TestREx: a Framework for Repeatable Exploits
Stanislav Dashevskyi, Daniel Ricardo dos Santos, Fabio Massacci,, Antonino Sabetta

TL;DR
TestREx is a comprehensive framework designed to enable automated, repeatable testing of security exploits across diverse web application environments, aiding vulnerability discovery and security assessment.
Contribution
It introduces a novel framework that simplifies the deployment, execution, and monitoring of exploits in varied settings, enhancing security testing efficiency.
Findings
Supports automated exploit injection and monitoring
Enables large-scale vulnerability testing
Provides a corpus of example applications
Abstract
Web applications are the target of many well known exploits and also a fertile ground for the discovery of security vulnerabilities. Yet, the success of an exploit depends both on the vulnerability in the application source code and the environment in which the application is deployed and run. As execution environments are complex (application servers, databases and other supporting applications), we need to have a reliable framework to test whether known exploits can be reproduced in different settings, better understand their effects, and facilitate the discovery of new vulnerabilities. In this paper, we present TestREx - a framework that allows for highly automated, easily repeatable exploit testing in a variety of contexts, so that a security tester may quickly and efficiently perform large-scale experiments with vulnerability exploits. It supports packing and running applications…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
