SURESHKUMAR.NET FORUMS
Registered Member Login:
Not a member? Register today!



Welcome to the SURESHKUMAR.NET FORUMS.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.




Security testing

        

Reply
 
LinkBack Thread Tools Display Modes
Old 18-02-08, 04:23 PM   #1 (permalink)
Senior Member
 
akankshalal's Avatar
 
Join Date: Feb 2008
Posts: 14
Thanks: 1
Thanked 5 Times in 3 Posts
Rep Power: 3 akankshalal is on a distinguished road
Security testing

Plz tell me about security testing...n wht r career prospects?

akankshalal is offline Offline   Reply With Quote
Old 19-02-08, 02:34 AM   #2 (permalink)
Senior Member
 
Join Date: Jan 2008
Location: hyd
Age: 27
Posts: 108
Thanks: 0
Thanked 24 Times in 15 Posts
Rep Power: 6 tejus is a jewel in the rough tejus is a jewel in the rough tejus is a jewel in the rough
hi

In security testing we have to consider 3 things
1. authorization (EX:user name:akankshalal, not akankshalal1)
2. encryption (EX: password:mercury, encrypt password:*******)
3. access control (flow)
hope i reach your point of view. ok bye
if i am wrong please inform.
tejus is offline Offline   Reply With Quote
Old 11-06-08, 04:21 PM   #3 (permalink)
Junior Member
 
Join Date: Jun 2008
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 2 jitenderkkr is on a distinguished road
Re: Security testing

Hi, security testing is not limited to checking just three but yes these three points are inspected well in security testing. Basic purpose of security testing is to find out vulnerabilities in your application and get them fixed. Now vulnerability could be of authentication or of authorization type or any of the various other types. There are many areas to look for while doing the security testing. First checking the application against various kinds of attacks( Like XSS, SQL injections, Bufferoverflow, Session Hijacking etc.) Once you find a flaw it must be fixed as soon as possible.
Security testing is really a very big area to wrok under. As for a normal security test using automation tools one can check for more than 100K risks in single test run. Still if there is any query, I am here to reply
jitenderkkr is offline Offline   Reply With Quote
Old 19-08-08, 08:15 PM   #4 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 2 dreamzunlimited47 is on a distinguished road
Smile Re: Security testing

Quote:
Originally Posted by jitenderkkr View Post
Hi, security testing is not limited to checking just three but yes these three points are inspected well in security testing. Basic purpose of security testing is to find out vulnerabilities in your application and get them fixed. Now vulnerability could be of authentication or of authorization type or any of the various other types. There are many areas to look for while doing the security testing. First checking the application against various kinds of attacks( Like XSS, SQL injections, Bufferoverflow, Session Hijacking etc.) Once you find a flaw it must be fixed as soon as possible.
Security testing is really a very big area to wrok under. As for a normal security test using automation tools one can check for more than 100K risks in single test run. Still if there is any query, I am here to reply
Security Testing mainly is nothing but the check security and vulnerability in the application under test.
When I say Security then you have to adhere certain standard in your application and the Tester needs to see whether those standards are meet or not.
For example lets take password:
1: It should not be visible in plain text
2: It should be encrypted
3: There should be minimum and maximum length
4: If the processing time to authenticate is based on the length of the password then the code should be written in such a way that it should take almost same time for all processing.
5: Password should not flow in plain text in the networks.

Buffer Overflow should be handled properly
Unused codes should be deleted
The codes should not expose any vulnerability to the outer world. Like if the code is opening some socket then it should be properly closed.

For these kind of testing one requires a coding experience and should have a good idea on security concepts.

When it comes to Vulnerability then the testers needs to check how strong is the application to defend it self from external attacks.
It could be cross site scripting, sql injection , Cookies manipulatin , Denial Of Service Attack , Torzen Horse Attack, Dictionary Attack and server hundred types of other attacks. Hope this information helps you in some respect
dreamzunlimited47 is offline Offline   Reply With Quote
Old 22-08-08, 03:48 PM   #5 (permalink)
Junior Member
 
sharma.raja82@yahoo.com's Avatar
 
Join Date: Aug 2008
Posts: 3
Thanks: 0
Thanked 2 Times in 2 Posts
Rep Power: 2 sharma.raja82@yahoo.com is on a distinguished road
Re: Security testing

HI,
Dreamzunlimited,

Can you tell me sometiong about "Ciphers"...

Like.. How we can test "weak ciphers" and "Strong ciphers".
sharma.raja82@yahoo.com is offline Offline   Reply With Quote
Reply

Tags
security , testing


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
What kinds of testing should be considered? moses.rozario Testing Tools & QA 9 08-01-10 05:31 PM
Types of Testing akhila Testing Tools & QA 3 03-02-09 03:51 PM
TESTING TOOLS SITES yathish Testing Tools & QA 9 10-12-08 11:15 PM
testing defintions AjayKumar.Kataram Testing Tools & QA 1 23-04-08 02:08 PM


All times are GMT +6.5. The time now is 03:26 AM.

More Interview Questions Here...

Content Relevant URLs by vBSEO 3.3.2