Life as a Tester can be very intresting and Challenging. We just dont keep writing code or automation as our primary goal is certification, thus we always have to keep updating our skill sets. If your manager [Awesome techi earlier] asks you why it takes so much time, ask him to do it in the time given and promise to quit if he does :P
Thursday, September 11, 2008
Security Testing is quite a vast field. I had a different vision before I attended a training on Security, but the entire concept changed after the training. Visioning myself as a cool hacker (Just to note Hackers are people who want to improve Security by pointing flaws in code which have potential loopholes for crackers or hijackers to enter) after watching Die Hard 4, I had different opinion. I assumed it to be a pretty straight forward job for guys who are geeks. Alas hacking is not so simple, but extremely challenging and can be very frustrating at times.
[New] - Security Checklist and Report
Hacking is involved in 4 stages
1) Reconnaissance - To completely understand the application
2) Foot Printing Target - To create a sample application for Cracking
3) Discovering Vulnerabilities
4) hacking, Cracking or attacking.
Thus Security Testing also contains the same 4 steps except the last one. The last step would be replaced with
4) Providing Security Tips to avoid vulnerabilities
Hacking can happen due to these Major Reason
1) Weakness in Custom Application
2) Architectural Flaws
3) Flawed Design Configurations and Code
5 Classes of Code Vulnerability
1) Security Related Information
a) Weak or Non Standard Cryptography
b) Non Secure N/w Communications
c) Application Configuration Vulnerabilities
d) Access Control Vulnerabilities
i) Unprotected Database and File System Use
ii) Dynamic Code Vulnerabilities
iii) Native Code Loading
iv) Data Storage Vulnerabilities
v) Authentication Errors
Access to page through URL where no access is permitted by caching in Local M/C or Server
2) Input / Output Validation and Encoding Errors
a) SQL Injection
b) Cross Site Scripting – Unsuspecting Users to execute or access malicious code
i) Stored Attacks
ii) Reflected Attacks
Stealing Session and disclosure of information
Can be avoided by “HTML Entity Encoded”
c) OS Injection
d) Custom Cookie / Hidden Field Validation
3) Error Handling and logging Vulnerabilities
a) Insecure Error Handling
b) Insecure or Inadequate Logging
4) Insecure Components – Malicious Code
a) Unsafe Native Methods – Accessing System Resources Directly and not through Interfaces which pose threat id unsafe coding standards are followed
b) Unsupported Methods
5) Coding Errors
a) Buffer Overflow Vulnerabilities
b) Format String Vulnerabilities
c) Denial of Service Errors
d) Privilege Escalation Errors
e) Race Conditions
"The Path to a Secure Application: A Source Code Security Review Checklist"
Security in SAAS becomes of critical importance as then all details are now open to anybody over the internet. Thus the traditional methodology of speed, feature set and ease of use are not supplemented with Security and very soon Security will be of Highest importance.
The methodologies of Hacking are
1) Cross Site Scripting - 21% of hacking happens here
2) Injection Flaws - Traditional SQL injection
3) Uploading Malicious File
4) Insecure Direct Object Reference
5) Information Leakage - 73% of hacking happens here
6) Insecure Cryptography
7) Insecure Storage
8) Insecure Communication
9) Failure to restrict URL Access
10)Cross Site Request Forgery
11)Hidden form elements
Some Common Terminologies in the World of Security Testing
1) Phishing
2) Cross Site Scripting
3) SQL injection
4) Profiling
5) Same Origin Policy
Reasons for Hacking
1) For Fame to prove the world that you are the BEST
2) To Steal sensitive Information
3) To Deface a site, company
4) To plant Malicious Software for Gains
Failure are not to be Feared but faced - Indian and Western Thoughts
I was discussing with my wife about a small project on Library management. After 2 hours of discussion she was extremely excited about the future of the project and its prospect.
The next questioned I asked her “What if you get a job tomorrow, will you take the offer?”. She answered “Yes, of course”. Though the answer was what I was expecting, it startled me.
She was sure about the success of the project, yet she would prefer a job (which could be boring) to the fantastic existing project.
The reason is “India Culture to Western Education?”
Indians are GIVEN the Receipe to Succeed, but Western Educators TEACH on How to Overcome Failure – Give and Teach
Don’t we know that “Failure is the stepping stone of success”, yet our culture has only taught us to follow roads to success. If the road was the reciepe to Success, tested and proved, where comes the question of failure? We all succeed but since we don’t know how to handle failures we do never take “Road less travelled or Road never travelled”
Google was a failure College Project when explained to entrepreneurs, until Google owners themselves decided to become entrepreneurs. The rest is Future to answer.
Oracle was a project dropped by US Defense, yet Larry decided to complete the project, only to become the second Largest Player in IT industry.
We might explain this phenomenon to US booming economy. Larry and Sergey Brin were not multi millionaires to accomplish the task. The difference was the belief they had in product and the energy to overcome failure. My own Client had failed 4 times to succeed the fifth time.
Indian Family Binding to Western Independent attitude
Does not India have the economy today? I now earn fair enough to sustain the family and my wife can take all the risks. Yet she believes in earning now, because she needs to sustain a better life style for the Family and Future kids. Probably she might have taken the risk, if not for the family. Westerners can afford to take the risk, because the failure does not adversely affect the “Family”. Though this might sound logical this is not true. Why so, because..
Indians should be taking more risks as we have a family to support even if we fail. But our Culture has never taught us to work with failure and failures are feared. In fact Failures are considered to signs of demons and bad omen.
Mahatma Gandhiji himself might not have succeeded, if he had not had western influence within him. His methodology was a Road never travelled, yet he believed, and more important he knew how to overcome failures.
The moment Indians believe in themselves and are taught to overcome Failure by not fearing them but facing them, we are not far from making India a Super Power.