Tuesday, April 27, 2010

Open source Tools for Web Application Testing using Manual vulnerability penetration testing.

Open source Tools for Web Application Testing using Manual vulnerability penetration testing.
Methodical approach to web application penetration testing to ensure we are effective, efficient, and repeatable. Our methodology goes well beyond looking for the OWASP Top Ten issues.
Discovery – We work with you to understand the business impact of various features, so that we can qualify and quantify the business risk of the vulnerabilities we find.
Assessment – To ensure that all important areas are tested and to ensure consistency and repeat¬ability, we use a common security frame.
    ->Authentication
    ->Authorization
    ->User management    Session management     
    ->Data validation, including all common attack • such as SQL Injection, Cross Site Scripting, Command     Injection, Client Side Validation
    ->Error handling and exception management
    ->Auditing and logging
Reporting and deliverable – At the end of the engagement, we produce a detailed, written report with an executive summary prioritizing findings and the impact on your business. Our individual technical findings all contain specific details and recommendations for mitigation.

1 comment: