Staresc - automatic and extendable vulnerability assessment over SSH

DSpace/Manakin Repository

Show simple item record

dc.contributor.advisor Calzavara, Stefano it_IT
dc.contributor.author Cecchini, Davide <1997> it_IT
dc.date.accessioned 2022-09-29 it_IT
dc.date.accessioned 2023-02-22T10:55:48Z
dc.date.available 2023-02-22T10:55:48Z
dc.date.issued 2022-10-20 it_IT
dc.identifier.uri http://hdl.handle.net/10579/22228
dc.description.abstract Regardless of the technical level and the type of target, time is one of the major constraints during both defensive and offensive activities. To address this constraint, the cybersecurity community implemented many tools to automate repetitive tasks. Cybersecurity experts exploit these tools in order to have more time to spend on more tricky (and fun) activities. In this work we present Staresc: a tool that automates command-line PoCs execution on multiple targets, relying on SSH or Telnet connections. Staresc is an easily extendable tool that performs tests on target machines, the tests are defined in YAML files (called plugins) that the tool can import at execution time. Together with Staresc, we describe how to properly write its plugins and we outline a practical way to test, and validate, them. Moreover, Staresc has been compared with the major competitors already available. We show which ideas introduced by other tools we adapt to our use case, which new features we introduced and which motivations led our technical choices. Lastly, we discuss about possible improvements, covering the possible implementation challenges and their benefits. it_IT
dc.language.iso en it_IT
dc.publisher Università Ca' Foscari Venezia it_IT
dc.rights © Davide Cecchini, 2022 it_IT
dc.title Staresc - automatic and extendable vulnerability assessment over SSH it_IT
dc.title.alternative Staresc - automatic and extendable vulnerability assessment over SSH it_IT
dc.type Master's Degree Thesis it_IT
dc.degree.name Informatica - computer science it_IT
dc.degree.level Laurea magistrale it_IT
dc.degree.grantor Dipartimento di Scienze Ambientali, Informatica e Statistica it_IT
dc.description.academicyear 2021-2022_appello_171022 it_IT
dc.rights.accessrights openAccess it_IT
dc.thesis.matricno 862701 it_IT
dc.subject.miur INF/01 INFORMATICA it_IT
dc.description.note it_IT
dc.degree.discipline it_IT
dc.contributor.co-advisor it_IT
dc.date.embargoend it_IT
dc.provenance.upload Davide Cecchini (862701@stud.unive.it), 2022-09-29 it_IT
dc.provenance.plagiarycheck Stefano Calzavara (stefano.calzavara@unive.it), 2022-10-17 it_IT


Files in this item

This item appears in the following Collection(s)

Show simple item record