Tag: security
Questions Related to security
-
HTTP-ONLY is set
-
Domain is not set
-
Expiration is set to one week
-
Expiration is set to one day
-
The website could be defaced, and database tables could be deleted
-
Sensitive data could be stolen
-
A malicious script could be executed, and database tables could be deleted
-
A malicious script could be executed, and session tokens could be predicted
-
manually test for vulnerabilities
-
manually log in
-
manually step through the application
-
exclude links from the scan
-
ensure JavaScript Execute is turned on
-
track the “viewpromotions” parameter
-
ignore the “timestamp” parameter
-
turn off the Redundant Path limit setting
-
socialSecurityNumber
-
socialSecurityNum
-
secnum
-
customerssn
-
Application Tree
-
Request/Response
-
Application Data
-
Remediation Tasks View
-
a test policy
-
a test variant
-
a test case
-
a test HTTP request
-
Client (Browser)
-
Database
-
Web Application
-
Web Server
-
Group based access control should be implemented to assign permissions to application users
-
Consistent authorization checking should be performed on all application pages
-
A set of all allowable actions should be defined for each user role and all other's denied
-
All failed access authorization requests should be logged to a secure location for review by administrators
-
Hidden tags
-
Query Strings
-
Header
-
Cookies