Shipulin Georgy Farizovich (PhD in Law, Associate Professor, RTU MIREA; Associate Professor, Moscow Polytechnic University)
| |
The article is devoted to the consideration of issues related to the collection of information about the functioning of web applications in the framework of security assessment and penetration testing. The paper considered the main elements of the information collection process during penetration testing according to the OWASP Web Security Testing Guide web application penetration testing methodology, including the categories of data collected and aspects of their analysis for metadata, information about the components of the web application and the technology stack used. Based on the analysis of existing automated web scanning tools for web applications, their main limitations were identified (insufficient scanning coverage and completeness of data collection, mono-tasking). The architecture of the developed distributed web application network scanning system with component-level spidering and crowling functions is described, and the results of its experimental launches are presented.
Keywords:penetration testing, OWASP, web application, network scanning, crawling, spidering, information collection, information security
|
|
| |
|
Read the full article …
|
Citation link: Shipulin G. F. BUILDING A DISTRIBUTED WEB APPLICATION NETWORK SCANNING SYSTEM WITH SPIDERING AND CROWLING FUNCTIONS // Современная наука: актуальные проблемы теории и практики. Серия: Естественные и Технические Науки. -2026. -№02. -С. 216-220 DOI 10.37882/2223-2966.2026.02.49 |
|
|