| With the rapid development of the technology of computer network, the application of Web technology has been widely used in various fields, but because of illegal mining in the Web application security exploit and endless malicious attacks, cause that the web applications provide users with convenient, efficient service, at the same time, users have to possible web for its own security issues and concerns. Therefore, do safety testing and evaluation for Web applications, to find the potential safety hazard and repair it, can effectively improve the reliability and safety of the Web application itself. This paper researches the evaluation method of information security in penetration testing technique,the research content includes the analysis of penetration testing theory, technical analysis, method design, case simulation etc.In the case simulation chapter,the paper mainly selected the most common vulnerability--SQL injection vulnerability, which typically occurs in Web applications, and the case simulation chapter has carried out a depth research and analysis on it. |