Skip to main content

Security Testing Basic

Security testing is an activity intended to bring out of flaws in the security mechanisms of a data system that protect data & maintain functionality as thought. Security Testing is a type of software testing that means to uncover exposures of the system & determine that its information and resources are saved from possible interlopers.
Security testing is a huge subject. Each and every technology that you use; whether it is programming words like PHP & .NET and a feature like authentication & input validation; introduces a new set of security exposures. 
What really should come in mind piece concerned about security?
  •  Authentication: The source of the application & its data is real.
  •  Authorization: Particular users should only get enter in to authorized functions.
  • Confidentiality: Data and information is protected from theft.
  • Integrity: The application & its data are not altered in course of time during transmittal.
  •  Non repudiation: Guaranteed that sender & receiver of data cannot deny having sent and received the information.
  • Focus Ares for Security:There are the four main focus areas to be included in security testing:
  • Network security: It’s involves looking for exposures in the network infrastructure (resources & policies).
  •  System software security: It’s involves assessing failing in the some software (operating system, & other software, database system).
  • Client-side application security: It deals with insuring that the client (browser and any such tool) can’t be manipulated.
  •  Server-side application security: It is involves making sure that the server code & its technologies are robust sufficient to fend off any invasion.

EXAMPLE OF A BASIC SECURITY TEST
This is the example of a very basic security test which one can perform on a web site or application:
1.       Login of the web application.
2.       Log out to the web application.
3.       Click on the button of the browser (Check if you are asked to login again and if you are allowed for the logged in application.)




OWASP

The meaning of “Open Web Application Security Project” (OWASP) is a greater resource for software security masters. Be ensuring to check out the “Testing Guide”:
WASP Top 10 security threats are:
  1.  Injecting injection
  2. Broken Authentication & Session Management
  3. Cross Site Scripting (XSS)
  4.  Unsafe Direct Target References
  5. Security in Misconfiguration
  6.  Sensitive Information Exposure
  7.  Escaping Function Level Access Control
  8. Cross Site Request Forgery (CSRF)
  9.  Using Known exposure Elements
  10.  Invalidated Redirects & Forwards

Use of Automated Security Scanner Tools
Using the over the attacks & checking that security application development best exercises have been followed is a large part of testing whether an application is protected or not. But one should not completely depend on manually testing them. It is a fast stepped world with a lot of time restraint. There are many tools in the market that can easily to check for each the security exposure in a go. The Nets parker community version demo can be downloaded free. Also there is online testing creature (tools); but I have not tried whatever those were better than the Nets parker.

Comments

  1. Hi
    Thanks for your post,

    This is good idea, even i wasn't aware about these things. Thanks for giving basic information about testing. I hope this will be benefecial for my web too

    Thanks
    Invoicing Software

    ReplyDelete

Post a Comment

Popular posts from this blog

In Regression Testing: Difference between Automation And Manual Testing

The difference between an Automation Testing & Manual-Testing is a pillar of the Software testing, because the whole-testing is based on the Automation Testing and Manual Testing. In the project you can do both Automation Testing & Manual Testing & you can also do both Automation testing and Manual Testing simultaneously. Difference between Automation and Manual Testing Automation Testing Manual Testing The automation testing is a continuous component of the manual testing. This testing is an initiate of the testing, without of this testing we cannot start the automation testing. This takes less of time. This takes a lot of time. In the automation testing, we always test by the running the scripts. In the manual testing testers’re allowed to do the random for find the Bugs. In automation testing, it is done on the different on same time. The manual testing would be executes sequentially. ...

Want to know about Mobile Application Testing? Came to right place

What is Mobile Application Testing ? Mobile Application Testing is a phenomenon of testing functionality, usability and consistency of application software designed for mobiles. It is done in two ways: Automated and Manually. When you buy a new mobile, various applications came pre-installed and some you install as per your need from mobile software distribution platforms such as Google Play, Nokia Store etc. In the recent years, mobile devices had shown a rapid growth rate .  Factors that give an open challenge to Mobile application Testing : 1. Mobile devices models : Different models have different hardware configurations, input methods (some are QWERTY, some are touch while others are normal). 2. Several different operating systems (OS) : Market  is full of availability of different operating  systems  (   Android , IOS, BREW, BREWMP, Symbian,   Windows Phone , and   BlackBerry   (RIM)).Each operating system is unique in ...

INTRODUCTION TO SELENIUM TESTING

If you are interesting in software testing and desperately want to work in software testing profile then this post is surely for you, as we know that selenium testing is an important aspect of  software testing so you should go through this at least once. WHAT IS SELENIUM TESTING? SELENIUM is a tool for authoring tests without learning test scripting language like selenium IDE. Selenium is not just a tool but actually it is a cluster of independent tools. And selenium testing is a testing which is performed by using selenium tool. WHY WE USE SELENIUM TESTING I f we talk about the functioning and scenario of today's IT industries or companies then it is known to everyone that there is a mass movement towards automation testing. Not only this but the cluster of manual testing scenario  has also raised a great demand to make to manual testing automated by using various tools such as selenium.  There are numerous benefits which a software tester gets if he/she impleme...