Invention Grant
- Patent Title: Scanning unexposed web applications for vulnerabilities
-
Application No.: US17545022Application Date: 2021-12-08
-
Publication No.: US11991202B2Publication Date: 2024-05-21
- Inventor: Jijo John , Dmitriy Kashitsyn , Andrew Tisdale
- Applicant: Rapid7, Inc.
- Applicant Address: US MA Boston
- Assignee: Rapid7, Inc.
- Current Assignee: Rapid7, Inc.
- Current Assignee Address: US MA Boston
- Agent Ashwin Anand
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/50 ; G06F21/55 ; G06F21/60 ; H04L9/40

Abstract:
Disclosed herein are methods, systems, and processes for scanning unexposed web applications for security vulnerabilities. A web application executing on a client computing device is accessed and a determination is made that elements in a document object model (DOM) associated with the web application are completely loaded. A brute force operation is performed to identify unexposed actionable events associated with the elements in the DOM. The unexposed actionable events identified as part of performing the brute force operation are received from the client computing device, and the web application is scanned for security vulnerabilities based on the unexposed actionable events.
Public/Granted literature
- US20220159032A1 SCANNING UNEXPOSED WEB APPLICATIONS FOR VULNERABILITIES Public/Granted day:2022-05-19
Information query