July 23rd, 2008 chris
Security nowadays is more of a necessity than a luxury. Due to the influx of networks and the internet, every system is a sitting duck for the predator. There are three trends that have a great influence on the growth and evolution of the security problem. They are called the Trinity of Trouble and they are the following:
- Connectivity
- Extensibility
- Complexity
Posted in Software Security
July 23rd, 2008 chris
The Test Plan Document describes the scope, approach, resources, and schedule of the testing activities.
It is composed of the following 16 Sections:
- Test plan identifier
- Introduction
- Test items
- Features to be tested
- Features not to be tested
- Approach
- Item pass/fail criteria
- Suspension criteria and resumption requirements
- Test deliverables
- Testing tasks
- Environmental needs
- Responsibilities
- Staffing and training needs
- Schedule
- Risks and contingencies
- Approvals
Posted in Software Testing
July 23rd, 2008 chris
Eight documents that can be used in software testing according to IEEE Standard for Software Test Documentation
- Test plan
- Test design specification
- Test case specification
- Test procedure specification
- Test item transmittal report
- Test log
- Test incident report
- Test summary report
Posted in Software Testing
July 23rd, 2008 chris
The following are the five issues to watch for on Shared Hosting
- Exposed Source Code
- Exposed Session Data
- Session Injection
- Filesystem Browsing
- Safe Mode
Posted in Software Security
July 23rd, 2008 chris
The following are the four issues to watch for on Authentication and Authorization
- Brute Force Attacks
- Password Sniffing
- Replay Attacks
- Persistent Logins
Posted in Software Security
July 23rd, 2008 chris
The following are the three issues to watch for on Files and Commands
- Transversing the Filesystem
- Remote File Risks
- Command Injection
Posted in Software Security
July 23rd, 2008 chris
The following are the four issues to watch for on Includes
- Exposed Source Code
- Backdoor URLs
- Filename Manipulation
- Code Injection
Posted in Software Security
July 23rd, 2008 chris
The following are the four issues to watch for on Sessions and Cookies
- Cookie Theft
- Exposed Session Data
- Session Fixation
- Session Hijacking
Posted in Software Security
July 23rd, 2008 chris
The following are the three issues to watch for on Database and SQL
- Exposed Access Credentials
- SQL Injection
- Exposed Data
Posted in Software Security
July 23rd, 2008 chris
The following are the seven issues to watch for on Forms and URLs
- Forms and Data
- Semantic URL Attacks
- File Upload Attacks
- Cross-Site Scripting
- Cross-Site Request Forgeries
- Spoofed Form Submission
- Spoofed HTTP Request
Posted in Software Security