Home / Current Issue / Paper 1705611
Vulnerability Assessment and Penetration Testing in Excel College Website
Subject area: Science,Engineering and Technology · Area of research: Cyber Security
Abstract
The vulnerability assessment and penetration testing project conducted on the Excel College website aimed to evaluate the security posture of the website and identify potential vulnerabilities that could compromise its integrity, confidentiality, and availability. This project involved a systematic approach to simulate real-world attacks, assess security controls, and provide recommendations for remediation. Throughout the assessment, various tools and techniques were employed to identify vulnerabilities such as SQL injection, cross-site scripting (XSS), insecure configurations, and outdated software versions. Additionally, manual testing was performed to uncover logical flaws and assess the overall resilience of the website against different attack vectors.
Keywords
Vulnerability Assessment, Penetration Testing, Security Weaknesses, SQL Injection, Cross-site Scripting (XSS), Security Posture, Automated Scanning, Manual Testing, Remediation Recommendations, Cyber Threats
References
[1] D. J. Stutz and P. S. Barford, “A Survey of Network Attack Detection Techniques,” IEEE Communications Surveys & Tutorials, vol. 15, no. 4, pp. 2026–2049, Fourth Quarter 2013, doi: 10.1109/SURV.2013.033113.00017.
[2] C. Anley, "The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws," Wiley, 2nd Edition, 2011.
[3] P. Engebretson, "The Basics of Hacking and Penetration Testing: Ethical Hacking and Penetration Testing Made Easy," Elsevier, 1st Edition, 2011.
[4] D. Kennedy, J. O'Gorman, R. Hammett, and J. Muniz, "Metasploit: The Penetration Tester's Guide," No Starch Press, 2011.
[5] OWASP Foundation, "OWASP Testing Guide," [Online]. Available: https://owasp.org/www-project-web-security-testing-guide/.
[6] D. J. Cuthbert, M. D. Earp, and J. McCartney, "Penetration Testing: A Hands-On Introduction to Hacking," O'Reilly Media, 2014.
[7] G. S. Anand, N. Bharath, and N. S. Narayanaswamy, "Security Metrics for the Web Application Penetration Testing Process," in 2015 IEEE International Conference on Computational Intelligence and Computing Research, 2015, pp. 1-6, doi: 10.1109/ICCIC.2015.7435736.
[8] M. Stamp, "Information Security: Principles and Practice," Wiley, 2nd Edition, 2011.
[9] P. D. McNamee, S. S. Yau, and M. Papalaskari, "Vulnerability Assessment and Penetration Testing (VAPT): An Overview of Common Practices," in 2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC), 2017, pp. 398-405, doi: 10.1109/COMPSAC.2017.217.
[10] S. J. Jha, S. H. Jha, and S. K. Thakur, "A Comprehensive Review on Penetration Testing Methodologies," in 2016 International Conference on Computational Techniques in Information and Communication Technologies (ICCTICT), 2016, pp. 230-235, doi: 10.1109/ICCTICT.2016.7505187
How to cite this paper
@article{1705611,
author = {Samuel Y, Suganthar Gurusamy R, Nathiya S},
title = {Vulnerability Assessment and Penetration Testing in Excel College Website},
journal = {Iconic Research And Engineering Journals},
year = {2024},
volume = {7},
number = {9},
pages = {175-178},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/17056111.pdf},
abstract = {The vulnerability assessment and penetration testing project conducted on the Excel College website aimed to evaluate the security posture of the website and identify potential vulnerabilities that could compromise its integrity, confidentiality, and availability. This project involved a systematic approach to simulate real-world attacks, assess security controls, and provide recommendations for remediation. Throughout the assessment, various tools and techniques were employed to identify vulnerabilities such as SQL injection, cross-site scripting (XSS), insecure configurations, and outdated software versions. Additionally, manual testing was performed to uncover logical flaws and assess the overall resilience of the website against different attack vectors.},
keywords = {Vulnerability Assessment, Penetration Testing, Security Weaknesses, SQL Injection, Cross-site Scripting (XSS), Security Posture, Automated Scanning, Manual Testing, Remediation Recommendations, Cyber Threats},
month = {March},
}