6
Security Testing Case Study 360logica Software Testing Services

Security Testing Case Study 360logica Software Testing Services

Embed Size (px)

Citation preview

Page 1: Security Testing Case Study 360logica Software Testing Services

Security Testing Case Study

360logica Software Testing Services

Page 2: Security Testing Case Study 360logica Software Testing Services

The Client

Our Customer is a Online News Community http://www.newsfromfriends.com . User can get their personal newspaper and share thoughts and address them to special persons

Page 3: Security Testing Case Study 360logica Software Testing Services

The requirements

• Customer wanted to make sure their users privacy and content are secured enough, few of their security test requirements are below:

• SQL injection vulnerability• Cross site scripting• Business workflow securities• Authentication security• Brute force authentication breach testing• Firewall security testing• Web server files security

Page 4: Security Testing Case Study 360logica Software Testing Services

The Solution

• Identification of Application Input e.g. Files, environment variables, parameters in URL, through form submission etc., config files and registry

• Identification Application Output e.g. Files, Environmental Variables , Network Traffic , The Windows Registry , Console/Form , Database Source and Hidden

• Logical tests Authentication, login, Email confirmation, business work flow securities, data encryption etc.

Page 5: Security Testing Case Study 360logica Software Testing Services

The Technology• PHP

• Linux• Apache

Page 6: Security Testing Case Study 360logica Software Testing Services

Contribution• Breach finding using cross site scripting and SQL

injection• Breach finding using Brute force authentication• Link injection, other user’s profile access breach

and their content as well• Hidden folders and direct files access from web

server• Email security and Data encryption security