Ir directamente a la navegación principal Ir directamente a la búsqueda Ir directamente al contenido principal

Generative AI for web application pentesting

  • Raul Diaz Parra

Producción científica: Contribución a una revistaArtículo (Contribución a Revista)revisión exhaustiva

Resumen

The integration of Generative AI into cybersecurity practices has opened new possibilities for automating and enhancing offensive security operations. This study explores the application of ShellGPT in the context of web application penetration testing using the OWASP Web Security Testing Guide (WSTG) as the methodological framework. The experiment targeted a vulnerable application and systematically progressed through reconnaissance, enumeration, and exploitation phases. Notably, ShellGPT successfully identified and exploited an SQL injection vulnerability, enabling full data extraction from the backend database. Results show that LLMs can generate accurate commands and support non-expert users throughout the penetration testing lifecycle.
Idioma originalEspañol (Perú)
Páginas (desde-hasta)502-514
PublicaciónIssues in Information Systems
Volumen26
N.º1
DOI
EstadoPublicada - 4 oct. 2025

Palabras Clave

  • Cybersecurity
  • Offensive security
  • Penetration testing
  • Large language models
  • ShellGPT

Citar esto