamp":1498209200000},"page":"196-212","source":"Crossref","is-referenced-by-count":3,"title":["A Formal Approach to Exploiting Multi-stage Attacks Based on File-System Vulnerabilities of\u00a0Web Applications"],"prefix":"10.1007","author":[{"given":"Federico","family":"De Meo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luca","family":"Vigan\u00f2","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,6,24]]},"reference":[{"key":"13_CR1","doi-asserted-by":"publisher","unstructured":"Akhawe, D., Barth, A., Lam, P., Mitchell, J., Song, D.: Towards a formal foundation of web security. In CSF. IEEE (2010). doi:\n10.1109\/CSF.2010.27","DOI":"10.1109\/CSF.2010.27"},{"key":"13_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/978-3-642-28756-5_19","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"A Armando","year":"2012","unstructured":"Armando, A., et al.: The AVANTSSAR platform for the automated validation of trust and security of service-oriented architectures. In: Flanagan, C., K\u00f6nig, B. (eds.) TACAS 2012. LNCS, vol. 7214, pp. 267\u2013282. Springer, Heidelberg (2012). doi:\n10.1007\/978-3-642-28756-5_19"},{"key":"13_CR3","unstructured":"ASP documentation: Including Files in ASP Applications. \nhttps:\/\/msdn.microsoft.com\/en-us\/library\/ms524876(v=vs.90).aspx"},{"key":"13_CR4","doi-asserted-by":"publisher","unstructured":"B\u00fcchler, M., Oudinet, J., Pretschner, A.: Semi-automatic security testing of web applications from a secure model. In: SERE. doi:\n10.1109\/SERE.2012.38","DOI":"10.1109\/SERE.2012.38"},{"key":"13_CR5","doi-asserted-by":"publisher","unstructured":"Calvi, A., Vigan\u00f2, L.: An automated approach for testing the security of web applications against chained attacks. In: 31st ACM\/SIGAPP Symposium on Applied Computing (SAC). ACM Press (2016). doi:\n10.1145\/2851613.2851803","DOI":"10.1145\/2851613.2851803"},{"key":"13_CR6","unstructured":"Carey, M.: Penetration Testing vs. Vulnerability Scanning - What\u2019s the Difference? \nhttps:\/\/www.alienvault.com\/blogs\/security-essentials\/penetration-testing-vs-vulnerability-scanning-whats-the-difference"},{"key":"13_CR7","unstructured":"Christey, S.: The 2009 CWE\/SANS top 25 most dangerous programming errors. \nhttp:\/\/cwe.mitre.org\/top25"},{"key":"13_CR8","unstructured":"Damele, B., Guimar\u00e3es, A.: Advanced SQL injection to operating system full control. In: BlackHat EU (2009)"},{"key":"13_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/978-3-319-46598-2_13","volume-title":"Security and Trust Management","author":"F Meo De","year":"2016","unstructured":"De Meo, F., Rocchetto, M., Vigan\u00f2, L.: Formal analysis of vulnerabilities of web applications based on SQL injection. In: Barthe, G., Markatos, E., Samarati, P. (eds.) STM 2016. LNCS, vol. 9871, pp. 179\u2013195. Springer, Cham (2016). doi:\n10.1007\/978-3-319-46598-2_13"},{"key":"13_CR10","unstructured":"De Meo, F., Vigan\u00f2, L.: WAFEx: Web Application Formal Exploiter. \nhttp:\/\/regis.di.univr.it\/wafex\/"},{"key":"13_CR11","unstructured":"De Meo, F., Vigan\u00f2, L.: A Formal Approach to Exploiting Multi-Stage Attacks based on File-System Vulnerabilities of Web Applications (Extended Version) (2017). \nhttps:\/\/arxiv.org\/abs\/1705.03658"},{"key":"13_CR12","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","volume":"29","author":"D Dolev","year":"1983","unstructured":"Dolev, D., Yao, A.C.: On the security of public key protocols. IEEE Trans. Inf. Theory 29, 198\u2013208 (1983). doi:\n10.1109\/TIT.1983.1056650","journal-title":"IEEE Trans. Inf. Theory"},{"key":"13_CR13","unstructured":"DotDotPwn - The Directory Traversal Fuzzer. \nhttps:\/\/github.com\/wireghoul\/dotdotpwn"},{"key":"13_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-642-14215-4_7","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Doup\u00e9","year":"2010","unstructured":"Doup\u00e9, A., Cova, M., Vigna, G.: Why johnny can\u2019t pentest: an analysis of black-box web vulnerability scanners. In: Kreibich, C., Jahnke, M. (eds.) DIMVA 2010. LNCS, vol. 6201, pp. 111\u2013131. Springer, Heidelberg (2010). doi:\n10.1007\/978-3-642-14215-4_7"},{"key":"13_CR15","unstructured":"DVWA: Damn Vulnerable Web Application. \nhttp:\/\/www.dvwa.co.uk\/"},{"key":"13_CR16","unstructured":"Glynn, F.: Vulnerability Assessment and Penetration Testing. \nhttp:\/\/www.veracode.com\/security\/vulnerability-assessment-and-penetration-testing"},{"key":"13_CR17","unstructured":"Joomla! \nhttps:\/\/www.joomla.org"},{"key":"13_CR18","unstructured":"The Java EE 5 Tutorial: Reusing Content in JSP Pages. \nhttp:\/\/docs.oracle.com\/javaee\/5\/tutorial\/doc\/bnajb.html"},{"key":"13_CR19","unstructured":"OWASP. Top 10 for 2013. \nhttps:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"13_CR20","unstructured":"PHP documentation: include. \nhttp:\/\/php.net\/manual\/it\/function.include.php"},{"key":"13_CR21","unstructured":"Postswigger. Burp Proxy (2014). \nhttps:\/\/portswigger.net\/burp\/proxy.html"},{"key":"13_CR22","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1007\/978-3-642-55415-5_3","volume-title":"ICT Systems Security and Privacy Protection","author":"M Rocchetto","year":"2014","unstructured":"Rocchetto, M., Ochoa, M., Torabi Dashti, M.: Model-based detection of CSRF. In: Cuppens-Boulahia, N., Cuppens, F., Jajodia, S., Abou El Kalam, A., Sans, T. (eds.) SEC 2014. IFIP AICT, vol. 428, pp. 30\u201343. Springer, Heidelberg (2014). doi:\n10.1007\/978-3-642-55415-5_3"},{"key":"13_CR23","unstructured":"SANS Institute. Penetration Testing: Assessing Your Overall Security Before Attackers Do. \nhttps:\/\/www.sans.org\/reading-room\/whitepapers\/analyst\/penetration-testing-assessing-security-attackers-34635"},{"key":"13_CR24","unstructured":"Trustwave SpiderLabs. Joomla SQL Injection Vulnerability Exploit Results in Full Administrative Access (2015). \nhttps:\/\/www.trustwave.com\/Resources\/SpiderLabs-Blog\/Joomla-SQL-Injection-Vulnerability-Exploit-Results-in-Full-Administrative-Access"},{"key":"13_CR25","doi-asserted-by":"publisher","unstructured":"Vigan\u00f2, L.: The SPaCIoS project: secure provision and consumption in the internet of services. In: Software Testing, Verification and Validation (ICST) (2013). doi:\n10.1109\/ICST.2013.75","DOI":"10.1109\/ICST.2013.75"},{"key":"13_CR26","unstructured":"Wfuzz: The Web Bruteforcer. \nhttps:\/\/github.com\/xmendez\/wfuzz"}],"container-title":["Lecture Notes in Computer Science","Engineering Secure Software and Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-62105-0_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,23]],"date-time":"2017-06-23T09:17:53Z","timestamp":1498209473000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-62105-0_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319621043","9783319621050"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-62105-0_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2017]]}}}