International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1718982

1718982PublishedVol 9 · Issue 1

A Web-Based Automated Fuzzing Tool for Web Applications

Ritik Dhankhar Ajay Sharma Shakti Arora

Subject area: Science,Engineering and Technology  ·  Area of research: Fuzzing Tool

DOI: https://doi.org/10.64388/IREV9I1-1718982

Abstract

The importance of Web Application Security grows daily as more organizations are threatened and attacked by cyber criminals. With the growing threat from cyber criminals, performing security testing to identify vulnerabilities in web systems is critical. Of all security testing techniques, fuzz testing is perhaps the best technique available today. Fuzz testing involves injecting input into a target application, including mal- formed, unexpected, or random data to see how it reacts when it receives bad data. In the case of web applications, fuzz testing is done by sending numerous HTTP requests (each request contains different forms of crafted or invalid data) to a web server to measure the response generated by the server. This study will create an Automated Web Application Fuzzer which will be integrated with Jenkins so that continuous security testing of Web Applications can occur. Test cases were created using known security vulnerabilities within web applications. Testing revealed that the automation tool found vulnerabilities in thirteen (13) out of fifteen (15) test cases. Therefore, testing reveals that the majority of web vulnerabilities can be easily identified simply by reviewing the content of HTTP responses, thereby validating the effectiveness of the proposed auto- mated web application fuzzing methodology

Keywords

Web Application Security, Fuzz Testing, Automated Vulnerability Detection, HTTP Request Testing

How to cite this paper

Ritik Dhankhar, Ajay Sharma, Shakti Arora "A Web-Based Automated Fuzzing Tool for Web Applications" Iconic Research And Engineering Journals Volume 9 Issue 1 2025 Page 2235-2243 https://doi.org/10.64388/IREV9I1-1718982
Ritik Dhankhar, Ajay Sharma, Shakti Arora "A Web-Based Automated Fuzzing Tool for Web Applications" Iconic Research And Engineering Journals, vol. 9, no. 1, Jul. 2025, doi: https://doi.org/10.64388/IREV9I1-1718982
Ritik Dhankhar, Ajay Sharma, Shakti Arora (2025). A Web-Based Automated Fuzzing Tool for Web Applications. Iconic Research And Engineering Journals, 9(1). doi: https://doi.org/10.64388/IREV9I1-1718982
Ritik Dhankhar, Ajay Sharma, Shakti Arora "A Web-Based Automated Fuzzing Tool for Web Applications" Iconic Research And Engineering Journals, vol. 9, no. 1, Jul. 2025. Crossref, https://doi.org/10.64388/IREV9I1-1718982
@article{1718982,
      author = {Ritik Dhankhar, Ajay Sharma, Shakti Arora},
      title = {A Web-Based Automated Fuzzing Tool for Web Applications},
      journal = {Iconic Research And Engineering Journals},
      year = {2025},
      volume = {9},
      number = {1},
      pages = {2235-2243},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1718982.pdf},
      abstract = {The importance of Web Application Security grows daily as more organizations are threatened and attacked by cyber criminals. With the growing threat from cyber criminals, performing security testing to identify vulnerabilities in web systems is critical. Of all security testing techniques, fuzz testing is perhaps the best technique available today. Fuzz testing involves injecting input into a target application, including mal- formed, unexpected, or random data to see how it reacts when it receives bad data. In the case of web applications, fuzz testing is done by sending numerous HTTP requests (each request contains different forms of crafted or invalid data) to a web server to measure the response generated by the server. This study will create an Automated Web Application Fuzzer which will be integrated with Jenkins so that continuous security testing of Web Applications can occur. Test cases were created using known security vulnerabilities within web applications. Testing revealed that the automation tool found vulnerabilities in thirteen (13) out of fifteen (15) test cases. Therefore, testing reveals that the majority of web vulnerabilities can be easily identified simply by reviewing the content of HTTP responses, thereby validating the effectiveness of the proposed auto- mated web application fuzzing methodology},
      keywords = {Web Application Security, Fuzz Testing, Automated Vulnerability Detection, HTTP Request Testing},
      month = {July},
      doi = {https://doi.org/10.64388/IREV9I1-1718982}
  }