Invention Grant
- Patent Title: System and method for providing application penetration testing
- Patent Title (中): 提供应用程序渗透测试的系统和方法
-
Application No.: US12043673Application Date: 2008-03-06
-
Publication No.: US08484738B2Publication Date: 2013-07-09
- Inventor: Alberto Gustavo Soliño Testa , Gerardo Gabriel Richarte , Fernando Federico Russ , Diego Martin Kelyacoubian , Ariel Futoransky , Diego Bartolome Tiscornia , Ariel Waissbein , Hector Adrian Manrique , Javier Ricardo De Acha Campos , Eduardo Arias , Sebastian Pablo Cufre , Axel Elián Brzostowski
- Applicant: Alberto Gustavo Soliño Testa , Gerardo Gabriel Richarte , Fernando Federico Russ , Diego Martin Kelyacoubian , Ariel Futoransky , Diego Bartolome Tiscornia , Ariel Waissbein , Hector Adrian Manrique , Javier Ricardo De Acha Campos , Eduardo Arias , Sebastian Pablo Cufre , Axel Elián Brzostowski
- Applicant Address: US MA Boston
- Assignee: Core SDI Incorporated
- Current Assignee: Core SDI Incorporated
- Current Assignee Address: US MA Boston
- Agency: Sheehan Phinney Bass & Green PA
- Agent Peter A. Nieves
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00

Abstract:
A system and method provide application penetration testing. The system contains logic configured to find at least one vulnerability in the application so as to gain access to data associated with the application, logic configured to confirm the vulnerability and determine if the application can be compromised, and logic configured to compromise and analyze the application by extracting or manipulating data from a database associated with the application. In addition, the method provides for penetration testing of a target by: receiving at least one confirmed vulnerability of the target; receiving a method for compromising the confirmed vulnerability of the target; installing a network agent on the target in accordance with the method, wherein the network agent allows a penetration tester to execute arbitrary operating system commands on the target; and executing the arbitrary operating system commands on the target to analyze risk to which the target may be exposed.
Public/Granted literature
- US20080263671A1 System and Method for Providing Application Penetration Testing Public/Granted day:2008-10-23
Information query