Tag: security
Questions Related to security
-
Cross site request forgery
-
Cross site scripting
-
HTTP Response Splitting
-
SQL injection
-
Reset password functionality was invoked during the testing
-
Change password form was submitted by appscan
-
Somebody changed your password while the scan was running
-
This is a result of an SQL injection test by appscan
-
Admin/admin1
-
John/nAscar
-
John/n@sc1234r
-
John/nascar2
-
../../help/images/about.jpeg
-
-
d:/etc/host/pwd
-
document.title(“/admin/administration”);
-
User account compromised
-
Steal user sessions
-
Site defacement and complete take over of the application
-
Complete user account compromise
-
When a login sequence needs to be recorded
-
When a particular application flow needs to be recorded
-
When in session parameter needs to be defined
-
When you need to test only a part of your application
-
Custom
-
Industry Standard
-
Compliance
-
Delta Analysis
-
Somebody put those files there during the test
-
Appscan created those files
-
Third party domain was not excluded from the scan
-
It’s a result of cross site scripting attack
-
Ignore the page parameter
-
Track the page parameter
-
Set the redundant path limit to 1
-
Set the depth limit to 1
-
Difference between 2 tests
-
How appscan modified the original web application page
-
How appscan constructed the test http request
-
How appscan arrived at the threat classification