V24s

"Get Updates : Subscribe to our e-mail newsletter to receive updates........" "Good Luck frnds" Admission 2019 Application Form 2019 Colleges Entrance Exam 2019 Results 2019 Notification 2019 University Educational Jobs 2019 Government Jobs 2019

Search This Blog v24s guys

Showing posts with label Software Testing Tools. Show all posts
Showing posts with label Software Testing Tools. Show all posts

23 February, 2012

Web Application Penetration Testing Tools

Application Penetration Testing


In recent years, web applications has grown dramatically popular, with organizations converting legacy mainframe and database systems into dynamic web applications using technologies such as PHP, Ajax, JavaScript, JSP, Java, ASP, ASP.NET, Cold Fusion, Perl, Flash and Ruby etc. These applications expose customer information, financial data and other sensitive and confidential data over the Internet and intranet. With the accessibility of such critical data, web application security testing also becomes paramount. Ensuring that web applications are secure is a critical need for companies today.

iViZ's on demand application testing platform performs various types of application penetration security audits including web application security Testing, SAP audit, or other customized system audit. iViZ Security uses both black box and white box testing methodology. Enterprise application security being critical to organizations, iViZ Security allows organizations to significantly improve overall security software and reduce risk to the organization in a way that compliments the web application security infrastructure and process they currently have in place.


How Web Application Pen Testing works?

Web Application Penetration Testing is carried out from iViZ Security SOC (Security operations center) remotely over the Internet using our patent-pending technology. The section below details the methodology used in the application security testing process.

Application Penetration Testing, Web Application Security Assessment

iViZ's application penetration test provides a customized, comprehensive, impartial, and periodic security assessment of various kinds of applications - internally developed, commercial enterprise web applications (Web-based portal, e-commerce application, or Web platform), open source applications, dynamic web 2.0 applications etc., This service provides a well-developed matrix of existing threats, application vulnerabilities, and real-world recommendations to address security weaknesses. In addition, iViZ conducts expert validation for vulnerabilities that cannot be identified through automated means.

Application Penetration Testing, Web Application Security Assessment

Internal Application Testing

To test internal applications, a proxy server (web proxy) may be set up at the customer site to act as an intermediary for requests from the iViZ Security scanning servers and test center. The iViZ Security penetration testing servers connect to the proxy server, requesting services, such as a connection, web page, or other resource, available from an internal web application server. Comprehensive testing of internal web applications can be quickly, easily and securely performed in this manner.


iViZ Security Methodology

The assessment methodology includes structured review processes based on recognized “best-in-class” practices as defined by such methodologies as the ISECOM's Open Source Security Testing methodology Manual (OSSTMM), the Open Web Application Security Project (OWASP), U.S. National Security Agency (NSA), and ISO 27001 Information Security Standard. The following application security attack vectors are tested during this exercise:


web application security testing

Solution Delivery

iViZ Security provides on-demand delivery for its over-the-Internet testing solution. The test reports and remediation recommendations are accessible anytime on the on demand application security management portal.

application security assessment

Delivery Features of Application Testing

  • Self-Service registration and maintenance of your hosts & applications using iViZ Security on-demand portal.
  • Test scheduling at your convenience.
  • Automatic test launch based on your schedule directly and remotely from iViZ Security SOC (Security Operation Center).
  • Email alerts to keep you updated on test progress.
  • Generation of comprehensive report based on automated testing coupled with expert validation on the tests to provide in-depth and comprehensive coverage.
  • Anytime access to vulnerability test results & remediation reports on iViZ Security on-demand portal.

What are the features?

Reduce Cost, Time & Effort Using On-Demand Platform

 

iViZ Security's unique on demand delivery platform and architecture is built to provide SaaS (Software as a Service) experience to our customers. On demand delivery significantly reduces the time and cost of conducting a conventional web application security testing effort. Customers can conduct regular Application Penetration Testing using this platform. The advantages of using a hosted solution are:

  • No Installation Overheads
  • No Software/Hardware Expenses
  • No Maintenance: 100% Remotely Managed.
  • Subscription Based Cost Effective Solution.
The above unique features reduce cost, time & effort required on your side as well as significantly enhances your ability to proactively manage your security posture.


Comprehensive & Accurate Testing.

 

iViZ Security's solution has a comprehensive application security vulnerability database. It performs vulnerability detection by simulating hacker attacks such as Cross-Site Scripting; HTTP Response Splitting; Parameter Tampering; Hidden Field Manipulation; Backdoors/Debug Options; Stealth Commanding; Forceful Browsing; Application Buffer Overflow; Cookie Poisoning; Third-Party Misconfiguration; Known Vulnerabilities; HTTP Attacks; SQL Injections; Suspicious Content; XML/SOAP Tests; Content Spoofing; LDAP Injection; XPath Injection; Session Fixation , automatic intelligent form filling.

Get Exhaustive and In-Depth Security Coverage With Expert Validated Testing

 

iViZ Security Automated application testing solution surpasses conventional manual testing process by finding out all possible attack paths, but some complex logical vulnerability require expert validation. To provide exhaustive & accurate web application testing coverage, iViZ Security incorporates expert validation of test results. This expert also separately carries out manual testing to explore security issues deeper into your network. A combination of automated testing further validated and scanned deeper by an expert provides in-depth and intelligent web application security test coverage and prioritized remediation recommendations.

Flexible Reporting For Effective Remediation

 

iViZ Security provides comprehensive reports designed for management, developers, QA engineers, system managers and security professionals, providing them full visibility & control of their security testing needs. The reports are customizable so that users have full control of content and layout.

Monitor Trends With Test Audit History

 

iViZ Security can store your previous test history data providing you with rich trend intelligence information to help manage your security posture effectively. Succeeding audits highlight the remediation status reported in earlier audits along with their severity levels. This helps keep track of security activities and find clues of possible attacks.

Who should conduct Application Security Assessment?

Web Application Security Assessment is highly recommended for organization that relies on :

  • Off-the-shelf products (operating systems, applications, databases, networking equipment etc.)
  • Bespoke development (dynamic web sites, in-house applications etc.)
  • Wireless (WIFI, Bluetooth, IR, GSM, RFID etc.) 

If your business is in any of the below industries , you should actively consider carrying out application testing.

  • Banking, finance and insurance
  • Information technology and consulting
  • Online Retail/ Ecommerce
  • Manufacturing
  • Telecommunications
  • Research and development
  • Government
  • Television/Media

Why choose iViZ Security?

  • World's first on-demand penetration testing company
  • Multi-Stage Attack Analysis detects all possible attack paths unlike non-comprehensive conventional test methods
  • Unique Patent-Pending security technology which addresses the gaps in the current day security testing methodology.
  • World class team and technology: World's Top 8 Innovative Technology (By Intel and UC Berkeley) and World's Top 6 Security Startups(London Business School, Homeland Security and Pentagon) (View iViZ Security Awards)

Free Web Application Security Testing Tools

Websites are getting more and more complex everyday and there are almost no static websites being built.
Security GuyToday, the simplest website has at least a contact or newsletter form and many are built with CMS systems or it may be using 3rd party plugins, services, etc. that we don't have an exact control over.

Even if the website is 100% hand-coded, we trust what we created and think that it is safe, it is still possible that a special character is not sanitized or we are not aware of a new attacking technique.

So, it is really hard to say "my website is safe" without running tests over it. The good part is there are powerful and free web application security testing tools which can help you to identify any possible holes.

Before presenting them, let's remind the classic: "something can be secure as only as its weakest link" (which also tells us that it is not always the application and can still be the server it is hosted or that easy to remember FTP password).

Netsparker Community Edition (Windows)

 

Netsparker Community Edition

This is the free-community edition of the powerful Netsparker which still comes with a bunch of features and also false-positive-free.

The application can detect SQL Injection + cross-site scripting issues.
Once a scan is complete, it displays the solutions besides the issues and enables you to see the browser view and HTTP request/response.

Websecurify (Windows, Linux, Mac OS X)

 

Websecurify
Websecurify is a very easy-to-use and open source tool which automatically identifies web application vulnerabilities by using advanced discovery and fuzzing technologies.

It can create simple reports (that can be exported into multiple formats) once ran.
The tool is also multilingual and extensible with the add-on support.

 

Wapiti (Windows, Linux, Mac OS X)

 

Wapiti

Wapiti is an open source and web-based tool that scans the web pages of the deployed web applications, looking for scripts and forms where it can inject data.
It is built with Python and can detect:
  • File handling errors (Local and remote include/require, fopen, readfile…)
  • Database, XSS, LDAP and CRLF injections (HTTP response splitting, session fixation…)
  • Command execution detection (eval(), system(), passtru()…)

N-Stalker Free Version (Windows)

 

N-Stalker Free Version
The free edition performs restricted-yet-still-powerful set of web security assessment checks compared to the paid versions of the application.

It can check up to 100 web pages at once including web server and cross-site scripting checks.

 

skipfish (Windows, Linux, Mac OS X)

 

Skipfish

skipfish is a fully automated and active web application security reconnaissance tool.

It is lightweight and pretty fast (can perform 2000 requests/second).

The application has automatic learning capabilities, on-the-fly wordlist creation and form autocompletion.
skipfish comes with low false positive, differential security checks which are capable of spotting a range of subtle flaws, including blind injection vectors.

 

Scrawlr (Windows)

 

Scrawlr

Scrawlr is a free software for scanning SQL injection vulnerabilities on your web applications.
It is developed by HP Web Security Research Group in coordination with Microsoft Security Response Center.

Watcher (Windows)

 

Watcher

It is a plugin for Fiddler (the awesome HTTP debugging proxy) and works as a passive-analysis tool for HTTP-based web applications.

Watcher runs silently in the background and interact with the web-application to apply 30+ tests (where new ones can be added) while you browse.

It will identify issues like cross-domain form POSTs, dangerous context-switching between HTTP and HTTPS, etc.

x5s (Windows)

 

x5s

x5s is again a plugin for Fiddler just like Watcher which is designed to find encoding and character transformation issues that can lead to XSS vulnerability.

It simply tests user-controlled input using special characters like <, >, ', and reviews how the output encodes the special characters.

Exploit-Me (Windows, Linux, Mac OS X)

 

Exploit-Me

Rather than using a proxy like most of the security testing tools, Exploit-Me directly integrates into Firefox.

It is a set of 3 add-ons:
  • XSS-Me: for testing reflected XSS vulnerabilities
  • SQL Inject Me: for testing SQL injection vulnerabilities
  • Access-Me: for testing access vulnerabilities
They are all lightweight , work while you browse websites and simply inform you by adding extra styles to the objects with vulnerabilities

 

WebScarab (Windows, Linux, Mac OS X)

 

WebScarab
WebScarab is actually a proxy to sniff the HTTP(s) traffic and manipulate it.
However, it comes with features like "parameter fuzzer (for testing XSS and SQL injection vulnerabilities), or "CRLF injection (HTTP response splitting)" and more.

 

Acunetix Free Version (Windows)

 

Acunetix

This is the free and limited-featured version of a paid/pro product.
It performs a check on any website and identifies cross site scripting (XSS) vulnerabilities.

And, if you are looking to improve yourself in the area of web application security and need to play with an application legally, there is DVWA (damn vulnerable web app.) which is there for just this purpose.

How to Test Banking Applications

Banking applications are considered to be one of the most complex applications in today’s software development and testing industry. What makes Banking application so complex? What approach should be followed in order to test the complex workflows involved? In this article we will be highlighting different stages and techniques involved in testing Banking applications.

The characteristics of a Banking application are as follows:
  • Multi tier functionality to support thousands of concurrent user sessions
  • Large scale Integration , typically a banking application integrates with numerous other applications such as Bill Pay utility and Trading accounts
  • Complex Business workflows
  • Real Time and Batch processing
  • High rate of Transactions per seconds
  • Secure Transactions
  • Robust Reporting section to keep track of day to day transactions
  • Strong Auditing to troubleshoot customer issues
  • Massive storage system
  • Disaster Management.
The above listed ten points are the most important characteristics of a Banking application.
Banking applications have multiple tiers involved in performing an operation. For Example, a banking application may have:
  1. Web Server to interact with end users via Browser
  2. Middle Tier to validate the input and output for web server
  3. Data Base to store data and procedures
  4. Transaction Processor which could be a large capacity Mainframe or any other Legacy system to carry out Trillions of transactions per second.
If we talk about testing banking applications it requires an end to end testing methodology involving multiple software testing techniques to ensure:
  • Total  coverage of all banking workflows and Business Requirements
  • Functional aspect of the application
  • Security aspect of the application
  • Data Integrity
  • Concurrency
  • User Experience
Typical stages involved in testing Banking Applications are shown in below workflow which we will be discussing individually.

Testing Banking Applications

 

1) Requirement Gathering:

 

Requirement gathering phase involves documentation of requirements either as Functional Specifications or Use Cases. Requirements are gathered as per customer needs and documented by Banking Experts or Business Analyst. To write requirements on more than one subject experts are involved as banking itself has multiple sub domains and one full fledge banking application will be the integration of all. For Example: A banking application may have separate modules for Transfers, Credit Cards, Reports, Loan Accounts, Bill Payments, Trading Etc.

 

2) Requirement Review:

 

The deliverable of Requirement Gathering is reviewed by all the stakeholders such as QA Engineers, Development leads and Peer Business Analysts. They cross check that neither existing business workflows nor new workflows are violated.

 

3) Business Scenario Preparations: 

 

In this stage QA Engineers derive Business Scenarios from the requirement documents (Functions Specs or Use Cases); Business Scenarios are derived in such a way that all Business Requirements are covered. Business Scenarios are high level scenarios without any detailed steps, further these Business Scenarios are reviewed by Business Analyst to ensure all of Business Requirements are met and its easier for BAs to review high level scenarios than reviewing low level detailed Test Cases.

 

4) Functional Testing:

 

In this stage functional testing is performed and the usual software testing activities are performed such as:

Test Case Preparation:

In this stage Test Cases are derived from Business Scenarios, one Business Scenario leads to several positive test cases and negative test cases. Generally tools used during this stage are Microsoft Excel, Test Director or Quality Center.

Test Case Review: 

Reviews by peer QA Engineers

Test Case Execution:

Test Case Execution could be either manual or automatic involving tools like QC, QTP or any other.

5) Database Testing:

 

Banking Application involves complex transaction which are performed both at UI level and Database level, Therefore Database testing is as important as functional testing. Database in itself is an entirely separate layer hence it is carried out by database specialists and it uses techniques like
  • Data loading
  • Database Migration
  • Testing DB Schema and Data types
  • Rules Testing
  • Testing Stored Procedures and Functions
  • Testing Triggers
  • Data Integrity
  •  

6) Security Testing:

 

Security Testing is usually the last stage in the testing cycle as completing functional and non functional are entry criteria to commence Security testing. Security testing is one of the major stages in the entire Application testing cycle as this stage ensures that application complies with Federal and Industry standards. Security testing cycle makes sure the application does not have any web vulnerability which may expose sensitive data to an intruder or an attacker and complies with standards like OWASP.

In this stage the major task involves in the whole application scan which is carried out using tools like IBM Appscan or HP WebInspect (2 Most popular tools).

Once the Scan is complete the Scan Report is published out of which False Positives are filtered out and rest of the vulnerability are reported to Development team for fixing depending on the Severity.
Other Manual tools for Security Testing used are: Paros Proxy, Http Watch, Burp Suite, Fortify tools Etc.
Apart from the above stages there might be different stages involved like Integration Testing and Performance Testing.

In today’s scenario majority of Banking Projects are using: Agile/Scrum, RUP and Continuous Integration methodologies, and Tools packages like Microsoft’s VSTS and Rational Tools.

As we mentioned RUP above, RUP stands for Rational Unified Process, which is an iterative software development methodology introduced by IBM which comprises of four phases in which development and testing activities are carried out.

Four phases are:

i) Inception
ii) Collaboration
iii) Construction and
iv) Transition
RUP widely involves IBM Rational tools.

In this article we discussed how complex a Banking application could be and what are the typical phases involved in testing the application. Apart from that we also discussed current trends followed by IT industries including software development methodologies and tools.

Popular Posts

Recent Posts

Google Analytics