{"id":7831,"date":"2012-10-19T09:42:39","date_gmt":"2012-10-19T09:42:39","guid":{"rendered":"https:\/\/emadridnet.uc3m.es\/?p=7831"},"modified":"2022-03-31T09:45:24","modified_gmt":"2022-03-31T09:45:24","slug":"automatic-analysis-of-web-applications-security","status":"publish","type":"post","link":"https:\/\/emadridnet.uc3m.es\/en\/2012\/10\/19\/automatic-analysis-of-web-applications-security\/","title":{"rendered":"\u00abAutomatic Analysis of Web Applications Security\u00bb"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; fullwidth=&#8221;on&#8221; admin_label=&#8221;Header&#8221; _builder_version=&#8221;4.15&#8243; background_image=&#8221;https:\/\/emadridnet.uc3m.es\/wp-content\/uploads\/sites\/40\/2021\/05\/meetup-02.jpg&#8221; parallax=&#8221;on&#8221; custom_padding=&#8221;|||&#8221; animation_style=&#8221;slide&#8221; animation_direction=&#8221;top&#8221; animation_intensity_slide=&#8221;2%&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_fullwidth_header title=&#8221;\u00abAutomatic Analysis of Web Applications Security\u00bb&#8221; subhead=&#8221;Juan Ram\u00f3n Bermejo&#8221; button_one_url=&#8221;https:\/\/docs.google.com\/forms\/d\/e\/1FAIpQLSfX6_IzjEU623_remyLvSjNm_VAGhXqFB3gh4Cvf1q67cc1JA\/viewform&#8221; background_overlay_color=&#8221;rgba(255,255,255,0.6)&#8221; content_max_width=&#8221;700px&#8221; content_max_width_tablet=&#8221;100%&#8221; content_max_width_phone=&#8221;&#8221; content_max_width_last_edited=&#8221;on|desktop&#8221; _builder_version=&#8221;4.15.1&#8243; title_font=&#8221;Roboto|300|||||||&#8221; title_font_size=&#8221;60px&#8221; title_line_height=&#8221;1.4em&#8221; content_font=&#8221;||||||||&#8221; content_font_size=&#8221;17px&#8221; content_line_height=&#8221;1.9em&#8221; subhead_font=&#8221;|600|||||||&#8221; subhead_font_size=&#8221;20px&#8221; subhead_line_height=&#8221;1.8em&#8221; background_color=&#8221;rgba(255,255,255,0.3)&#8221; background_image=&#8221;https:\/\/storage.googleapis.com\/wp-uploads.bucket.wp.uc3m.es\/wp-content\/uploads\/sites\/40\/2022\/03\/31074054\/juan-ramon-bermejo-higuera-19393-7.jpg&#8221; custom_button_one=&#8221;on&#8221; button_one_text_size=&#8221;14px&#8221; button_one_text_color=&#8221;#ffffff&#8221; button_one_bg_color=&#8221;#8300e9&#8243; button_one_bg_color_gradient_start=&#8221;#d883f8&#8243; button_one_bg_color_gradient_end=&#8221;#352DBE&#8221; button_one_bg_color_gradient_direction=&#8221;90deg&#8221; button_one_border_width=&#8221;10px&#8221; button_one_border_color=&#8221;rgba(0,0,0,0)&#8221; button_one_border_radius=&#8221;100px&#8221; button_one_letter_spacing=&#8221;3px&#8221; button_one_font=&#8221;Roboto|700||on|||||&#8221; custom_button_two=&#8221;on&#8221; button_two_text_size=&#8221;14px&#8221; button_two_text_color=&#8221;#ffffff&#8221; button_two_bg_color=&#8221;#06c8ff&#8221; button_two_border_width=&#8221;10px&#8221; button_two_border_color=&#8221;rgba(0,0,0,0)&#8221; button_two_border_radius=&#8221;100px&#8221; button_two_letter_spacing=&#8221;3px&#8221; button_two_font=&#8221;Roboto|700||on|||||&#8221; background_layout=&#8221;light&#8221; min_height=&#8221;370.3px&#8221; custom_margin=&#8221;||||false&#8221; custom_padding=&#8221;0vw||0vw||true|&#8221; custom_padding_tablet=&#8221;250px||250px||true&#8221; custom_padding_last_edited=&#8221;off|desktop&#8221; link_option_url_new_window=&#8221;on&#8221; hover_enabled=&#8221;0&#8243; title_font_size_tablet=&#8221;40px&#8221; title_font_size_phone=&#8221;32px&#8221; title_font_size_last_edited=&#8221;on|desktop&#8221; button_one_text_color_hover=&#8221;#ffffff&#8221; button_two_text_color_hover=&#8221;#ffffff&#8221; button_one_letter_spacing_hover=&#8221;3px&#8221; button_two_letter_spacing_hover=&#8221;3px&#8221; global_colors_info=&#8221;{}&#8221; button_one_text_size__hover_enabled=&#8221;off&#8221; button_two_text_size__hover_enabled=&#8221;off&#8221; button_one_text_color__hover_enabled=&#8221;on&#8221; button_one_text_color__hover=&#8221;#ffffff&#8221; button_two_text_color__hover_enabled=&#8221;on&#8221; button_two_text_color__hover=&#8221;#ffffff&#8221; button_one_border_width__hover_enabled=&#8221;off&#8221; button_two_border_width__hover_enabled=&#8221;off&#8221; button_one_border_color__hover_enabled=&#8221;off&#8221; button_two_border_color__hover_enabled=&#8221;off&#8221; button_one_border_radius__hover_enabled=&#8221;off&#8221; button_two_border_radius__hover_enabled=&#8221;off&#8221; button_one_letter_spacing__hover_enabled=&#8221;on&#8221; button_one_letter_spacing__hover=&#8221;3px&#8221; button_two_letter_spacing__hover_enabled=&#8221;on&#8221; button_two_letter_spacing__hover=&#8221;3px&#8221; button_one_bg_color__hover_enabled=&#8221;off&#8221; button_two_bg_color__hover_enabled=&#8221;off&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p><span>UNIR<\/span><\/p>\n<p>[\/et_pb_fullwidth_header][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;Visiting&#8221; _builder_version=&#8221;4.15&#8243; min_height=&#8221;418.7px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.15&#8243; custom_padding=&#8221;0px|0px|24px|0px|false|false&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.15&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.15.1&#8243; text_font=&#8221;||||||||&#8221; text_font_size=&#8221;16px&#8221; text_line_height=&#8221;1.9em&#8221; header_font=&#8221;||||||||&#8221; header_2_font=&#8221;Roboto|300|||||||&#8221; header_2_font_size=&#8221;50px&#8221; header_2_line_height=&#8221;1.4em&#8221; hover_enabled=&#8221;0&#8243; header_2_font_size_tablet=&#8221;40px&#8221; header_2_font_size_phone=&#8221;32px&#8221; header_2_font_size_last_edited=&#8221;on|phone&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2 style=\"text-align: justify\">Abstract<\/h2>\n<p style=\"text-align: justify\">To accomplish a security auditory of web applications by manual penetration test or manual code review is an arduous task and no efficient because test all attack surface of web applications under all distinct conditions validating all inputs is very difficult and finally there will remain many security vulnerabilities in the code.<\/p>\n<p style=\"text-align: justify\">To get web applications with a high degree of security a new security tasks should be included in the security development life cycle (SDLC) by using and integrating several types of automatic commercial and open source tools to obtain a better result as whole building a specific methodology for tools selected integration. In this presentation I will try to explain the new tendencies in automatic tools for security analysis of web applications to use in each phase of SDLC.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;About&#8221; _builder_version=&#8221;4.15&#8243; min_height=&#8221;562px&#8221; custom_margin=&#8221;-3px|||||&#8221; custom_padding=&#8221;0px||0px|||&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row column_structure=&#8221;1_2,1_2&#8243; padding_top_bottom_link_1=&#8221;true&#8221; padding_left_right_link_1=&#8221;true&#8221; _builder_version=&#8221;4.15&#8243; min_height=&#8221;552.8px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.15&#8243; background_image=&#8221;https:\/\/storage.googleapis.com\/wp-uploads.bucket.wp.uc3m.es\/wp-content\/uploads\/sites\/40\/2021\/05\/28095053\/column-background-02.png&#8221; custom_padding=&#8221;50px|50px|50px|50px&#8221; custom_padding_tablet=&#8221;&#8221; custom_padding_phone=&#8221;20px|20px|20px|20px|true|true&#8221; custom_padding_last_edited=&#8221;on|phone&#8221; global_colors_info=&#8221;{}&#8221; padding_phone=&#8221;20px|20px|20px|20px|true|true&#8221; padding_last_edited=&#8221;on|phone&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;https:\/\/storage.googleapis.com\/wp-uploads.bucket.wp.uc3m.es\/wp-content\/uploads\/sites\/40\/2022\/03\/31074054\/juan-ramon-bermejo-higuera-19393-7.jpg&#8221; title_text=&#8221;juan-ramon-bermejo-higuera-19393-7&#8243; align_tablet=&#8221;center&#8221; align_phone=&#8221;&#8221; align_last_edited=&#8221;on|desktop&#8221; _builder_version=&#8221;4.15.1&#8243; animation_style=&#8221;zoom&#8221; animation_intensity_zoom=&#8221;10%&#8221; box_shadow_style=&#8221;preset1&#8243; box_shadow_vertical=&#8221;32px&#8221; box_shadow_blur=&#8221;100px&#8221; box_shadow_color=&#8221;rgba(0,0,0,0.15)&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.15&#8243; custom_padding=&#8221;|||&#8221; custom_padding_tablet=&#8221;0px|||&#8221; custom_padding_last_edited=&#8221;off|desktop&#8221; global_colors_info=&#8221;{}&#8221; padding_tablet=&#8221;0px|||&#8221; padding_last_edited=&#8221;off|desktop&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.15.1&#8243; text_font=&#8221;||||||||&#8221; text_font_size=&#8221;16px&#8221; text_line_height=&#8221;1.9em&#8221; header_font=&#8221;||||||||&#8221; header_2_font=&#8221;Roboto|300|||||||&#8221; header_2_font_size=&#8221;50px&#8221; header_2_line_height=&#8221;1.4em&#8221; hover_enabled=&#8221;0&#8243; header_2_font_size_tablet=&#8221;40px&#8221; header_2_font_size_phone=&#8221;32px&#8221; header_2_font_size_last_edited=&#8221;on|phone&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2>Bio<\/h2>\n<p style=\"text-align: justify\"><span>Degree in Computer Engineering from the Spanish National University of Distance Education is currently a doctoral student in Research in Electrical, Electronics Engineering and Control at the same University. In 2011, ended fis studies of Master in Computer Engineering on Networking, Communications and Content Management offered by the UNED. He has developed his career over the past 15 years under the Ministry of Defense working with IBM Mainframe systems and more recently with the Command and Control Air Defense System of the Spanish Air Force, where he is currently working on various migration projects of several subsystems.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;Past Events&#8221; _builder_version=&#8221;4.15&#8243; background_image=&#8221;https:\/\/emadridnet.uc3m.es\/wp-content\/uploads\/sites\/40\/2021\/05\/bg-4.png&#8221; background_size=&#8221;initial&#8221; background_position=&#8221;bottom_left&#8221; custom_padding=&#8221;0px|0px|0|0px|false|false&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.15&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.15&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.15&#8243; text_font=&#8221;||||||||&#8221; text_font_size=&#8221;16px&#8221; text_line_height=&#8221;1.9em&#8221; header_font=&#8221;||||||||&#8221; header_2_font=&#8221;Roboto|300|||||||&#8221; header_2_font_size=&#8221;50px&#8221; header_2_line_height=&#8221;1.4em&#8221; text_orientation=&#8221;center&#8221; header_2_font_size_tablet=&#8221;40px&#8221; header_2_font_size_phone=&#8221;32px&#8221; header_2_font_size_last_edited=&#8221;on|phone&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>Video<\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row custom_padding_last_edited=&#8221;on|phone&#8221; _builder_version=&#8221;4.15&#8243; background_image=&#8221;https:\/\/storage.googleapis.com\/wp-uploads.bucket.wp.uc3m.es\/wp-content\/uploads\/sites\/40\/2021\/05\/28095101\/column-background-03-1.png&#8221; min_height=&#8221;175px&#8221; custom_margin=&#8221;15px|auto|-12px|auto||&#8221; custom_padding=&#8221;0px|50px|0|50px|false|false&#8221; custom_padding_tablet=&#8221;&#8221; custom_padding_phone=&#8221;20px|20px||20px||true&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.15&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.15.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p><iframe loading=\"lazy\" title=\"Seminario eMadrid sobre &amp;ldquo;&amp;Eacute;tica y seguridad en e-Learning&amp;rdquo; - An&amp;aacute;lisis autom&amp;aacute;tico de la seguridad de aplicaciones web\" src=\"https:\/\/player.vimeo.com\/video\/52380166?h=a7d1e234d9&amp;dnt=1&amp;app_id=122963\" width=\"640\" height=\"480\" frameborder=\"0\" allow=\"autoplay; fullscreen; picture-in-picture\" allowfullscreen><\/iframe><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.15&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.15&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.15&#8243; text_font=&#8221;||||||||&#8221; text_font_size=&#8221;16px&#8221; text_line_height=&#8221;1.9em&#8221; header_font=&#8221;||||||||&#8221; header_2_font=&#8221;Roboto|300|||||||&#8221; header_2_font_size=&#8221;50px&#8221; header_2_line_height=&#8221;1.4em&#8221; text_orientation=&#8221;center&#8221; custom_padding=&#8221;84px|||||&#8221; header_2_font_size_tablet=&#8221;40px&#8221; header_2_font_size_phone=&#8221;32px&#8221; header_2_font_size_last_edited=&#8221;on|phone&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2>Slides<\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.15&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.15&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.15.1&#8243; _module_preset=&#8221;default&#8221; text_orientation=&#8221;center&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p><iframe loading=\"lazy\" title=\"2012 10 19 (uned) emadrid jrbermejo md analisis automatico seguridad aplicaciones web\" src=\"https:\/\/www.slideshare.net\/slideshow\/embed_code\/key\/diQQDVkdKIfWjA\" width=\"427\" height=\"356\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" style=\"border:1px solid #CCC; border-width:1px; margin-bottom:5px; max-width: 100%;\" allowfullscreen> <\/iframe> <\/p>\n<div style=\"margin-bottom:5px\"> <strong> <a href=\"https:\/\/www.slideshare.net\/emadridnet\/2012-10-19-uned-emadrid-jrbermejo-md-analisis-automatico-seguridad-aplicaciones-web\" title=\"2012 10 19 (uned) emadrid jrbermejo md analisis automatico seguridad aplicaciones web\" target=\"_blank\">2012 10 19 (uned) emadrid jrbermejo md analisis automatico seguridad aplicaciones web<\/a> <\/strong> from <strong><a href=\"https:\/\/www.slideshare.net\/emadridnet\" target=\"_blank\">eMadrid network<\/a><\/strong> <\/div>\n<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>UNIRAbstract To accomplish a security auditory of web applications by manual penetration test or manual code review is an arduous task and no efficient because test all attack surface of web applications under all distinct conditions validating all inputs is very difficult and finally there will remain many security vulnerabilities in the code. To get [&hellip;]<\/p>\n","protected":false},"author":82,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[28],"tags":[],"class_list":["post-7831","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/posts\/7831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/users\/82"}],"replies":[{"embeddable":true,"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/comments?post=7831"}],"version-history":[{"count":2,"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/posts\/7831\/revisions"}],"predecessor-version":[{"id":7834,"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/posts\/7831\/revisions\/7834"}],"wp:attachment":[{"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/media?parent=7831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/categories?post=7831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/emadridnet.uc3m.es\/en\/wp-json\/wp\/v2\/tags?post=7831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}