Difference between revisions of "OWASP Testing Guide v4 Table of Contents"

From OWASP
Jump to: navigation, search
(Added notes)
(38 intermediate revisions by 7 users not shown)
Line 7: Line 7:
 
http://www.owasp.org/index.php/OWASP_Testing_Project
 
http://www.owasp.org/index.php/OWASP_Testing_Project
  
'''Updated: 26th November 2012'''
+
'''Updated: 15th February 2013'''
  
 
[[ OWTGv4 Contributors list|'''Contributors List]]
 
[[ OWTGv4 Contributors list|'''Contributors List]]
Line 18: Line 18:
 
== Table of Contents ==
 
== Table of Contents ==
  
==[[Testing Guide Foreword|Foreword by OWASP Chair]]==  
+
==[[Testing Guide Foreword|Foreword by Eoin Keary]]==  
[To review--> OWASP Chair]
+
[To review--> Eoin Keary -> Done!!]
  
 
==[[Testing Guide Frontispiece |1. Frontispiece]]==  
 
==[[Testing Guide Frontispiece |1. Frontispiece]]==  
Line 66: Line 66:
  
  
[[Testing Information Gathering|'''4.2 Information Gathering ''']] [Andrew Muller]
+
[[Testing Information Gathering|'''4.2 Information Gathering ''']]
  
[[Testing for Web Server Fingerprint (OWASP-IG-010)|4.2.10 Testing for Web Server Fingerprint (OWASP-IG-010)]]
+
[[Testing: Search engine discovery/reconnaissance (OWASP-IG-002)|4.2.1 Conduct Search Engine Discovery and Reconnaissance for Information Leakage (OTG-INFO-001) ]] formerly "Search Engine Discovery/Reconnaissance (OWASP-IG-002)"
  
[[Testing: Spiders, Robots, and Crawlers (OWASP-IG-001)|4.2.1 Spiders, Robots and Crawlers (OWASP-IG-001)]] [Modify! rename to "Review Webserver Metafiles" - could also be considered a Configuration Management test]
+
[[Testing for Web Application Fingerprint (OWASP-IG-004)|4.2.2 Fingerprint Web Server (OTG-INFO-002) ]] formerly "Testing for Web Application Fingerprint (OWASP-IG-004)"
  
[[Testing for Application Discovery (OWASP-IG-005)|4.2.5 Application Discovery (OWASP-IG-005)]] [Modify! - rename to "Enumerate Applications on Webserver"]
+
[[Testing: Spiders, Robots, and Crawlers (OWASP-IG-001)|4.2.3 Review Webserver Metafiles for Information Leakage (OTG-INFO-003) ]] formerly "Spiders, Robots and Crawlers (OWASP-IG-001)"
  
[[Testing Review webpage comments and metadata(OWASP-IG-007)|4.2.7 Review webpage comments and metadata(OWASP-IG-007)]]  
+
[[Testing for Application Discovery (OWASP-IG-005)|4.2.4 Enumerate Applications on Webserver (OTG-INFO-004) ]] formerly "Application Discovery (OWASP-IG-005)"
  
[[Testing: Identify application entry points (OWASP-IG-003)|4.2.3 Identify application entry points (OWASP-IG-003)]]
+
[[Testing Review webpage comments and metadata(OWASP-IG-007)|4.2.5 Review Webpage Comments and Metadata for Information Leakage (OTG-INFO-005) ]] formerly "Review webpage comments and metadata(OWASP-IG-007)"
  
[[Testing Identify application exit/handover points (OWASP-IG-008)|4.2.8 Identify application exit/handover points (OWASP-IG-008)]]
+
[[Testing: Identify application entry points (OWASP-IG-003)|4.2.6 Identify application entry points (OTG-INFO-006) ]] formerly "Identify application entry points (OWASP-IG-003)"
  
[[Testing Map execution paths through application (OWASP-IG-009)|4.2.9 Map execution paths through application (OWASP-IG-009)]]
+
[[Testing Identify application exit/handover points (OWASP-IG-008)|4.2.7 Identify application exit/handover points (OTG-INFO-007) ]] formerly "Identify application exit/handover points (OWASP-IG-008)"
  
[[Testing for Web Application Fingerprint (OWASP-IG-004)|4.2.4 Testing for Web Application Fingerprint (OWASP-IG-004)]]
+
[[Testing Map execution paths through application (OWASP-IG-009)|4.2.8 Map execution paths through application (OTG-INFO-008)]] formerly "Map execution paths through application (OWASP-IG-009)"
  
[[Testing for Error Code (OWASP-IG-006)|4.2.6 Analysis of Error Codes (OWASP-IG-006)]]
+
[[Testing for Web Application Fingerprint (OWASP-IG-010)|4.2.9 Fingerprint Web Application Framework (OTG-INFO-009) ]] formerly "Testing for Web Application Fingerprint (OWASP-IG-010)"
  
[[Testing: Search engine discovery/reconnaissance (OWASP-IG-002)|4.2.2 Search Engine Discovery/Reconnaissance (OWASP-IG-002)]]
+
[[Testing for Web Application (OTG-INFO-011)|4.2.10 Fingerprint Web Application (OTG-INFO-010) ]] formerly "Testing for Web Application Fingerprint (OWASP-IG-010)"
  
 +
[[Map Network and Application Architecture (OTG-INFO-012)|4.2.11 Map Network and Application Architecture (OTG-INFO-011) ]] formerly "Testing for Infrastructure Configuration Management Testing weakness (OWASP-CM-001)"
  
  
 
[[Testing for configuration management|'''4.3 Configuration and Deploy Management Testing ''']]
 
[[Testing for configuration management|'''4.3 Configuration and Deploy Management Testing ''']]
  
[[Testing for infrastructure configuration management (OWASP-CM-003)|4.3.1 Testing for Infrastructure Configuration Management Testing weakness (OWASP-CM-001)]]
+
[[Testing for infrastructure configuration management (OWASP-CM-003)|4.3.1 Test Network/Infrastructure Configuration (OTG-CONFIG-001) ]] formerly "Testing for Infrastructure Configuration Management Testing weakness (OWASP-CM-001)"
  
[[Testing for application configuration management (OWASP-CM-004)|4.3.2 Testing for Application Configuration Management weakness (OWASP-CM-002)]]
+
[[Testing for application configuration management (OWASP-CM-004)|4.3.2 Test Application Platform Configuration (OTG-CONFIG-002 ]] formerly "Testing for Application Configuration Management weakness (OWASP-CM-002)"
  
[[Testing for file extensions handling  (OWASP-CM-005)|4.3.3 Testing for File Extensions Handling  (OWASP-CM-003)]]
+
[[Testing for file extensions handling  (OWASP-CM-005)|4.3.3 Test File Extensions Handling for Sensitive Information (OTG-CONFIG-003) ]] formerly "Testing for File Extensions Handling  (OWASP-CM-003)"
  
[[Testing for Old, Backup and Unreferenced Files (OWASP-CM-006)|4.3.4 Old, Backup and Unreferenced Files (OWASP-CM-004) ]]
+
[[Testing for Old, Backup and Unreferenced Files (OWASP-CM-006)|4.3.4 Review Old, Backup and Unreferenced Files for Sensitive Information (OTG-CONFIG-004) ]] formerly "Old, Backup and Unreferenced Files (OWASP-CM-004)"
  
[[Testing for Admin Interfaces  (OWASP-CM-007)|4.3.5 Infrastructure and Application Admin Interfaces  (OWASP-CM-005)]]
+
[[Testing for Admin Interfaces  (OWASP-CM-007)|4.3.5 Enumerate Infrastructure and Application Admin Interfaces (OTG-CONFIG-005) ]] formerly "Infrastructure and Application Admin Interfaces  (OWASP-CM-005)"
  
[[Testing for HTTP Methods and XST  (OWASP-CM-008)|4.3.6 Testing for Bad HTTP Methods (OWASP-CM-006)]][new - Abian Blome]
+
[[Testing for HTTP Methods and XST  (OWASP-CM-008)|4.3.6 Test HTTP Methods (OTG-CONFIG-006) ]] formerly "Testing for Bad HTTP Methods (OWASP-CM-006)"
  
> Informative Error Messages [MAT NOTE: in info gathering]<br>
+
[[Testing for Database credentials/connection strings available|4.3.7 Testing for Database credentials/connection strings available (OTG-CONFIG-007) ]] formerly "Testing for Database credentials/connection strings available (OWASP-CM-007)"
  
[[Testing for Database credentials/connection strings available|4.3.7 Testing for Database credentials/connection strings available (OWASP-CM-007)]]
+
[[Testing for Content Security Policy weakness|4.3.8 Test Content Security Policy (OTG-CONFIG-008) ]] formerly "Testing for Content Security Policy weakness (OWASP-CM-008)"
  
[[Testing for Content Security Policy weakness|4.3.8 Testing for Content Security Policy weakness (OWASP-CM-008)]][New! - Simone Onofri]
+
[[Testing for Missing HSTS header|4.3.9 Test HTTP Strict Transport Security (OTG-CONFIG-009) ]] formerly "Testing for Missing HSTS header (OWASP-CM-009)"
  
[[Testing for Missing HSTS header|4.3.9 Testing for Missing HSTS header (OWASP-CM-009)]][New! Juan Manuel Bahamonde ]
+
[[Testing for Frame Options|4.3.10 Test Frame Options (OTG-CONFIG-010) ]]
  
[[Testing for RIA policy files weakness|4.3.10 Testing for RIA policy files weakness (OWASP-CM-010)]] [New!]
+
[[Testing for RIA policy files weakness|4.3.11 Test RIA cross domain policy (OTG-CONFIG-011) ]] formerly "Testing for RIA policy files weakness (OWASP-CM-010)"
  
> Incorrect time[New! MAT NOTE: explain the test in detail please]
+
[[Testing for Content Type Options|4.3.12 Test Content Type Options (OTG-CONFIG-012) ]] new
  
> Unpatched components and libraries (e.g. JavaScript libraries)[New! NOTE: tu discuss it][Note: this can be covered inside OWASP-CM-001/OWASP-CM-002]
 
  
> Test data in production systems (and vice versa)[New! MAT NOTE: this is not a particular test that could find a vulnerability]<br>
+
[[Testing Identity Management|'''4.4 Identity Management Testing''']]
  
 +
[[Test Role Definitions (OTG-IDENT-001)|4.4.1 Test Role Definitions (OTG-IDENT-001)]] New
  
[[Testing for authentication|'''4.4 Authentication Testing ''']]  
+
[[Test User Registration Process (OTG-IDENT-002)|4.4.2 Test User Registration Process (OTG-IDENT-002)]] New
  
[[Testing for Credentials Transported over an Encrypted Channel (OWASP-AT-001)|4.4.1 Testing for Credentials Transported over an Encrypted Channel  (OWASP-AT-001)]] [Robert Winkel]
+
[[Test Account Provisioning Process (OTG-IDENT-003)|4.4.3 Test Account Provisioning Process (OTG-IDENT-003)]] New
  
[[Testing for User Enumeration and Guessable User Account (OWASP-AT-002)|4.4.2 Testing for User Enumeration and Guessable User Account (OWASP-AT-002)]] [Robert Winkel]
+
[[Testing for Account Enumeration and Guessable User Account (OWASP-AT-002)|4.4.4 Testing for Account Enumeration and Guessable User Account (OTG-IDENT-004) ]] formerly "Testing for Account Enumeration and Guessable User Account (OWASP-AT-002)"
  
[[Testing for default credentials (OWASP-AT-003)|4.4.3 Testing for default credentials (OWASP-AT-003)]]
+
[[Testing for Weak or unenforced username policy (OWASP-AT-009)| 4.4.5 Testing for Weak or unenforced username policy (OTG-IDENT-005)]] formerly "Testing for Weak or unenforced username policy (OWASP-AT-009)
  
[[Testing for Weak lock out mechanism (OWASP-AT-004)|4.4.4 Testing for Weak lock out mechanism (OWASP-AT-004)]] [New! - Robert Winkel]
+
[[Test Permissions of Guest/Training Accounts (OTG-IDENT-006)|4.4.6 Test Permissions of Guest/Training Accounts (OTG-IDENT-006)]] New
  
> Account lockout DoS [New! - Robert Winkel - we can put it in the 4.4.4]
+
[[Test Account Suspension/Resumption Process (OTG-IDENT-007)|4.4.7 Test Account Suspension/Resumption Process (OTG-IDENT-007)]] New
  
[[Testing for Bypassing Authentication Schema (OWASP-AT-005)|4.4.5 Testing for bypassing authentication schema (OWASP-AT-005)]]
+
[[Test User Deregistration Process (OTG-IDENT-008)|4.4.8 Test User Deregistration Process (OTG-IDENT-008)]] New
  
[[Testing for Vulnerable Remember Password (OWASP-AT-006)|4.4.6 Testing for vulnerable remember
+
[[Test Account Deregistration Process (OTG-IDENT-009)|4.4.9 Test Account Deregistration Process (OTG-IDENT-009)]] New
password functionality (OWASP-AT-006)]] [Robert Winkel]
+
  
[[Testing for Browser cache weakness (OWASP-AT-007)|4.4.7 Testing for Browser cache weakness (OWASP-AT-007)]] [New! - Abian Blome]
 
  
[[Testing for Weak password policy (OWASP-AT-008)|4.4.8 Testing for Weak password policy (OWASP-AT-008)]] [New! - Robert Winkel]
 
  
[[Testing for Weak or unenforced username policy (OWASP-AT-009)|4.4.9 Testing for Weak or unenforced username policy (OWASP-AT-009)]] [New! - Robert Winkel]
+
[[Testing for authentication|'''4.5 Authentication Testing ''']]  
  
> Weak security question/answer [New! - Robert Winkel - MAT Note: same as AT-006]<br>
+
[[Testing for Credentials Transported over an Encrypted Channel (OWASP-AT-001)|4.5.1 Testing for Credentials Transported over an Encrypted Channel  (OTG-AUTHN-001)]] formerly "Testing for Credentials Transported over an Encrypted Channel  (OWASP-AT-001)"
  
[[Testing for failure to restrict access to authenticated resource(OWASP-AT-010)|4.4.10 Testing for failure to restrict access to authenticated resource (OWASP-AT-010)]] [New! - This seems better suited to the Authorization test cases (Andrew Muller)]<br>
+
[[Testing for default credentials (OWASP-AT-003)|4.5.2 Testing for default credentials (OTG-AUTHN-002)]] formerly "Testing for default credentials (OWASP-AT-003)"
  
[[Testing for weak password change or reset functionalities (OWASP-AT-011)|4.4.11 Testing for weak password change or reset functionalities (OWASP-AT-011)]] [New! - Robert Winkel]<br>
+
[[Testing for Weak lock out mechanism (OWASP-AT-004)|4.5.3 Testing for Weak lock out mechanism (OTG-AUTHN-003)]] formerly "Testing for Weak lock out mechanism (OWASP-AT-004)"
  
[[Testing for Captcha (OWASP-AT-012)|4.4.12 Testing for CAPTCHA (OWASP-AT-012)]] [Note: Andrew Muller - CAPTCHA's objective is not authentication but to test humanness. This could be moved to Business Logic or the now deleted Denial of Service section]
+
[[Testing for Bypassing Authentication Schema (OWASP-AT-005)|4.5.4 Testing for bypassing authentication schema (OTG-AUTHN-004)]] formerly "Testing for bypassing authentication schema (OWASP-AT-005)"
  
> Weaker authentication in alternative channel (e.g. mobile app, IVR, help desk) [New!: MAT Note: to explain better the kind of test to perform please]<br>
+
[[Testing for Vulnerable Remember Password (OWASP-AT-006)|4.5.5 Test remember password functionality (OTG-AUTHN-005)]] formerly "Testing for vulnerable remember password functionality (OWASP-AT-006)"
  
 +
[[Testing for Browser cache weakness (OWASP-AT-007)|4.5.6 Testing for Browser cache weakness (OTG-AUTHN-006)]] formerly "Testing for Browser cache weakness (OWASP-AT-007)"
  
[[Testing for Session Management|'''4.5 Session Management Testing''']]  
+
[[Testing for Weak password policy (OWASP-AT-008)|4.5.7 Testing for Weak password policy (OTG-AUTHN-007)]] formerly "Testing for Weak password policy (OWASP-AT-008)"
  
[[Testing for Session_Management_Schema (OWASP-SM-001)|4.5.1 Testing for Bypassing Session Management Schema (OWASP-SM-001)]]
+
[[Testing for Weak security question/answer (OTG-AUTHN-008)|4.5.8 Testing for Weak security question/answer (OTG-AUTHN-008)]] New! - Robert Winkel
  
[[Testing for cookies attributes  (OWASP-SM-002)|4.5.2 Testing for Cookies attributes (Cookies are set not ‘HTTP Only’, ‘Secure’,  and no time validity) (OWASP-SM-002)]]
+
[[Testing for weak password change or reset functionalities (OWASP-AT-011)|4.5.9 Testing for weak password change or reset functionalities (OTG-AUTHN-009)]] formerly "Testing for weak password change or reset functionalities (OWASP-AT-011)"
  
[[Testing for Session Fixation  (OWASP-SM-003)|4.5.3 Testing for Session Fixation  (OWASP-SM-003)]]
+
[[Testing for Weaker authentication in alternative channel (OTG-AUTHN-010)|4.5.10 Testing for Weaker authentication in alternative channel (OTG-AUTHN-010)]] (e.g. mobile app, IVR, help desk)
  
[[Testing for Exposed Session Variables  (OWASP-SM-004)|4.5.4 Testing for Exposed Session Variables  (OWASP-SM-004)]]
 
  
[[Testing for CSRF  (OWASP-SM-005)|4.5.5 Testing for Cross Site Request Forgery (CSRF)  (OWASP-SM-005)]]
+
[[Testing for Authorization|'''4.6 Authorization Testing''']]  
  
> Weak Session Token (MAT NOTE included in 4.5.1)
+
[[Test Management of Account Permissions (OTG-AUTHZ-001)|4.6.1 Test Management of Account Permissions (OTG-AUTHZ-001)]] New
+
[[Testing for Session token not restricted properly (OWASP-SM-006)|4.5.6 Testing for Session token not restricted properly (such as domain or path not set properly) (OWASP-SM-006)]] [New! - Abian Blome]<br>
+
  
> Session passed over http (NOTE: included in SM-004) [New!] <br>
+
[[Testing for Path Traversal  (OWASP-AZ-001)|4.6.2 Testing Directory traversal/file include (OTG-AUTHZ-002)]] formerly "Testing Directory traversal/file include (OWASP-AZ-001)"
  
[[Testing for logout functionality (OWASP-SM-007)|4.5.7 Testing for logout functionality (OWASP-SM-007)]]
+
[[Testing for Bypassing Authorization Schema  (OWASP-AZ-002)|4.6.3 Testing for bypassing authorization schema (OTG-AUTHZ-003)]] formerly "Testing for bypassing authorization schema  (OWASP-AZ-002)"
  
>Session token not removed on server after logout [New!: NOTE included in the above test]<br>
+
[[Testing for Privilege escalation  (OWASP-AZ-003)|4.6.4 Testing for Privilege Escalation (OTG-AUTHZ-004)]] formerly "Testing for Privilege Escalation  (OWASP-AZ-003)"
  
> Logout function not properly implemented (NOTE:same above)<br>
+
[[Testing for Insecure Direct Object References (OWASP-AZ-004)|4.6.5 Testing for Insecure Direct Object References (OTG-AUTHZ-005)]] formerly "Testing for Insecure Direct Object References (OWASP-AZ-004)"
  
> Persistent session token [New! NOTE: this is not a vulnerability if session time out is correctly performed]<br>
+
[[Testing for Failure to Restrict access to authorized resource (OWASP-AZ-005)|4.6.6 Testing for Failure to Restrict access to authorized resource (OTG-AUTHZ-006)]] formerly "Testing for Failure to Restrict access to authorized resource (OWASP-AZ-005)"
  
[[Testing for Session puzzling (OWASP-SM-008)|4.5.8 Testing for Session puzzling (OWASP-SM-008)]] [New! - Abian Blome]
+
[[Test privileges of server components (OTG-AUTHZ-007)|4.6.7 Test privileges of server components (OTG-AUTHZ-007)]] (e.g. indexing service, reporting interface, file generator)
  
> Missing user-viewable log of authentication events [NOTE: needs more details: which test perform?]
+
[[Test enforcement of application entry points (OTG-AUTHZ-008)|4.6.8 Test enforcement of application entry points (OTG-AUTHZ-008)]] (including exposure of objects)
  
> Establishment of multiple sessions with same credentials [New! - Andrew Muller]
+
[[Testing for failure to restrict access to authenticated resource(OWASP-AT-010)|4.6.9 Testing for failure to restrict access to authenticated resource (OTG-AUTHZ-009)]] formerly "Testing for failure to restrict access to authenticated resource (OWASP-AT-010)"
  
  
[[Testing for Authorization|'''4.6 Authorization Testing''']]  
+
[[Testing for Session Management|'''4.7 Session Management Testing''']]
  
[[Testing for Path Traversal  (OWASP-AZ-001)|4.6.1 Testing Directory traversal/file include (OWASP-AZ-001) [Juan Galiana] ]]
+
[[Testing for Session_Management_Schema (OWASP-SM-001)|4.7.1 Testing for Bypassing Session Management Schema (OTG-SESS-001)]] formerly "Testing for Bypassing Session Management Schema (OWASP-SM-001)"
  
[[Testing for Bypassing Authorization Schema (OWASP-AZ-002)|4.6.2 Testing for bypassing authorization schema  (OWASP-AZ-002)]]
+
[[Testing for cookies attributes (OWASP-SM-002)|4.7.2 Testing for Cookies attributes (OTG-SESS-002)]] formerly "Testing for Cookies attributes (OWASP-SM-002)" (Cookies are set not ‘HTTP Only’, ‘Secure’,  and no time validity)
  
[[Testing for Privilege escalation (OWASP-AZ-003)|4.6.3 Testing for Privilege Escalation  (OWASP-AZ-003) [Irene Abezgauz]]]
+
[[Testing for Session Fixation (OWASP-SM-003)|4.7.3 Testing for Session Fixation (OTG-SESS-003)]] formerly "Testing for Session Fixation  (OWASP-SM-003)"
  
[[Testing for Insecure Direct Object References (OWASP-AZ-004)|4.6.4 Testing for Insecure Direct Object References (OWASP-AZ-004) [Irene Abezgauz] ]]
+
[[Testing for Exposed Session Variables  (OWASP-SM-004)|4.7.4 Testing for Exposed Session Variables (OTG-SESS-004)]] formerly "Testing for Exposed Session Variables (OWASP-SM-004)"
  
[[Testing for Failure to Restrict access to authorized resource (OWASP-AZ-005)|4.6.5 Testing for Failure to Restrict access to authorized resource (OWASP-AZ-005) [New!] ]]
+
[[Testing for CSRF  (OWASP-SM-005)|4.7.5 Testing for Cross Site Request Forgery (CSRF) (OTG-SESS-005)]] formerly "Testing for Cross Site Request Forgery (CSRF) (OWASP-SM-005)"
  
> Server component has excessive privileges (e.g. indexing service, reporting interface, file generator)[New!]<br>
+
[[Test Session Token Strength (OTG-SESS-006)|4.7.6 Test Session Token Strength (OTG-SESS-006)]]
> Lack of enforcement of application entry points (including exposure of objects)[New!]<br>
+
 +
[[Testing for logout functionality (OWASP-SM-007)|4.7.7 Testing for logout functionality (OTG-SESS-007)]] formerly "Testing for logout functionality (OWASP-SM-007)"
  
 +
[[Testing for Session puzzling (OWASP-SM-008)|4.7.8 Testing for Session puzzling (OWASP-SM-008)]]
  
[[Testing for business logic  (OWASP-BL-001)|'''4.7 Business Logic Testing  (OWASP-BL-001)''']] [To review--> contributor here]
+
[[Test Session Timeout (OTG-SESS-008)|4.7.8 Test Session Timeout (OTG-SESS-008)]]
Business Logic<br>
+
  
Business logic data validation[New!] NOTE MAT: to discuss this section<br>
+
[[Test multiple concurrent sessions (OTG-SESS-009)|4.7.9 Test multiple concurrent sessions (OTG-SESS-009)]]
Ability to forge requests[New!]<br>
+
Lack of integrity checks (e.g. overwriting updates) [New!]<br>
+
Lack of tamper evidence[New!]<br>
+
Use of untrusted time source[New!]<br>
+
Lack of limits to excessive rate (speed) of use[New!]<br>
+
Lack of limits to size of request[New!]<br>
+
Lack of limit to number of times a function can be used[New!]<br>
+
Bypass of correct sequence[New!]<br>
+
Missing user-viewable log of activity[New!]<br>
+
Self-hosted payment cardholder data processing[New!]<br>
+
Lack of security incident reporting information[New!]<br>
+
Defenses against application mis-use[New!]<br>
+
  
  
 
[[Testing for Data Validation|'''4.8 Data Validation Testing''']]  
 
[[Testing for Data Validation|'''4.8 Data Validation Testing''']]  
  
[[Testing for Reflected Cross site scripting (OWASP-DV-001) |4.8.1 Testing for Reflected Cross Site Scripting (OWASP-DV-001) ]]
+
[[Testing for Reflected Cross site scripting (OWASP-DV-001) |4.8.1 Testing for Reflected Cross Site Scripting (OTG-INPVAL-001)]] formerly "Testing for Reflected Cross Site Scripting (OWASP-DV-001)"
  
[[Testing for Stored Cross site scripting (OWASP-DV-002) |4.8.2 Testing for Stored Cross Site Scripting (OWASP-DV-002) ]]
+
[[Testing for Stored Cross site scripting (OWASP-DV-002) |4.8.2 Testing for Stored Cross Site Scripting (OTG-INPVAL-002)]] formerly "Testing for Stored Cross Site Scripting (OWASP-DV-002)"
  
[[Testing for HTTP Verb Tampering (OWASP-DV-003)|4.8.3 Testing for HTTP Verb Tampering   [Brad Causey] ]]
+
[[Testing for HTTP Verb Tampering (OWASP-DV-003)|4.8.3 Testing for HTTP Verb Tampering (OTG-INPVAL-003)]] formerly "Testing for HTTP Verb Tampering (OWASP-DV-003)"
  
[[Testing for HTTP Parameter pollution (OWASP-DV-004)|4.8.4 Testing for HTTP Parameter pollution [Luca Carettoni, Stefano Di Paola, Brad Causey] ]]
+
[[Testing for HTTP Parameter pollution (OWASP-DV-004)|4.8.4 Testing for HTTP Parameter pollution (OTG-INPVAL-004) ]] formerly "Testing for HTTP Parameter pollution (OWASP-DV-004)"
  
[[Testing for Unvalidated Redirects and Forwards (OWASP-DV-004)|4.8.5 Testing for Unvalidated Redirects and Forwards [Brad Causey] ]]
+
[[Testing for Unvalidated Redirects and Forwards (OWASP-DV-004)|4.8.5 Testing for Unvalidated Redirects and Forwards (OTG-INPVAL-005) ]] formerly "Testing for Unvalidated Redirects and Forwards (OWASP-DV-004)"
  
[[Testing for SQL Injection (OWASP-DV-005)| 4.8.5 Testing for SQL Injection (OWASP-DV-005) [Ismael Gonçalves](Ismael NOTE: ready to be reviewed)]]
+
[[Testing for SQL Injection (OWASP-DV-005)| 4.8.6 Testing for SQL Injection (OTG-INPVAL-006)]] formerly "Testing for SQL Injection (OWASP-DV-005)" '''Ready to be reviewed'''
  
[[Testing for Oracle|4.8.5.1 Oracle Testing]]
+
[[Testing for Oracle|4.8.6.1 Oracle Testing]]
  
[[Testing for MySQL|4.8.5.2 MySQL Testing [Ismael Gonçalves]]]
+
[[Testing for MySQL|4.8.6.2 MySQL Testing [Ismael Gonçalves]]]
  
[[Testing for SQL Server|4.8.5.3 SQL Server Testing]]
+
[[Testing for SQL Server|4.8.6.3 SQL Server Testing]]
  
[[Testing for MS Access |4.8.5.4 MS Access Testing]]
+
[[OWASP_Backend_Security_Project_Testing_PostgreSQL|4.8.6.4 Testing PostgreSQL (from OWASP BSP) ]]
  
[[Testing for NoSQL injection|4.8.5.5 Testing for NoSQL injection [New!]]]
+
[[Testing for MS Access |4.8.6.5 MS Access Testing]]
  
[[OWASP_Backend_Security_Project_Testing_PostgreSQL|4.8.5.5 Testing PostgreSQL (from OWASP BSP) ]]
+
[[Testing for NoSQL injection|4.8.6.6 Testing for NoSQL injection [New!]]]
  
[[Testing for LDAP Injection  (OWASP-DV-006)|4.8.6 Testing for LDAP Injection  (OWASP-DV-006)]]
+
[[Testing for LDAP Injection  (OWASP-DV-006)|4.8.7 Testing for LDAP Injection  (OTG-INPVAL-007)]] formerly "Testing for LDAP Injection  (OWASP-DV-006)"
  
[[Testing for ORM Injection  (OWASP-DV-007)|4.8.7 Testing for ORM Injection  (OWASP-DV-007)]]
+
[[Testing for ORM Injection  (OWASP-DV-007)|4.8.8 Testing for ORM Injection  (OTG-INPVAL-008)]] formerly "Testing for ORM Injection  (OWASP-DV-007)"
  
[[Testing for XML Injection (OWASP-DV-008)|4.8.8 Testing for XML Injection (OWASP-DV-008)]]
+
[[Testing for XML Injection (OWASP-DV-008)|4.8.9 Testing for XML Injection (OTG-INPVAL-009)]] formerly "Testing for XML Injection (OWASP-DV-008)"
 +
 
 +
[[Testing for SSI Injection  (OWASP-DV-009)|4.8.10 Testing for SSI Injection  (OTG-INPVAL-010)]] formerly "Testing for SSI Injection  (OWASP-DV-009)"
 +
 
 +
[[Testing for XPath Injection  (OWASP-DV-010)|4.8.11 Testing for XPath Injection  (OTG-INPVAL-011)]] formerly "Testing for XPath Injection  (OWASP-DV-010)"
 +
 
 +
[[Testing for IMAP/SMTP Injection  (OWASP-DV-011)|4.8.12 IMAP/SMTP Injection  (OTG-INPVAL-012)]] formerly "IMAP/SMTP Injection  (OWASP-DV-011)"
 +
 
 +
[[Testing for Code Injection  (OWASP-DV-012)|4.8.13 Testing for Code Injection  (OTG-INPVAL-013)]] formerly "Testing for Code Injection  (OWASP-DV-012)"
 +
 
 +
[[Testing for Local File Inclusion|4.8.13.1 Testing for Local File Inclusion]]
 +
 
 +
[[Testing for Remote File Inclusion|4.8.13.2 Testing for Remote File Inclusion]]
 +
 
 +
[[Testing for Command Injection  (OWASP-DV-013)|4.8.14 Testing for Command Injection  (OTG-INPVAL-014)]] formerly "Testing for Command Injection  (OWASP-DV-013)"
 +
 
 +
[[Testing for Buffer Overflow (OWASP-DV-014)|4.8.15 Testing for Buffer overflow (OTG-INPVAL-015)]] formerly "Testing for Buffer overflow (OWASP-DV-014)"
 +
 
 +
[[Testing for Heap Overflow|4.8.15.1 Testing for Heap overflow]]
 +
 
 +
[[Testing for Stack Overflow|4.8.15.2 Testing for Stack overflow]]
 +
 
 +
[[Testing for Format String|4.8.15.3 Testing for Format string]]
 +
 
 +
[[Testing for Incubated Vulnerability (OWASP-DV-015)|4.8.16 Testing for incubated vulnerabilities (OTG-INPVAL-016)]] formerly "Testing for incubated vulnerabilities (OWASP-DV-015)"
 +
 
 +
[[Testing for HTTP Splitting/Smuggling  (OWASP-DV-016)|4.8.17 Testing for HTTP Splitting/Smuggling  (OTG-INPVAL-017) ]] formerly "Testing for HTTP Splitting/Smuggling  (OWASP-DV-016)"
 +
 
 +
 
 +
 
 +
[[Error Handling|'''4.9 Error Handling''']]
 +
 
 +
[[Testing for Error Code (OWASP-IG-006)|4.9.9 Analysis of Error Codes (OTG-ERR-001)]] formerly "Analysis of Error Codes (OWASP-IG-006)"
 +
 
 +
 
 +
[[Cryptography|'''4.10 Cryptography''']]
 +
 
 +
[[Testing for Insecure encryption usage (OWASP-EN-001)| 4.10.1  Testing for Insecure encryption usage (OTG-CRYPST-001)]] formerly "Testing for Insecure encryption usage (OWASP-EN-001)"
 +
 
 +
[[Testing for Weak SSL/TSL Ciphers, Insufficient Transport Layer Protection (OWASP-EN-002)| 4.10.2 Testing for Weak SSL/TSL Ciphers, Insufficient Transport Layer Protection (OTG-CRYPST-002)]] formerly "Testing for Weak SSL/TSL Ciphers, Insufficient Transport Layer Protection (OWASP-EN-002)"
 +
 
 +
[[Testing for Padding Oracle (OWASP-EN-003)| 4.10.3 Testing for Padding Oracle (OTG-CRYPST-003)]] formerly "Testing for Padding Oracle (OWASP-EN-003)"
 +
 
 +
[[Testing for Cacheable HTTPS Response (OTG-CRYPST-004)| 4.10.4 Testing for Cacheable HTTPS Response (OTG-CRYPST-004)]]
 +
 
 +
[[Test Cache Directives (OTG-CRYPST-005)|4.10.5 Test Cache Directives (OTG-CRYPST-005)]]
 +
 
 +
[[Testing for Insecure Cryptographic Storage (OTG-CRYPST-006)|4.10.6 Testing for Insecure Cryptographic Storage (OTG-CRYPST-006)]]
 +
 
 +
[[Testing for Sensitive information sent via unencrypted channels (OTG-CRYPST-007)|4.10.7 Testing for Sensitive information sent via unencrypted channels (OTG-CRYPST-007)]]
 +
 
 +
[[Test Cryptographic Key Management (OTG-CRYPST-008)|4.10.8 Test Cryptographic Key Management (OTG-CRYPST-008)]]
 +
 
 +
 
 +
[[Logging|'''4.11 Logging''']] Not convinced Logging should be included as it requires access to logs to test
 +
 
 +
[[Test time synchronisation (OTG-LOG-001)|4.11.1 Test time synchronisation (OTG-LOG-001) ]] formerly "Incorrect time"
 +
 
 +
[[Test user-viewable log of authentication events (OTG-LOG-002)|4.11.2 Test user-viewable log of authentication events (OTG-LOG-002)]]
 +
 
 +
 
 +
[[Testing for business logic  (OWASP-BL-001)|'''4.12 Business Logic Testing  (OWASP-BL-001)''']] [To review--> David Fern]
 +
Business Logic<br>
  
[[Testing for SSI Injection  (OWASP-DV-009)|4.8.9 Testing for SSI Injection  (OWASP-DV-009)]]
+
[[Test business logic data validation (OTG-BUSLOGIC-001)|4.12.1 Test business logic data validation (OTG-BUSLOGIC-001)]] [New!] NOTE MAT: to discuss this section
  
[[Testing for XPath Injection  (OWASP-DV-010)|4.8.10 Testing for XPath Injection  (OWASP-DV-010)]]
+
[[Test Ability to forge requests (OTG-BUSLOGIC-002)|4.12.2 Test Ability to forge requests (OTG-BUSLOGIC-002)]] [New!]
  
[[Testing for IMAP/SMTP Injection  (OWASP-DV-011)|4.8.11 IMAP/SMTP Injection  (OWASP-DV-011)]]
+
[[Test integrity checks (OTG-BUSLOGIC-003)|4.12.3 Test integrity checks (OTG-BUSLOGIC-003)]] (e.g. overwriting updates) [New!]
  
[[Testing for Code Injection  (OWASP-DV-012)|4.8.12 Testing for Code Injection  (OWASP-DV-012)]]
+
[[Test tamper evidence (OTG-BUSLOGIC-004)|4.12.4 Test tamper evidence (OTG-BUSLOGIC-004)]] [New!]
  
[[Testing for Command Injection  (OWASP-DV-013)|4.8.13 Testing for Command Injection  (OWASP-DV-013) [Juan Galiana]]]
+
[[Test excessive rate (speed) of use limits (OTG-BUSLOGIC-005)|4.12.5 Test excessive rate (speed) of use limits (OTG-BUSLOGIC-005)]] [New!]
  
[[Testing for Buffer Overflow (OWASP-DV-014)|4.8.14 Testing for Buffer overflow (OWASP-DV-014)]]
+
[[Test size of request limits (OTG-BUSLOGIC-006)|4.12.6 Test size of request limits (OTG-BUSLOGIC-006)]] [New!]
  
[[Testing for Heap Overflow|4.8.14.1 Testing for Heap overflow]]
+
[[Test number of times a function can be used limits (OTG-BUSLOGIC-007)|4.12.7 Test number of times a function can be used limits (OTG-BUSLOGIC-002)]] [New!]
  
[[Testing for Stack Overflow|4.8.14.2 Testing for Stack overflow]]
+
[[Test bypass of correct sequence (OTG-BUSLOGIC-008)|4.12.8 Test bypass of correct sequence (OTG-BUSLOGIC-008)]] [New!]
  
[[Testing for Format String|4.8.14.3 Testing for Format string]]
+
[[Test self-hosted payment cardholder data processing (OTG-BUSLOGIC-009)|4.12.9 Test self-hosted payment cardholder data processing (OTG-BUSLOGIC-009)]] [New!]
  
[[Testing for Incubated Vulnerability (OWASP-DV-015)|4.8.15 Testing for incubated vulnerabilities (OWASP-DV-015)]]
+
[[Test security incident reporting information (OTG-BUSLOGIC-010)|4.12.10 Test security incident reporting information (OTG-BUSLOGIC-010)]] [New!]
  
[[Testing for HTTP Splitting/Smuggling  (OWASP-DV-016)|4.8.16 Testing for HTTP Splitting/Smuggling  (OWASP-DV-016) [Juan Galiana] ]]
+
[[Test defenses against application mis-use (OTG-BUSLOGIC-011)|4.12.11 Test defenses against application mis-use (OTG-BUSLOGIC-011)]] [New!]
  
> Regular expression DoS[New!] note: to understand better<br>
 
  
> XML DoS [New! - Andrew Muller]
 
  
 +
[[Denial of Service|'''4.13 Denial of Service''']]
  
[[Data Encryption (New!)]]
+
[[Test Regular expression DoS (OTG-DOS-001)| 4.13.1 Test Regular expression DoS (OTG-DOS-001)]] [New!] note: to understand better<br>
  
[[Testing for Insecure encryption usage (OWASP-EN-001)| 4.9.1  Testing for Insecure encryption usage (OWASP-EN-001]]
+
[[Test XML DoS (OTG-DOS-002)| 4.13.2 Test XML DoS (OTG-DOS-002)]] [New! - Andrew Muller]
  
[[Testing for Weak SSL/TSL Ciphers, Insufficient Transport Layer Protection (OWASP-EN-002)| 4.9.2 Testing for Weak SSL/TSL Ciphers, Insufficient Transport Layer Protection (OWASP-EN-002)]]
+
[[Testing for Captcha (OWASP-AT-012)|4.13.3 Testing for CAPTCHA (OTG-DOS-003)]] formerly "Testing for CAPTCHA (OWASP-AT-012)"
  
[[Testing for Padding Oracle (OWASP-EN-003)| 4.9.3 Testing for Padding Oracle (OWASP-EN-003) [Giorgio Fedon]]]
 
  
> [[Testing for Cacheable HTTPS Response | x.x.3 Testing for Cacheable HTTPS Response<br>
 
Cache directives insecure<br>
 
> Testing for Insecure Cryptographic Storage [put in x.x.1]<br>
 
[[Testing for Sensitive information sent via unencrypted channels | x.x.4<br>
 
  
[[Web Service (XML Interpreter)|'''4.10 Web Service Testing''']] [Tom Eston]  
+
[[Web Service (XML Interpreter)|'''4.14 Web Service Testing''']] [Tom Eston]  
  
[[Scoping a Web Service Test (OWASP-WS-001)|4.10.1 Scoping a Web Service Test (OWASP-WS-001)]]
+
[[Scoping a Web Service Test (OWASP-WS-001)|4.14.1 Scoping a Web Service Test (OTG-WEBSVC-001)]] formerly "Scoping a Web Service Test (OWASP-WS-001)"
  
[[WS Information Gathering (OWASP-WS-002)|4.10.2 WS Information Gathering (OWASP-WS-002)]]
+
[[WS Information Gathering (OWASP-WS-002)|4.14.2 WS Information Gathering (OTG-WEBSVC-002)]] formerly "WS Information Gathering (OWASP-WS-002)"
  
[[WS Authentication Testing (OWASP-WS-003)|4.10.3 WS Authentication Testing (OWASP-WS-003)]]
+
[[WS Authentication Testing (OWASP-WS-003)|4.14.3 WS Authentication Testing (OTG-WEBSVC-003)]] formerly "WS Authentication Testing (OWASP-WS-003)"
  
[[WS Management Interface Testing (OWASP-WS-004)|4.10.4 WS Management Interface Testing (OWASP-WS-004)]]
+
[[WS Management Interface Testing (OWASP-WS-004)|4.14.4 WS Management Interface Testing (OTG-WEBSVC-004)]] formerly "WS Management Interface Testing (OWASP-WS-004)"
  
[[Weak XML Structure Testing (OWASP-WS-005)|4.10.5 Weak XML Structure Testing (OWASP-WS-005)]]
+
[[Weak XML Structure Testing (OWASP-WS-005)|4.14.5 Weak XML Structure Testing (OTG-WEBSVC-005)]] formerly "Weak XML Structure Testing (OWASP-WS-005)"
  
[[XML Content-Level Testing (OWASP-WS-006)|4.10.6 XML Content-Level Testing (OWASP-WS-006)]]
+
[[XML Content-Level Testing (OWASP-WS-006)|4.14.6 XML Content-Level Testing (OTG-WEBSVC-006)]] formerly "XML Content-Level Testing (OWASP-WS-006)"
  
[[WS HTTP GET Parameters/REST Testing (OWASP-WS-007)|4.10.7 WS HTTP GET Parameters/REST Testing (OWASP-WS-007)]]
+
[[WS HTTP GET Parameters/REST Testing (OWASP-WS-007)|4.14.7 WS HTTP GET Parameters/REST Testing (OTG-WEBSVC-007)]] formerly "WS HTTP GET Parameters/REST Testing (OWASP-WS-007)"
  
[[WS Naughty SOAP Attachment Testing (OWASP-WS-008)|4.10.8 WS Naughty SOAP Attachment Testing (OWASP-WS-008)]]
+
[[WS Naughty SOAP Attachment Testing (OWASP-WS-008)|4.14.8 WS Naughty SOAP Attachment Testing (OTG-WEBSVC-008)]] formerly "WS Naughty SOAP Attachment Testing (OWASP-WS-008)"
  
[[WS Replay/MiTM Testing (OWASP-WS-009)|4.10.9 WS Replay/MiTM Testing (OWASP-WS-009)]]
+
[[WS Replay/MiTM Testing (OWASP-WS-009)|4.14.9 WS Replay/MiTM Testing (OTG-WEBSVC-009)]] formerly "WS Replay/MiTM Testing (OWASP-WS-009)"
  
[[WS BEPL Testing (OWASP-WS-010)|4.10.10 WS BEPL Testing (OWASP-WS-010)]]
+
[[WS BEPL Testing (OWASP-WS-010)|4.14.10 WS BEPL Testing (OTG-WEBSVC-010)]] formerly "WS BEPL Testing (OWASP-WS-010)"
  
  
[[Client Side Testing|'''4.11 Client Side Testing''']] [New!]  
+
[[Client Side Testing|'''4.15 Client Side Testing''']] [New!]  
  
[[Testing for DOM-based Cross site scripting  (OWASP-DV-003)|4.11.1 Testing for DOM based Cross Site Scripting  (OWASP-CS-001) [Stefano Di Paola] ]]
+
[[Testing for DOM-based Cross site scripting  (OWASP-DV-003)|4.15.1 Testing for DOM based Cross Site Scripting  (OTG-CLIENT-001)]] formerly "Testing for DOM based Cross Site Scripting  (OWASP-CS-001)" [Stefano Di Paola]
  
[[Testing for HTML5 (OWASP CS-002)|4.11.2 Testing for HTML5 (OWASP CS-002) [Juan Galiana] ]]<br/>
+
[[Testing for HTML5 (OWASP CS-002)|4.15.2 Testing for HTML5 (OTG-CLIENT-002)]] formerly "Testing for HTML5 (OWASP CS-002)" [Juan Galiana]
  
[[Testing for Cross site flashing (OWASP-DV-004)|4.11.3 Testing for Cross Site Flashing  (OWASP-CS-003)]]
+
[[Testing for Cross site flashing (OWASP-DV-004)|4.15.3 Testing for Cross Site Flashing  (OTG-CLIENT-003)]] formerly "Testing for Cross Site Flashing  (OWASP-CS-003)"
  
[[Testing for Testing for ClickHijacking (OWASP-CS-004)|4.11.4 Testing for Testing for ClickHijacking (OWASP-CS-004) ]]<br>
+
[[Testing for Clickjacking (OWASP-CS-004)|4.15.4 Testing for Clickjacking (OTG-CLIENT-004)]] formerly "Testing for Clickjacking (OWASP-CS-004)" [Davide Danelon]  
  
  
Line 336: Line 377:
 
==[[Appendix A: Testing Tools |Appendix A: Testing Tools ]]==
 
==[[Appendix A: Testing Tools |Appendix A: Testing Tools ]]==
  
* Black Box Testing Tools [To review--> Amro. We need only tools for webapp testing]
+
* Black Box Testing Tools [To review--> Amro AlOlaqi]
  
 
==[[OWASP Testing Guide Appendix B: Suggested Reading | Appendix B: Suggested Reading]]==
 
==[[OWASP Testing Guide Appendix B: Suggested Reading | Appendix B: Suggested Reading]]==
Line 345: Line 386:
 
==[[OWASP Testing Guide Appendix C: Fuzz Vectors | Appendix C: Fuzz Vectors]]==
 
==[[OWASP Testing Guide Appendix C: Fuzz Vectors | Appendix C: Fuzz Vectors]]==
  
* Fuzz Categories [To review--> contributor here]
+
* Fuzz Categories [To review--> Amro AlOlaqi]
  
  
 
==[[OWASP Testing Guide Appendix D: Encoded Injection | Appendix D: Encoded Injection]]==
 
==[[OWASP Testing Guide Appendix D: Encoded Injection | Appendix D: Encoded Injection]]==
  
[To review--> contributor here]
+
[To review--> Amro AlOlaqi]
  
 
----
 
----

Revision as of 03:18, 18 June 2013


This is the DRAFT of the table of content of the New Testing Guide v4.

You can download the stable version v3 here

Back to the OWASP Testing Guide Project: http://www.owasp.org/index.php/OWASP_Testing_Project

Updated: 15th February 2013

Contributors List



The following is a DRAFT of the Toc based on the feedback already received.

Table of Contents

Foreword by Eoin Keary

[To review--> Eoin Keary -> Done!!]

1. Frontispiece

[To review--> Mat]

1.1 About the OWASP Testing Guide Project [To review--> Mat]

1.2 About The Open Web Application Security Project [To review--> ]


2. Introduction

2.1 The OWASP Testing Project

2.2 Principles of Testing

2.3 Testing Techniques Explained

2.4 Security requirements test derivation,functional and non functional test requirements, and test cases through use and misuse cases

2.5 Security test data analysis and reporting: root cause identification and business/role case test data reporting

3. The OWASP Testing Framework

3.1. Overview

3.2. Phase 1: Before Development Begins

3.3. Phase 2: During Definition and Design

3.4. Phase 3: During Development

3.5. Phase 4: During Deployment

3.6. Phase 5: Maintenance and Operations

3.7. A Typical SDLC Testing Workflow

4. Web Application Penetration Testing

4.1 Introduction and Objectives [To review--> Mat]

4.1.1 Testing Checklist [To review at the end of brainstorming --> Mat]


4.2 Information Gathering

4.2.1 Conduct Search Engine Discovery and Reconnaissance for Information Leakage (OTG-INFO-001) formerly "Search Engine Discovery/Reconnaissance (OWASP-IG-002)"

4.2.2 Fingerprint Web Server (OTG-INFO-002) formerly "Testing for Web Application Fingerprint (OWASP-IG-004)"

4.2.3 Review Webserver Metafiles for Information Leakage (OTG-INFO-003) formerly "Spiders, Robots and Crawlers (OWASP-IG-001)"

4.2.4 Enumerate Applications on Webserver (OTG-INFO-004) formerly "Application Discovery (OWASP-IG-005)"

4.2.5 Review Webpage Comments and Metadata for Information Leakage (OTG-INFO-005) formerly "Review webpage comments and metadata(OWASP-IG-007)"

4.2.6 Identify application entry points (OTG-INFO-006) formerly "Identify application entry points (OWASP-IG-003)"

4.2.7 Identify application exit/handover points (OTG-INFO-007) formerly "Identify application exit/handover points (OWASP-IG-008)"

4.2.8 Map execution paths through application (OTG-INFO-008) formerly "Map execution paths through application (OWASP-IG-009)"

4.2.9 Fingerprint Web Application Framework (OTG-INFO-009) formerly "Testing for Web Application Fingerprint (OWASP-IG-010)"

4.2.10 Fingerprint Web Application (OTG-INFO-010) formerly "Testing for Web Application Fingerprint (OWASP-IG-010)"

4.2.11 Map Network and Application Architecture (OTG-INFO-011) formerly "Testing for Infrastructure Configuration Management Testing weakness (OWASP-CM-001)"


4.3 Configuration and Deploy Management Testing

4.3.1 Test Network/Infrastructure Configuration (OTG-CONFIG-001) formerly "Testing for Infrastructure Configuration Management Testing weakness (OWASP-CM-001)"

4.3.2 Test Application Platform Configuration (OTG-CONFIG-002 formerly "Testing for Application Configuration Management weakness (OWASP-CM-002)"

4.3.3 Test File Extensions Handling for Sensitive Information (OTG-CONFIG-003) formerly "Testing for File Extensions Handling (OWASP-CM-003)"

4.3.4 Review Old, Backup and Unreferenced Files for Sensitive Information (OTG-CONFIG-004) formerly "Old, Backup and Unreferenced Files (OWASP-CM-004)"

4.3.5 Enumerate Infrastructure and Application Admin Interfaces (OTG-CONFIG-005) formerly "Infrastructure and Application Admin Interfaces (OWASP-CM-005)"

4.3.6 Test HTTP Methods (OTG-CONFIG-006) formerly "Testing for Bad HTTP Methods (OWASP-CM-006)"

4.3.7 Testing for Database credentials/connection strings available (OTG-CONFIG-007) formerly "Testing for Database credentials/connection strings available (OWASP-CM-007)"

4.3.8 Test Content Security Policy (OTG-CONFIG-008) formerly "Testing for Content Security Policy weakness (OWASP-CM-008)"

4.3.9 Test HTTP Strict Transport Security (OTG-CONFIG-009) formerly "Testing for Missing HSTS header (OWASP-CM-009)"

4.3.10 Test Frame Options (OTG-CONFIG-010)

4.3.11 Test RIA cross domain policy (OTG-CONFIG-011) formerly "Testing for RIA policy files weakness (OWASP-CM-010)"

4.3.12 Test Content Type Options (OTG-CONFIG-012) new


4.4 Identity Management Testing

4.4.1 Test Role Definitions (OTG-IDENT-001) New

4.4.2 Test User Registration Process (OTG-IDENT-002) New

4.4.3 Test Account Provisioning Process (OTG-IDENT-003) New

4.4.4 Testing for Account Enumeration and Guessable User Account (OTG-IDENT-004) formerly "Testing for Account Enumeration and Guessable User Account (OWASP-AT-002)"

4.4.5 Testing for Weak or unenforced username policy (OTG-IDENT-005) formerly "Testing for Weak or unenforced username policy (OWASP-AT-009)

4.4.6 Test Permissions of Guest/Training Accounts (OTG-IDENT-006) New

4.4.7 Test Account Suspension/Resumption Process (OTG-IDENT-007) New

4.4.8 Test User Deregistration Process (OTG-IDENT-008) New

4.4.9 Test Account Deregistration Process (OTG-IDENT-009) New


4.5 Authentication Testing

4.5.1 Testing for Credentials Transported over an Encrypted Channel (OTG-AUTHN-001) formerly "Testing for Credentials Transported over an Encrypted Channel (OWASP-AT-001)"

4.5.2 Testing for default credentials (OTG-AUTHN-002) formerly "Testing for default credentials (OWASP-AT-003)"

4.5.3 Testing for Weak lock out mechanism (OTG-AUTHN-003) formerly "Testing for Weak lock out mechanism (OWASP-AT-004)"

4.5.4 Testing for bypassing authentication schema (OTG-AUTHN-004) formerly "Testing for bypassing authentication schema (OWASP-AT-005)"

4.5.5 Test remember password functionality (OTG-AUTHN-005) formerly "Testing for vulnerable remember password functionality (OWASP-AT-006)"

4.5.6 Testing for Browser cache weakness (OTG-AUTHN-006) formerly "Testing for Browser cache weakness (OWASP-AT-007)"

4.5.7 Testing for Weak password policy (OTG-AUTHN-007) formerly "Testing for Weak password policy (OWASP-AT-008)"

4.5.8 Testing for Weak security question/answer (OTG-AUTHN-008) New! - Robert Winkel

4.5.9 Testing for weak password change or reset functionalities (OTG-AUTHN-009) formerly "Testing for weak password change or reset functionalities (OWASP-AT-011)"

4.5.10 Testing for Weaker authentication in alternative channel (OTG-AUTHN-010) (e.g. mobile app, IVR, help desk)


4.6 Authorization Testing

4.6.1 Test Management of Account Permissions (OTG-AUTHZ-001) New

4.6.2 Testing Directory traversal/file include (OTG-AUTHZ-002) formerly "Testing Directory traversal/file include (OWASP-AZ-001)"

4.6.3 Testing for bypassing authorization schema (OTG-AUTHZ-003) formerly "Testing for bypassing authorization schema (OWASP-AZ-002)"

4.6.4 Testing for Privilege Escalation (OTG-AUTHZ-004) formerly "Testing for Privilege Escalation (OWASP-AZ-003)"

4.6.5 Testing for Insecure Direct Object References (OTG-AUTHZ-005) formerly "Testing for Insecure Direct Object References (OWASP-AZ-004)"

4.6.6 Testing for Failure to Restrict access to authorized resource (OTG-AUTHZ-006) formerly "Testing for Failure to Restrict access to authorized resource (OWASP-AZ-005)"

4.6.7 Test privileges of server components (OTG-AUTHZ-007) (e.g. indexing service, reporting interface, file generator)

4.6.8 Test enforcement of application entry points (OTG-AUTHZ-008) (including exposure of objects)

4.6.9 Testing for failure to restrict access to authenticated resource (OTG-AUTHZ-009) formerly "Testing for failure to restrict access to authenticated resource (OWASP-AT-010)"


4.7 Session Management Testing

4.7.1 Testing for Bypassing Session Management Schema (OTG-SESS-001) formerly "Testing for Bypassing Session Management Schema (OWASP-SM-001)"

4.7.2 Testing for Cookies attributes (OTG-SESS-002) formerly "Testing for Cookies attributes (OWASP-SM-002)" (Cookies are set not ‘HTTP Only’, ‘Secure’, and no time validity)

4.7.3 Testing for Session Fixation (OTG-SESS-003) formerly "Testing for Session Fixation (OWASP-SM-003)"

4.7.4 Testing for Exposed Session Variables (OTG-SESS-004) formerly "Testing for Exposed Session Variables (OWASP-SM-004)"

4.7.5 Testing for Cross Site Request Forgery (CSRF) (OTG-SESS-005) formerly "Testing for Cross Site Request Forgery (CSRF) (OWASP-SM-005)"

4.7.6 Test Session Token Strength (OTG-SESS-006)

4.7.7 Testing for logout functionality (OTG-SESS-007) formerly "Testing for logout functionality (OWASP-SM-007)"

4.7.8 Testing for Session puzzling (OWASP-SM-008)

4.7.8 Test Session Timeout (OTG-SESS-008)

4.7.9 Test multiple concurrent sessions (OTG-SESS-009)


4.8 Data Validation Testing

4.8.1 Testing for Reflected Cross Site Scripting (OTG-INPVAL-001) formerly "Testing for Reflected Cross Site Scripting (OWASP-DV-001)"

4.8.2 Testing for Stored Cross Site Scripting (OTG-INPVAL-002) formerly "Testing for Stored Cross Site Scripting (OWASP-DV-002)"

4.8.3 Testing for HTTP Verb Tampering (OTG-INPVAL-003) formerly "Testing for HTTP Verb Tampering (OWASP-DV-003)"

4.8.4 Testing for HTTP Parameter pollution (OTG-INPVAL-004) formerly "Testing for HTTP Parameter pollution (OWASP-DV-004)"

4.8.5 Testing for Unvalidated Redirects and Forwards (OTG-INPVAL-005) formerly "Testing for Unvalidated Redirects and Forwards (OWASP-DV-004)"

4.8.6 Testing for SQL Injection (OTG-INPVAL-006) formerly "Testing for SQL Injection (OWASP-DV-005)" Ready to be reviewed

4.8.6.1 Oracle Testing

4.8.6.2 MySQL Testing [Ismael Gonçalves]

4.8.6.3 SQL Server Testing

4.8.6.4 Testing PostgreSQL (from OWASP BSP)

4.8.6.5 MS Access Testing

4.8.6.6 Testing for NoSQL injection [New!]

4.8.7 Testing for LDAP Injection (OTG-INPVAL-007) formerly "Testing for LDAP Injection (OWASP-DV-006)"

4.8.8 Testing for ORM Injection (OTG-INPVAL-008) formerly "Testing for ORM Injection (OWASP-DV-007)"

4.8.9 Testing for XML Injection (OTG-INPVAL-009) formerly "Testing for XML Injection (OWASP-DV-008)"

4.8.10 Testing for SSI Injection (OTG-INPVAL-010) formerly "Testing for SSI Injection (OWASP-DV-009)"

4.8.11 Testing for XPath Injection (OTG-INPVAL-011) formerly "Testing for XPath Injection (OWASP-DV-010)"

4.8.12 IMAP/SMTP Injection (OTG-INPVAL-012) formerly "IMAP/SMTP Injection (OWASP-DV-011)"

4.8.13 Testing for Code Injection (OTG-INPVAL-013) formerly "Testing for Code Injection (OWASP-DV-012)"

4.8.13.1 Testing for Local File Inclusion

4.8.13.2 Testing for Remote File Inclusion

4.8.14 Testing for Command Injection (OTG-INPVAL-014) formerly "Testing for Command Injection (OWASP-DV-013)"

4.8.15 Testing for Buffer overflow (OTG-INPVAL-015) formerly "Testing for Buffer overflow (OWASP-DV-014)"

4.8.15.1 Testing for Heap overflow

4.8.15.2 Testing for Stack overflow

4.8.15.3 Testing for Format string

4.8.16 Testing for incubated vulnerabilities (OTG-INPVAL-016) formerly "Testing for incubated vulnerabilities (OWASP-DV-015)"

4.8.17 Testing for HTTP Splitting/Smuggling (OTG-INPVAL-017) formerly "Testing for HTTP Splitting/Smuggling (OWASP-DV-016)"


4.9 Error Handling

4.9.9 Analysis of Error Codes (OTG-ERR-001) formerly "Analysis of Error Codes (OWASP-IG-006)"


4.10 Cryptography

4.10.1 Testing for Insecure encryption usage (OTG-CRYPST-001) formerly "Testing for Insecure encryption usage (OWASP-EN-001)"

4.10.2 Testing for Weak SSL/TSL Ciphers, Insufficient Transport Layer Protection (OTG-CRYPST-002) formerly "Testing for Weak SSL/TSL Ciphers, Insufficient Transport Layer Protection (OWASP-EN-002)"

4.10.3 Testing for Padding Oracle (OTG-CRYPST-003) formerly "Testing for Padding Oracle (OWASP-EN-003)"

4.10.4 Testing for Cacheable HTTPS Response (OTG-CRYPST-004)

4.10.5 Test Cache Directives (OTG-CRYPST-005)

4.10.6 Testing for Insecure Cryptographic Storage (OTG-CRYPST-006)

4.10.7 Testing for Sensitive information sent via unencrypted channels (OTG-CRYPST-007)

4.10.8 Test Cryptographic Key Management (OTG-CRYPST-008)


4.11 Logging Not convinced Logging should be included as it requires access to logs to test

4.11.1 Test time synchronisation (OTG-LOG-001) formerly "Incorrect time"

4.11.2 Test user-viewable log of authentication events (OTG-LOG-002)


4.12 Business Logic Testing (OWASP-BL-001) [To review--> David Fern] Business Logic

4.12.1 Test business logic data validation (OTG-BUSLOGIC-001) [New!] NOTE MAT: to discuss this section

4.12.2 Test Ability to forge requests (OTG-BUSLOGIC-002) [New!]

4.12.3 Test integrity checks (OTG-BUSLOGIC-003) (e.g. overwriting updates) [New!]

4.12.4 Test tamper evidence (OTG-BUSLOGIC-004) [New!]

4.12.5 Test excessive rate (speed) of use limits (OTG-BUSLOGIC-005) [New!]

4.12.6 Test size of request limits (OTG-BUSLOGIC-006) [New!]

4.12.7 Test number of times a function can be used limits (OTG-BUSLOGIC-002) [New!]

4.12.8 Test bypass of correct sequence (OTG-BUSLOGIC-008) [New!]

4.12.9 Test self-hosted payment cardholder data processing (OTG-BUSLOGIC-009) [New!]

4.12.10 Test security incident reporting information (OTG-BUSLOGIC-010) [New!]

4.12.11 Test defenses against application mis-use (OTG-BUSLOGIC-011) [New!]


4.13 Denial of Service

4.13.1 Test Regular expression DoS (OTG-DOS-001) [New!] note: to understand better

4.13.2 Test XML DoS (OTG-DOS-002) [New! - Andrew Muller]

4.13.3 Testing for CAPTCHA (OTG-DOS-003) formerly "Testing for CAPTCHA (OWASP-AT-012)"


4.14 Web Service Testing [Tom Eston]

4.14.1 Scoping a Web Service Test (OTG-WEBSVC-001) formerly "Scoping a Web Service Test (OWASP-WS-001)"

4.14.2 WS Information Gathering (OTG-WEBSVC-002) formerly "WS Information Gathering (OWASP-WS-002)"

4.14.3 WS Authentication Testing (OTG-WEBSVC-003) formerly "WS Authentication Testing (OWASP-WS-003)"

4.14.4 WS Management Interface Testing (OTG-WEBSVC-004) formerly "WS Management Interface Testing (OWASP-WS-004)"

4.14.5 Weak XML Structure Testing (OTG-WEBSVC-005) formerly "Weak XML Structure Testing (OWASP-WS-005)"

4.14.6 XML Content-Level Testing (OTG-WEBSVC-006) formerly "XML Content-Level Testing (OWASP-WS-006)"

4.14.7 WS HTTP GET Parameters/REST Testing (OTG-WEBSVC-007) formerly "WS HTTP GET Parameters/REST Testing (OWASP-WS-007)"

4.14.8 WS Naughty SOAP Attachment Testing (OTG-WEBSVC-008) formerly "WS Naughty SOAP Attachment Testing (OWASP-WS-008)"

4.14.9 WS Replay/MiTM Testing (OTG-WEBSVC-009) formerly "WS Replay/MiTM Testing (OWASP-WS-009)"

4.14.10 WS BEPL Testing (OTG-WEBSVC-010) formerly "WS BEPL Testing (OWASP-WS-010)"


4.15 Client Side Testing [New!]

4.15.1 Testing for DOM based Cross Site Scripting (OTG-CLIENT-001) formerly "Testing for DOM based Cross Site Scripting (OWASP-CS-001)" [Stefano Di Paola]

4.15.2 Testing for HTML5 (OTG-CLIENT-002) formerly "Testing for HTML5 (OWASP CS-002)" [Juan Galiana]

4.15.3 Testing for Cross Site Flashing (OTG-CLIENT-003) formerly "Testing for Cross Site Flashing (OWASP-CS-003)"

4.15.4 Testing for Clickjacking (OTG-CLIENT-004) formerly "Testing for Clickjacking (OWASP-CS-004)" [Davide Danelon]


5. Writing Reports: value the real risk

5.1 How to value the real risk [To review--> Amro AlOlaqi]

5.2 How to write the report of the testing [To review--> Amro AlOlaqi]

Appendix A: Testing Tools

  • Black Box Testing Tools [To review--> Amro AlOlaqi]

Appendix B: Suggested Reading

  • Whitepapers [To review--> David Fern]
  • Books [To review--> David Fern]
  • Useful Websites [To review--> David Fern]

Appendix C: Fuzz Vectors

  • Fuzz Categories [To review--> Amro AlOlaqi]


Appendix D: Encoded Injection

[To review--> Amro AlOlaqi]