WEB APPLICATION TESTING USING OWSAP METHODOLOGY AND BURPSUITE
DOI:
https://doi.org/10.64751/Abstract
Web applications are widely used for delivering digital services such as e-commerce, banking, education, healthcare, and business management. Since these applications process sensitive information and communicate with databases, APIs, and authentication systems, security weaknesses can create serious risks. Regular security testing is therefore necessary to identify vulnerabilities and improve the overall security posture of web applications. The proposed Web Application Testing Using OWASP Methodology and Burp Suite project provides a systematic approach for assessing the security of web applications within an authorized testing environment. The OWASP methodology provides a structured security-testing approach, while Burp Suite supports the inspection and analysis of web application traffic. Together, they help security testers identify and document potential security weaknesses. The assessment focuses on important security areas such as authentication, authorization, session management, input validation, security configuration, access control, and protection of sensitive information. Identified observations are validated and classified according to appropriate OWASP categories. Each finding can be assigned a severity level and documented with relevant evidence and remediation recommendations. The proposed system can provide a centralized dashboard for displaying assessment progress, vulnerability categories, severity distribution, affected components, and remediation status. Assessment results can be stored for historical comparison, allowing security teams to monitor whether previously identified issues have been addressed. The system can also generate structured reports for developers, testers, and management. The main objective of the project is to improve the efficiency, consistency, and documentation of web application security testing. By combining the OWASP methodology with Burp Suite-assisted testing, vulnerability classification, risk assessment, visualization, and reporting, the platform provides a comprehensive defensive security workflow. All testing activities should be conducted only against applications for which explicit authorization has been obtained.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.







