NAVEX: Precise and scalable exploit generation for dynamic web applications
NAVEX: Precise and scalable exploit generation for dynamic web applications Alhuzali et al., USENIX Security 2018
NAVEX (https://github.com/aalhuz/navex) is a very powerful tool for finding executable exploits in dynamic web applications. It combines static and dynamic analysis (to cope with dynamically generated web content) to find vulnerable points in web applications, determine whether inputs to those are appropriately sanitised, and then builds a navigation graph for the application and uses it to construct a series of HTTP requests that trigger the vulnerability.
It also works at real-world scale: NAVEX was used on 26 PHP applications with a total of 3.2M SLOC and 22.7K PHP files. It generated 204 concrete exploits across these applications in a total of 6.5 hours. While the current implementation of NAVEX targets PHP applications, the approach could be generalised to other languages and frameworks.
In this paper, our main contribution is a precise approach for vulnerability analysis of multi-tier web applications with dynamic features… our approach combines dynamic analysis of web applications with static analysis to automatically identify vulnerabilities and generate concrete exploits as proof of those vulnerabilities.
Here’s a example of what NAVEX can do. From the 64K Continue reading




CEO Hock Tan said the company will sell hardware to new customers and will see a boost from 5G.
Its pièce de résistance is to use software-defined networking to take resources from clouds and on-premises data centers and make it look like it’s a single data center, all on the same Layer 2.
Consul competes against Istio but has a broader focus on multi-tenancy infrastructure deployments.
Telefónica taps Netcracker for BSS; Cisco launches hybrid cloud platform for Google Cloud; China considers a merger of its three wireless carriers.
The company says its four 5G launch markets will be used to refine its customer experience and stress-test the network.