GeekInterview.com
  I am new, Sign me up!
 
GeekInterview.com  >  Interview Questions  >  Testing  >  DataBase Testing
Go To First  |  Previous Question  |  Next Question 
 DataBase Testing  |  Question 31 of 50    Print  
This is regarding security of a Database ...How can i test the security of a DB written using Stored Procedures....
1.Can I do SQl Injection attacks..If not
what else are the methods

  
Total Answers and Comments: 3 Last Update: July 06, 2007     Asked by: rose 
  
 Sponsored Links

 
 Best Rated Answer
Submitted by: idreams27
 

Hi,

Security testing can be performed in many ways. It can performed specified areas

    1. Black-Box Level
    2. White-Box Level and finally at
    3. Database Level.

For each of these there incudes different types of methods and based on these we can follow them. But all these methods can be used manually to test your application in above specified areas. We also require certian tools for few of the methods

Here are the list of security testing methods and techniques used in 3 areas

Functionality Testing
   a. Session Hijacking
   b. Session Prediction
   c. E-mail Spoofing
   d. Content Spoofing
   e. Phishing
   f.  Password Cracking
   g. Active Program Scripting Exploits

White-Box Testing
  a. Malicious Code Injection
  b. Penetration testing
  c. Input Validation
  d. Variable Manipulation

Database Testing (Stored procedures can be testing by SQL Injection and variable manipulation techniques you can fine more info on net)
  a. SQL injection
  b. Blind SQL Injection(Part of SQL Injection)
  c.  Input Validation

Atlast at website/webapplication level
  a. Cross-site scripting
  b. SSI Injection
  c. IP Spoofing

Hope this gives idea on what is security testing and in which all areas we carry out testing with what all methods and techniques

For any  more clarifications you can write at idreams27@yahoo.com

Thanks
Narasimha



Above answer was rated as good by the following members:
ramgupta
December 17, 2006 01:12:38   #1  
mcsreddy        

RE: This is regarding security of a Database ...How ca...

hi

Security testing is very critical these testing was performed by seperate team.for these security testing these people r using separate tools.by using stored procedures also we can perform the testing but we hav knoledge on database.Security testing performs penetration testing which is very tough.

By using queries also we can test the database but it requries more exposure on writing the database queries.


 
Is this answer useful? Yes | No
February 19, 2007 06:39:07   #2  
Naveen Pathak        

RE: This is regarding security of a Database ...How ca...

Hi Dear

The scurity test conduct in following areas:

1) Whether user comes from proper Login Page

2) Applying SQL injection and session hijecking

3)Whether Customer order file are un restrictive .

4)Email confirmation should be abaliable

Regards;

Naveen Pathak


 
Is this answer useful? Yes | No
July 06, 2007 08:10:16   #3  
idreams27 Member Since: July 2007   Contribution: 8    

RE: This is regarding security of a Database ...How ca...

Hi

Security testing can be performed in many ways. It can performed specified areas

1. Black-Box Level
2. White-Box Level and finally at
3. Database Level.

For each of these there incudes different types of methods and based on these we can follow them. But all these methods can be used manually to test your application in above specified areas. We also require certian tools for few of the methods

Here are the list of security testing methods and techniques used in 3 areas

Functionality Testing
a. Session Hijacking
b. Session Prediction
c. E-mail Spoofing
d. Content Spoofing
e. Phishing
f. Password Cracking
g. Active Program Scripting Exploits

White-Box Testing
a. Malicious Code Injection
b. Penetration testing
c. Input Validation
d. Variable Manipulation

Database Testing (Stored procedures can be testing by SQL Injection and variable manipulation techniques you can fine more info on net)
a. SQL injection
b. Blind SQL Injection(Part of SQL Injection)
c. Input Validation

Atlast at website/webapplication level
a. Cross-site scripting
b. SSI Injection
c. IP Spoofing

Hope this gives idea on what is security testing and in which all areas we carry out testing with what all methods and techniques

For any more clarifications you can write at idreams27@yahoo.com

Thanks
Narasimha


 
Is this answer useful? Yes | NoAnswer is useful 1   Answer is not useful 0Overall Rating: +1    


 
Go To Top


 Sponsored Links

 
About Us -  Privacy Policy -  Terms and Conditions -  Contact -  Ask Question -  Propose Category -  Site Updates 

Copyright © 2005 - 2009 GeekInterview.com. All Rights Reserved

Page copy protected against web site content infringement by Copyscape