{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T12:20:19Z","timestamp":1782994819705,"version":"3.54.5"},"publisher-location":"Berlin, Heidelberg","reference-count":24,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642142147","type":"print"},{"value":"9783642142154","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-14215-4_7","type":"book-chapter","created":{"date-parts":[[2010,7,2]],"date-time":"2010-07-02T01:18:35Z","timestamp":1278033515000},"page":"111-131","source":"Crossref","is-referenced-by-count":111,"title":["Why Johnny Can\u2019t Pentest: An Analysis of Black-Box Web Vulnerability Scanners"],"prefix":"10.1007","author":[{"given":"Adam","family":"Doup\u00e9","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marco","family":"Cova","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"7_CR1","unstructured":"AnantaSec: Web Vulnerability Scanners Evaluation (January 2009), \n                    \n                      http:\/\/anantasec.blogspot.com\/2009\/01\/web-vulnerability-scanners-comparison.html"},{"key":"7_CR2","doi-asserted-by":"crossref","unstructured":"Balzarotti, D., Cova, M., Felmetsger, V., Vigna, G.: Multi-module Vulnerability Analysis of Web-based Applications. In: Proceedings of the ACM conference on Computer and Communications Security (CCS), pp. 25\u201335 (2007)","DOI":"10.1145\/1315245.1315250"},{"issue":"4","key":"7_CR3","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2006.108","volume":"4","author":"M. Curphey","year":"2006","unstructured":"Curphey, M., Araujo, R.: Web Application Security Assessment Tools. IEEE Security and Privacy\u00a04(4), 32\u201341 (2006)","journal-title":"IEEE Security and Privacy"},{"key":"7_CR4","unstructured":"CVE: Common Vulnerabilities and Exposures, \n                    \n                      http:\/\/www.cve.mitre.org"},{"key":"7_CR5","unstructured":"Foundstone: Hacme Bank v2.0 (May 2006), \n                    \n                      http:\/\/www.foundstone.com\/us\/resources\/proddesc\/hacmebank.htm"},{"key":"7_CR6","unstructured":"Grossman, J.: Challenges of Automated Web Application Scanning. In: BlackHat Windows Security Conference (2004)"},{"key":"7_CR7","doi-asserted-by":"crossref","unstructured":"Kals, S., Kirda, E., Kruegel, C., Jovanovic, N.: SecuBat: A Web Vulnerability Scanner. In: Proceedings of the International World Wide Web Conference (2006)","DOI":"10.1145\/1135777.1135817"},{"key":"7_CR8","doi-asserted-by":"crossref","unstructured":"McAllister, S., Kruegel, C., Kirda, E.: Leveraging User Interactions for In-Depth Testing of Web Applications. In: Proceedings of the Symposium on Recent Advances in Intrusion Detection (2008)","DOI":"10.1007\/978-3-540-87403-4_11"},{"key":"7_CR9","unstructured":"Open Security Foundation: OSF DataLossDB: Data Loss News, Statistics, and Research, \n                    \n                      http:\/\/datalossdb.org\/"},{"key":"7_CR10","unstructured":"Open Web Application Security Project (OWASP): OWASP SiteGenerator, \n                    \n                      http:\/\/www.owasp.org\/index.php\/OWASP_SiteGenerator"},{"key":"7_CR11","unstructured":"Open Web Application Security Project (OWASP): OWASP WebGoat Project, \n                    \n                      http:\/\/www.owasp.org\/index.php\/Category:OWASP_WebGoat_Project"},{"key":"7_CR12","unstructured":"Open Web Application Security Project (OWASP): Web Input Vector Extractor Teaser, \n                    \n                      http:\/\/code.google.com\/p\/wivet\/"},{"key":"7_CR13","unstructured":"Open Web Application Security Project (OWASP): OWASP Top Ten Project (2010), \n                    \n                      http:\/\/www.owasp.org\/index.php\/Top_10"},{"key":"7_CR14","unstructured":"OpenID Foundation: OpenID, \n                    \n                      http:\/\/openid.net\/"},{"key":"7_CR15","unstructured":"PCI Security Standards Council: PCI DDS Requirements and Security Assessment Procedures, v1.2 (October 2008)"},{"key":"7_CR16","unstructured":"Peine, H.: Security Test Tools for Web Applications. Tech. Rep. 048.06, Fraunhofer IESE (January 2006)"},{"key":"7_CR17","unstructured":"Provos, N., Mavrommatis, P., Rajab, M., Monrose, F.: All Your iFRAMEs Point to Us. In: Proceedings of the USENIX Security Symposium, pp. 1\u201316 (2008)"},{"key":"7_CR18","unstructured":"RSnake: Sql injection cheat sheet, \n                    \n                      http:\/\/ha.ckers.org\/sqlinjection\/"},{"key":"7_CR19","unstructured":"RSnake: XSS (Cross Site Scripting) Cheat Sheet, \n                    \n                      http:\/\/ha.ckers.org\/xss.html"},{"key":"7_CR20","unstructured":"Small, S., Mason, J., Monrose, F., Provos, N., Stubblefield, A.: To Catch a Predator: A Natural Language Approach for Eliciting Malicious Payloads. In: Proceedings of the USENIX Security Symposium (2008)"},{"key":"7_CR21","unstructured":"Suto, L.: Analyzing the Effectiveness and Coverage of Web Application Security Scanners (October 2007) (case Study)"},{"key":"7_CR22","unstructured":"Suto, L.: Analyzing the Accuracy and Time Costs of Web Application Security Scanners (Feburary 2010)"},{"key":"7_CR23","doi-asserted-by":"crossref","unstructured":"Vieira, M., Antunes, N., Madeira, H.: Using Web Security Scanners to Detect Vulnerabilities in Web Services. In: Proceedings of the Conference on Dependable Systems and Networks (2009)","DOI":"10.1109\/DSN.2009.5270294"},{"key":"7_CR24","unstructured":"Wiegenstein, A., Weidemann, F., Schumacher, M., Schinzel, S.: Web Application Vulnerability Scanners\u2014a Benchmark. Tech. rep., Virtual Forge GmbH (October 2006)"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-14215-4_7.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,30]],"date-time":"2021-04-30T08:21:37Z","timestamp":1619770897000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-14215-4_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642142147","9783642142154"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-14215-4_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010]]}}}