Tag: security
Questions Related to security
-
Admin/admin1
-
John/nAscar
-
John/n@sc1234r
-
John/nascar2
-
../../help/images/about.jpeg
-
-
d:/etc/host/pwd
-
document.title(“/admin/administration”);
-
Don’t have to inform the application owner
-
To prevent production database corruption
-
To prevent user functionality disruption
-
To reduce network traffic
-
Inform the user population about the test
-
Inform the QA and system administers about the test
-
Backup the database
-
Shut down the configured SMPT servers
-
User account compromised
-
Steal user sessions
-
Site defacement and complete take over of the application
-
Complete user account compromise
-
Use https
-
Use encryption
-
Black box testing
-
Secure coding
-
400 return code
-
500 return code
-
302 return code
-
200 return code
-
Displaying “Welcome, “+request.getParameter(“userid”)
-
Displaying “You entered either a wrong user id or password” error message
-
Call stack trace
-
Return error code 404
-
Configure appscan not to test login/logout pages
-
Increase the thread count
-
Decrease the timeout
-
Increase the timeout
-
Add the domain name in the “Additional servers and domains” section in the scan configuration
-
Add 10.1.52.3 in the “Additional servers and domains” section in the scan configuration
-
Put the domain name in the login url
-
Change the application code to reflect the domain name every where