Geeks Talk

Prepare for your Next Interview


Welcome to the Geeks Talk forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

security testing

This is a discussion on security testing within the Testing Issues forums, part of the Software Testing category; Hi friends I am currently doing with one banking project so it is very important to have the security testing.but i know to test only with the basic as 1.username ...

Go Back   Geeks Talk > Software Testing > Testing Issues
Register Blogs FAQ Tag Cloud Calendar Mark Forums Read
  #1 (permalink)  
Old 09-02-2009
Junior Member
 
Join Date: Jul 2009
Location: chennai
Posts: 18
Thanks: 0
Thanked 0 Times in 0 Posts
saravanan123 is on a distinguished road
security testing

Hi friends

I am currently doing with one banking project so it is very important to have the security testing.but i know to test only with the basic as

1.username and password security
2.clicking anywhere in the page to get the source code
3.Check by putting the login link and checking

like these if you have undergone any of different security testing ?

otherwise we have any testing tool to undergo mainly for security testing?

can any one help me to know as urgent as possible?

Thanks and regards
Saravanan
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 09-11-2009
Expert Member
 
Join Date: Jul 2007
Location: Kolkata
Posts: 182
Thanks: 7
Thanked 17 Times in 16 Posts
animesh.chatterjee is on a distinguished road
Re: security testing

i just gave reply to the below written thread regarding this...

can you please go and check...

http://www.geekinterview.com/talk/72...testcases.html (Login page Testcases)
Reply With Quote
  #3 (permalink)  
Old 09-11-2009
Junior Member
 
Join Date: Jul 2009
Location: chennai
Posts: 18
Thanks: 0
Thanked 0 Times in 0 Posts
saravanan123 is on a distinguished road
Re: security testing

Dear Amish

I need to know in detail i got some clearance but i need more

canyou guide me to get more souce

regards
Saravanan
Reply With Quote
  #4 (permalink)  
Old 09-14-2009
Expert Member
 
Join Date: Jul 2007
Location: Kolkata
Posts: 182
Thanks: 7
Thanked 17 Times in 16 Posts
animesh.chatterjee is on a distinguished road
Re: security testing

few more testing can be ...

Authentication
* Disallow the user from directly accessing a page requiring the user to be logged in. If you are able to access a page requiring authentication and are currently not logged in, file a security ticket of severity 2-3 depending on the page.

Login
* If the username or password is incorrect do not display a message such as 'Your Username is Incorrect'. Instead ensure that a generic message stating 'Invalid Credentials' is displayed so as not to leak information about existing user accounts. If either the username or password is specifically mentioned file as a severity 3 issue.

Email Confirmation
* When emailing the order confirmation do not leak sensitive information such as the full credit card number, social security number, full name and address, or other similar sensitive information. If the card number or social security referenced in the email displays more than the last 4 digits (Unless otherwise defined) file a severity 2 issue.

Password Reset
* Ensure that if the password is reset that the temporary password expires after a reasonable amount of time as defined by the product manager (default is 48 hours). After 48 hours the temporary password will expire and will need to be regenerated.
Reply With Quote
  #5 (permalink)  
Old 09-16-2009
Junior Member
 
Join Date: Aug 2008
Location: Dubai<<<< Hyderabad
Posts: 10
Thanks: 2
Thanked 1 Time in 1 Post
kprasadbio is on a distinguished road
Re: security testing

i know few thinks like:

1. Secession Time out:
when a customer opens his A/c after that system is idel for long time, when the customer try to access it then the system should prompt for User id and password.

2. firewall testing
3. Cookies testing
Reply With Quote
Reply

  Geeks Talk > Software Testing > Testing Issues

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads

Thread Thread Starter Forum Replies Last Post
security testing hitesh_shah19 Testing Issues 6 05-28-2009 07:51 AM
Security Testing swatiw Testing Issues 10 05-25-2009 07:17 AM
Testing PHP – Security Testing RyanJames Testing Issues 7 02-03-2009 11:53 PM
security testing prathu.s Networking 0 11-13-2008 11:43 PM
Security Testing rose Testing Issues 1 06-20-2007 02:56 AM


All times are GMT -4. The time now is 07:07 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.1
Copyright © 2009 GeekInterview.com. All Rights Reserved