Prepare for your Next Interview
|
Welcome to the Geeks Talk forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us. |
This is a discussion on Testing PHP – Security Testing within the Testing Issues forums, part of the Software Testing category; Hi, What all aspects are steps one has to take and consider while doing security testing of a PHP application? Regards, RyanJames...
|
|||||||
|
|||
|
Testing PHP – Security Testing
Hi,
What all aspects are steps one has to take and consider while doing security testing of a PHP application? Regards, RyanJames |
| Sponsored Links |
|
|||
|
Re: Testing PHP – Security Testing
One of the aspects to take care of is login page security testing namely validation of userid and password has it been done without any loopholes for error or hacking into the system. Some other things like per page security checks and so on can be done based on the application which is taken for testing.
|
|
|||
|
Re: Testing PHP – Security Testing
Hi timmy, PHP will come under the web application, so we have to concentrate more on SQL and Java injection. other than this we have to do penetrate testing for the login page. |
|
|||
|
Re: Testing PHP – Security Testing
well, you have to test first for the javascript functionalities used in your application..
Second thing is url testing..I mean directly putting login url of diffrent accounts..there should be validations on these test points.. |
|
|||
|
Re: Testing PHP – Security Testing
Any data inserted into an output stream originating from a server is presented as originating from that server, even if it does not include malicious tags. Web developers must evaluate whether their sites will send untrusted data as part of an output stream.
Untrusted input can come from, but is not limited to, * URL parameters * Form elements * Cookies * Databases queries A combination of steps must be taken to mitigate this vulnerability. These steps include 1. Explicitly setting the character set encoding for each page generated by the web server 2. Identifying special characters 3. Encoding dynamic output elements 4. Filtering specific characters in dynamic elements 5. Examine cookies |
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Difference between Usability and Functional Testing | sunny_love | Testing Issues | 12 | 10-08-2007 02:08 AM |