GeekInterview.com
  I am new, Sign me up!
 
GeekInterview.com  >  Interview Questions  >  Testing  >  Security Testing
Go To First  |  Previous Question  |  Next Question 
 Security Testing  |  Question 6 of 11    Print  
Security Tools
A Web online specialty company has a online website and they want to you test. What sort of security tools or security need is required for a Test Analyst when he does testing?


  
Total Answers and Comments: 6 Last Update: August 11, 2009     Asked by: yonca 
  
 Sponsored Links

 
 Best Rated Answer

No best answer available. Please pick the good answer available or submit your answer.
July 31, 2008 08:47:55   #1  
srinivasulub1981 Member Since: December 2005   Contribution: 381    

RE: Security Tools

As per my knowledge below security methods needs to be verified in web testing.

· Cross-site scripting

· SQL Injection

· Buffer overflows

· Hidden fields

· CGI parameters

· Cookies

· Forceful browsing

· URL jumping

· Automatic Form fillers

· Known Attacks

· Crawling



 
Is this answer useful? Yes | No
July 31, 2008 08:48:57   #2  
srinivasulub1981 Member Since: December 2005   Contribution: 381    

RE: Security Tools
And there are so many open source tools to test security vulnerabilities like paros Acunetix.
 
Is this answer useful? Yes | No
September 13, 2008 07:09:32   #3  
Shilpa0901 Member Since: September 2008   Contribution: 5    

RE: Security Tools
It is a type of testing in which one will concentrate on the following areas.

Authentication
Direct URL testing
Firewall leakage testing

Authentication: in this type of testing usually one will enter different combinations of usernames and passwords and check whether it is allowing only authorised users or not.


Direct URL: In this type of testing one will enter the direct URL's and try to access the unauthorised pages and check whether they are been accessed or not.


Firewall Leakage: In this type of testing one level of users try to access other level of user pages to check whether firewalls are working properly or not.


 
Is this answer useful? Yes | No
March 29, 2009 03:15:49   #4  
saja_mohd Member Since: March 2009   Contribution: 1    

RE: Security Tools
Security Center Team Viewer Connection Internet
 
Is this answer useful? Yes | No
August 08, 2009 03:31:48   #5  
saravanan123 Member Since: July 2009   Contribution: 163    

RE: Security Tools
For security testing no toolis thereit shouldbe tested manualy but with the help os Load runner we can see howit will be
 
Is this answer useful? Yes | No
August 11, 2009 04:43:48   #6  
mathan_vel Member Since: December 2007   Contribution: 422    

RE: Security Tools

“The Security tools suite provides a fully featured web security scanner crawler report analysis tool as well as web security explanations and an extensive database of security checks for all leading web server platforms. The all-in-one web security software lets the user scan for SANS Top 20 and OWASP Top 10 2004 vulnerabilities. Additionally the new baseline security scanning feature automatically detects reports & addresses outdated server software closing up your web server even more to vulnerabilities and possible attacks.”

SANS: (Client-side Vulnerabilities in Server-side Vulnerabilities in Security Policy and Personnel Application Abuse Network Devices Zero Day Attacks)


OWASP: (Input Validation Access Control Authentication and Session Management Input Validation->Cross site scripting Buffer Overflows Input Validation->Injection Error Handling Data Protection Availability Application Configuration Management
Infrastructure Configuration Management)

 
Is this answer useful? Yes | No


 
Go To Top


 Sponsored Links

 
About Us -  Privacy Policy -  Terms and Conditions -  Contact -  Ask Question -  Propose Category -  Site Updates 

Copyright © 2005 - 2009 GeekInterview.com. All Rights Reserved

Page copy protected against web site content infringement by Copyscape