A review: Penetration testing approaches on Content Management System (CMS)

These days, Content Management Systems (CMS) have been the target for adversaries in the cyber world since they are mostly open-source like Drupal, Joomla and WordPress, where no experts want to address the vulnerabilities due to them having no price tags. This paper aims to review the available and...

Full description

Saved in:
Bibliographic Details
Main Authors: Jagamogan, Reevan Seelen, Ismail, Saiful Adli, Hassan, Noor Hafizah, Abas, Hafiza
Format: Conference or Workshop Item
Published: 2021
Subjects:
Online Access:http://eprints.utm.my/id/eprint/98198/
http://dx.doi.org/10.1109/ICRIIS53035.2021.9617087
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Teknologi Malaysia
Description
Summary:These days, Content Management Systems (CMS) have been the target for adversaries in the cyber world since they are mostly open-source like Drupal, Joomla and WordPress, where no experts want to address the vulnerabilities due to them having no price tags. This paper aims to review the available and proposed penetration testing approaches and tools used on content management systems (CMS) and tabulate the results in a review matrix. There are 22 articles found regarding the proposed approaches and tools where some of which use machine learning (ML) algorithms. The matrix is categorized based on whether those approaches involve the use of machine learning algorithms or they involve other approaches like using basic penetration tools like Sqlmap and Metasploit to perform basic penetration tests like SQL Injection or Cross-site scripting (XSS). The penetration testing algorithms are further categorized on whether they are reinforcement learning (RL) algorithms or normal algorithms. Some of the approaches are later discussed in the third section of the paper, where they are categorized into penetration testing approaches that use reinforcement learning, the usage of basic penetration testing tools and the other proposed penetration testing tools.