Utilizing Dynamic Analysis for Web Application Penetration Testing
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F24%3APU151536" target="_blank" >RIV/00216305:26220/24:PU151536 - isvavai.cz</a>
Result on the web
<a href="https://dx.doi.org/10.13164/eeict.2024.92" target="_blank" >https://dx.doi.org/10.13164/eeict.2024.92</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.13164/eeict.2024.92" target="_blank" >10.13164/eeict.2024.92</a>
Alternative languages
Result language
angličtina
Original language name
Utilizing Dynamic Analysis for Web Application Penetration Testing
Original language description
This paper presents the design and implementation of a new modular tool, called PtWebDA, for dynamic analysis of web applications as one of the techniques used in penetration testing. Compared to other available tools and their limitations, our solution enables efficient rate limiting while also allowing testing of HTTP headers, cookie attributes, and content security policy directives. To verify its effectiveness in supporting manual web application penetration testing, we performed experimental testing in a controlled environment. The results of testing the presented tool PtWebDA are discussed in detail and highlight the key contributions of our solution.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
20203 - Telecommunications
Result continuities
Project
<a href="/en/project/VK01030019" target="_blank" >VK01030019: Interactive checklists for effective cybersecurity testing</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2024
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings II of the 30th Conference STUDENT EEICT 2024
ISBN
978-80-214-6230-4
ISSN
—
e-ISSN
—
Number of pages
4
Pages from-to
92-95
Publisher name
Brno University of Technology, Faculty of Electrical Engineering and Communication
Place of publication
Brno
Event location
Brno
Event date
Apr 23, 2024
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—