Skip to main navigation Skip to search Skip to main content

Generative AI for web application pentesting

  • Raul Diaz Parra

Research output: Contribution to journalArticle (Contribution to Journal)peer-review

Abstract

The integration of Generative AI into cybersecurity practices has opened new possibilities for automating and enhancing offensive security operations. This study explores the application of ShellGPT in the context of web application penetration testing using the OWASP Web Security Testing Guide (WSTG) as the methodological framework. The experiment targeted a vulnerable application and systematically progressed through reconnaissance, enumeration, and exploitation phases. Notably, ShellGPT successfully identified and exploited an SQL injection vulnerability, enabling full data extraction from the backend database. Results show that LLMs can generate accurate commands and support non-expert users throughout the penetration testing lifecycle.
Original languageSpanish (Peru)
Pages (from-to)502-514
JournalIssues in Information Systems
Volume26
Issue number1
DOIs
StatePublished - 4 Oct 2025

Cite this