Automated Fuzzing Tool for Testing Web Application Security
Authors
Deen Bandhu Chhotu Ram University of Science and Technology, Murthal, Sonipat (India)
Deen Bandhu Chhotu Ram University of Science and Technology, Murthal, Sonipat (India)
Deen Bandhu Chhotu Ram University of Science and Technology, Murthal, Sonipat (India)
Article Information
DOI: 10.51244/IJRSI.2026.1306000306
Subject Category: Cybersecurity
Volume/Issue: 13/6 | Page No: 4161-4168
Publication Timeline
Submitted: 2026-06-14
Accepted: 2026-06-20
Published: 2026-07-07
Abstract
The importance of Web Application Security grows daily as more organizations are threatened and attacked by cyber criminals. With the growing threat from cyber criminals, performing security testing to identify vulnerabilities in web systems is critical. Of all security testing techniques, fuzz testing is perhaps the best technique available today. Fuzz testing involves injecting input into a target application, including malformed, unexpected, or random data to see how it reacts when it receives bad data. In the case of web applications, fuzz testing is done by sending numerous HTTP requests (each request contains different forms of crafted or invalid data) to a web server to measure the response generated by the server.
This study will create an Automated Web Application Fuzzer which will be integrated with Jenkins so that continuous security testing of Web Applications can occur. Test cases were created using known security vulnerabilities within web applications. Testing revealed that the automation tool found vulnerabilities in thirteen (13) out of fifteen (15) test cases. Therefore, testing reveals that the majority of web vulnerabilities can be easily identified simply by reviewing the content of HTTP responses, thereby validating the effectiveness of the proposed automated web application fuzzing methodology
Keywords
Web Application Security, Fuzz Testing
Downloads
References
1. OWASP Foundation, “JBroFuzz,” Open Web Application Security Project. [Google Scholar] [Crossref]
2. N. Antunes and M. Vieira, “Wapiti: A black-box web application vulnerability scanner,” SourceForge [Google Scholar] [Crossref]
3. Kali Linux, “Wfuzz: Web application fuzzing tool,” Kali Linux Tools. [Google Scholar] [Crossref]
4. PortSwigger Ltd., “Burp Suite: Web vulnerability scanner,” PortSwigger. [Google Scholar] [Crossref]
5. Arce, “w3af: Web application attack and audit framework,” w3af Project. [Google Scholar] [Crossref]
6. OWASP Foundation, OWASP Testing Guide, ver. 3, 2008. [Google Scholar] [Crossref]
7. K. Kawaguchi, “Jenkins: Continuous integration server,” Jenkins Wiki [Google Scholar] [Crossref]
8. StackHawk, “Techniques and tools of fuzz testing,” StackHawk Blog [Google Scholar] [Crossref]
9. PentesterLab, “Web for Pentester ISO,” PentesterLab [Google Scholar] [Crossref]
10. bWAPP Project, “bWAPP: Buggy Web Application,” SourceForge. [Google Scholar] [Crossref]
11. OWASP Foundation, “OWASP Mutillidae II, ver. 2.0.9,” OWASP. [Google Scholar] [Crossref]
12. OWASP Foundation, “OWASP Top 10 – Web Application Security Risks,” OWASP. [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- “Next-Generation Cybersecurity Through Blockchain and AI Synergy: A Paradigm Shift in Intelligent Threat Mitigation and Decentralised Security”
- Forensic Payroll Analytics for IPPIS: A Hybrid Anomaly-Detection Framework to Expose Payroll Fraud, Improve Data Governance, and Protect Employee Rights
- Factors Influencing Data Protection on Global Trade
- Development Of Artificial Intelligence-Based Model for Forensic Analysis of Cross-Platform Deepfakes
- Cyber Threats and Nigeria’s National Security: Assessing the Role of Regional Cooperation in West Africa