Research Article

VinJect: Toolkit for Penetration Testing and Vulnerability Scanning

Volume: 6 Number: 4 August 1, 2018
TR EN

VinJect: Toolkit for Penetration Testing and Vulnerability Scanning

Abstract

Penetration testing plays an important role in the development of secure software products and electronic systems. Sustainability of commercial systems is ensured through the regular scans of vulnerability. In this era where quality assurance and testing organizations become increasingly widespread, the effectiveness of the used tools and methods are critical. This article describes the architecture of the software named VinJect, which is developed for efficient penetration testing and vulnerability scanning. The primary goal of this application is to detect vulnerable locations in a shorter time with running in a multi-threaded structure. Our proposed application uses Wapiti and SQLmap applications’ services in the background. With user-friendly interfaces, it is also aimed to remove the bad UX that these applications running on the command line have. In the tests we performed, WinJect was found to be more efficient in completing the vulnerability scans in a much shorter time. 

Keywords

References

  1. [1] Allen, L., Heriyanto, T. and Ali, S., Kali Linux–Assuring security by penetration testing. Packt Publishing Ltd, 2014.
  2. [2] Stallings, W., Brown, L., Bauer, M.D. and Bhattacharjee, A.K., Computer security: principles and practice. Pearson Education, 2012.
  3. [3] Patil, S., Marathe, N., & Padiya, P., "Design of efficient web vulnerability scanner.", Inventive Computation Technologies (ICICT), International Conference on. Vol. 2. IEEE, 2016.
  4. [4] Aliero, M. S., & Ghani, I., "A component based SQL injection vulnerability detection tool.", Software Engineering Conference (MySEC), 2015 9th Malaysian. IEEE, 2015.
  5. [5] Parvez, M., Zavarsky, P., & Khoury, N., "Analysis of effectiveness of black-box web application scanners in detection of stored SQL injection and stored XSS vulnerabilities.", Internet Technology and Secured Transactions (ICITST), 2015 10th International Conference for. IEEE, 2015.
  6. [6] Khoury, N., Zavarsky, P., Lindskog, D., & Ruhl, R., "An analysis of black-box web application security scanners against stored SQL injection.", Privacy, Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom), 2011 IEEE Third International Conference on. IEEE, 2011.
  7. [7] Delamore, B., & Ko, R. K., "Escrow: A large-scale web vulnerability assessment tool.", Trust, Security and Privacy in Computing and Communications (TrustCom), 2014 IEEE 13th International Conference on. IEEE, 2014.
  8. [8] Liban, A., & Hilles, S. M., "Enhancing Mysql Injector vulnerability checker tool (Mysql Injector) using inference binary search algorithm for blind timing-based attack.", Control and System Graduate Research Colloquium (ICSGRC), 2014 IEEE 5th. IEEE, 2014.

Details

Primary Language

English

Subjects

Engineering

Journal Section

Research Article

Publication Date

August 1, 2018

Submission Date

May 21, 2018

Acceptance Date

May 28, 2018

Published in Issue

Year 2018 Volume: 6 Number: 4

APA
Akbulut, A. (2018). VinJect: Toolkit for Penetration Testing and Vulnerability Scanning. Duzce University Journal of Science and Technology, 6(4), 779-790. https://doi.org/10.29130/dubited.425414
AMA
1.Akbulut A. VinJect: Toolkit for Penetration Testing and Vulnerability Scanning. DUBİTED. 2018;6(4):779-790. doi:10.29130/dubited.425414
Chicago
Akbulut, Akhan. 2018. “VinJect: Toolkit for Penetration Testing and Vulnerability Scanning”. Duzce University Journal of Science and Technology 6 (4): 779-90. https://doi.org/10.29130/dubited.425414.
EndNote
Akbulut A (August 1, 2018) VinJect: Toolkit for Penetration Testing and Vulnerability Scanning. Duzce University Journal of Science and Technology 6 4 779–790.
IEEE
[1]A. Akbulut, “VinJect: Toolkit for Penetration Testing and Vulnerability Scanning”, DUBİTED, vol. 6, no. 4, pp. 779–790, Aug. 2018, doi: 10.29130/dubited.425414.
ISNAD
Akbulut, Akhan. “VinJect: Toolkit for Penetration Testing and Vulnerability Scanning”. Duzce University Journal of Science and Technology 6/4 (August 1, 2018): 779-790. https://doi.org/10.29130/dubited.425414.
JAMA
1.Akbulut A. VinJect: Toolkit for Penetration Testing and Vulnerability Scanning. DUBİTED. 2018;6:779–790.
MLA
Akbulut, Akhan. “VinJect: Toolkit for Penetration Testing and Vulnerability Scanning”. Duzce University Journal of Science and Technology, vol. 6, no. 4, Aug. 2018, pp. 779-90, doi:10.29130/dubited.425414.
Vancouver
1.Akhan Akbulut. VinJect: Toolkit for Penetration Testing and Vulnerability Scanning. DUBİTED. 2018 Aug. 1;6(4):779-90. doi:10.29130/dubited.425414

Cited By