how we conduct security testing in realtime,for every
project we conduct security testig or not
Answer / js_sabharwal
No, we dont conduct security testing for every project. For
example , I am developing Software for Primary Rimes or
Small Game.. I dont need to perform security testing.
Security Testing depends on the Risk of you project.
For example, Airplane Software, Health Care Softwares,
Banking Domains ..etc
How do we conduct ?
There are several ways to perform it again entirely depends
on your project/product, methods for web security testing
can be :
- Check for session hijacking.
- Check for session time out.
- Check for cross site scripting
- SQL Injection
- Http/Https
- Attempt of breach should log in 'Server Logs'
- Cookies Testing - Accepting/rejecting, invalid, decrypting
- Unauthorized access
- Multiple user login at same time
..etc
| Is This Answer Correct ? | 15 Yes | 1 No |
aplitue questions will be based on wich type ?
What are the types of maintenance?
How do u go about testing of client server application
What is difference between Defect and Bug?
What's the difference between system testing and acceptance testing?
can anybody tell me "what is ur testing process in ur company" pls explain what is the process when v get a build?
Explain the defect life cycle.
How is testing affected by object-oriented designs?
what is web server ur using at ur current testing of web application.
What is the difference between quality assurance and quality control?
Genarally what we have to tell. If anybody asks in the interview. what are challenges u faced in the Project and what are the Risks u faced in the Project, Anybody can suggest it ......Thanks in Advance....
how do u know whether the particular project belong to client server or web -based?