XSS or cross site scripting attack is a much familiar security threat in today’s cyber world and is taking a toll on the web sites and applications by breaking in to their security system.
What is Cross Site Scripting Attack?
- Cross site scripting attack is another attack categorized under the category of computer security vulnerabilities which are the most common and frequent among the web applications.
- These attacks are known for making the web application so vulnerable that the malicious outside attackers are able to inject the malicious client side scripts in to the web pages or applications that are later set for the view by the users who visit the page.
- Another nefarious purpose of these attacks is to incur the access controls like the same origin policy.
- The cross site scripting attacks account for almost 80 percent of all the security threats identified and documented in the year of 2007 till now by the Symantec.
- The cross site scripting technique for the good purpose is usually employed for curbing risk depending on the measure of the sensitivity of the data that is being processed by that particular web site or web page.
- Apart from this factor, another factor that makes it easy for the attacks to happen is the security mitigation as implemented by the owner of that web site.
- Cross site scripting attacks are employed by some people to create petty nuisance.
- This is nothing but the misuse of the vulnerability of the security system by the attackers for bypassing the security mechanisms on the client side which are usually implemented by the web browsers up on the web content on the web site.
- There are various ways through which the site can be attacked and accessed for injecting the malicious scripts in to them.
- Such ways or methods can provide the attacker an unauthorized and easy way to access all the sensitive content of the page, information of the user activity as stored by the web browser and session cookies etc.
- Cross site scripting attacks are a type of code injection attack and somewhat similar to the SQL injection attacks.
- Earlier the cross site scripting technique was seen as the loading of the third party application that had been attacked at an unrelated attack site while the execution of the java scripts took place in the context of security of the domain on target as created by the attacker.
- Eventually this cross site scripting attacks were carried out through different modes of the code injection using non java script vectors (like VBscript, flash, Java, ActiveX, HTML, SQL and so on).
- Cross site scripting attacks are a consequence of the cross site scripting vulnerabilities that have been under exploitation since the advent of 20th century.
So many famous social networking sites of today like my space, orkut, twitter, Facebook etc have witnessed these attacks in the past. With the advancement of the cross site scripting techniques, they have now successfully surpassed the vulnerabilities like buffer overflows reporting to be the most common security vulnerability. Even now around 60 percent of the total web sites have been sorted as vulnerable to the cross site scripting attacks.
As such there are no defined criteria for the classification of the XSS flaws, but according to the experts they are classified in to two categories:
1. Persistent XSS flaws
- Also known as stored XSS flaws and is the most destructive type.
- Occurs when the data which has been provided by the attacker is stored by the server.
2. Non persistent XSS flaws
- Also known as reflected XSS flaws and most common type.
- Occurs when data from a web client is used by server scripts for generating required pages without the sanitization of the queries.
Tuesday, March 13, 2012
Explain the concepts of Cross site scripting attacks?
Posted by
Sunflower
at
3/13/2012 01:50:00 PM
0
comments
Labels: Application, Attacker, attacks, Client, Client side scripting, Content, Control, Cross site scripting, Information, Injection, Security, Techniques, Test Scripts, Users, Web Applications, Websites
|
| Subscribe by Email |
|
Sunday, March 11, 2012
What is meant by content spoofing in detail?
Content spoofing is a rarely discussed topic and is much unheard by the many of us!
So let's evaluate the concepts of content spoofing in detail:
- Content spoofing has been categorized as an attack technique using which the attacker is able to inject a malicious code or payload in to the good content of a web site or a web application.
- This malicious payload or code is later thought of as being the legitimate content of that particular web site or web application which is a wrong interpretation.
- Content spoofing affects usually the web pages which have been built dynamically.
- Text only content spoofing is the technique in which the payload usually as text is passed in to the body of the web page or application in the form of a query string value.
- This approach usually takes effect on the pages of the web sites displaying some news entries and error pages.
- Such content is then later posted on the web site as its legitimate content.
- So when the users visit that particular link they perceive that the spoofed content is nothing but the legitimate content.
- In some cases it is possible that the pay load may exist on the web page for a longer time than estimated.
- Most of the web pages have been built dynamically with the sources from the HTML (hyper text mark up language).
- The attacker can easily change the content and when the particular web page is accessed by a browser, the location comes of the same domain as the user expected but the user does not come to know that the content is not legitimate instead it is shrouded one.
- As this is not enough to harm a web site, some attackers even manage to send malicious links to the users through emails and messages.
- In some cases the malicious links can be enforced up on the users following a cross site scripting attack.
- When the user clicks that link, he/ she visits the web page designed by the attacker with the malicious URL (uniform resource locator).
- The user will not come to know about this that he/ she is actually viewing am unauthentic web page.
- They will unknowingly believe that the spoofed content that they are viewing is purely authentic but this is not the case.
- Content spoofing does nothing but spoils the trust that the user has on the web site.
- The technique of content spoofing is being used like anything for the creation of fake web sites including fake login pages, press releases and defacement.
- Another point to be noted is that if you can fall victim to a cross site scripting attack, then the chances are that you may fall prey to content spoofing attacks as well.
- Content spoofing is a type of exploitation activity used by the hackers who have wrong intentions like presenting certain web pages to the user as if they are legitimate and not from an external source.
- This is somewhat similar to the SQL injection attacks. In both the cases the victims are defrauded like in phishing.
- Some attackers can even access the data base of a web application stored in a server and alter the contents.
- Content spoofing cannot be readily detected since there is large apparent difference between the actual and the spoofed content.
- The content spoofing carried out with the help of dynamic hyper text mark up language or DHTML is considered to be the most dangerous type since it can be used to form fake login pages.
- When any user inputs his sensitive data (can be a password, credit card number etc) in that page, the data goes directly to the attacker without the knowledge of the user that he has fallen victim to an identity theft.
Posted by
Sunflower
at
3/11/2012 12:51:00 PM
0
comments
Labels: Attackers, Code, Content, Content Spoofing, Database, Detection, Errors, Input, Load, Login, Malicious, pages, Sensitive, Spoofed, Text format, Users, Victim, Web Applications, Web pages, Website
|
| Subscribe by Email |
|
Saturday, March 10, 2012
What are different software development problems and what are its solutions?
Today‘s world is growing up in the age of software. The whole world revolves around the computers and the computing is all possible because of effective softwares. The quality of the software systems and applications that we use depends largely up on the quality and efficiency of the software development process.
For producing the quality and efficient softwares, a sound software development process is required. But, today as the technology is advancing, so are the problems associated with it.
In this article we are going to throw some light on the problems that come in the way of software development and also we shall seek some solutions for them.
DIFFERENT SOFTWARE DEVELOPMENT PROBLEMS
- There is a lack of skill in the IT sector and the available expertise is focused more up on the core competencies which include outsource functions that are distasteful and complex though still being important.
- The local software development relates to the global software development.
- A good cooperation is needed among the intra- organizational companies.
- There is a great need of effective outsourcing which includes the availability of global data centres, IT infrastructure and embedded softwares, software applications and maintenance applications.
- Apart from all these there is a big requirement for better application service providers or ASPs.
There are several other problems associated with the software development:
1. Communication Problems
- In today’s world the development of software is not concentrated over a region or area, engineers and experts from all over the world contribute in this.
- Formal communication is needed during the routine, inspections and for formal specifications whereas informal communication is required to describe the informally captured requirements.
- Problems like following occur:
(a) Distinct backgrounds
(b) Time zone difference
(c) Lack of information communication
(d) Distinct backgrounds
(e) Distance
2. Strategic Problems
A lot of problems are faced while designing a strategy for the software development like:
(a) When to start development?
(b) Which task is to be allotted to whom?
(c) How to manage risk at both organizational level and project level.
3. Complexity in Coordination
The members of the software development team often find it difficult to cooperate with each other.
4. Issues related to Diverse Cultures
- Team members are from different cultural backgrounds and this has an affect on their performance, individualism, and attitude towards the work.
- Emotions and attitude towards race, religion and class etc add to these problems.
- The team members should be smart enough to understand each other’s culture and learn to compromise and respect the cultures of each other.
- Some of the measures to overcome cultural issues include reducing the intense collaboration among the team members, reducing the cultural distance by cultural liaison and personnel exchange etc.
5. Physical or Geographical Dispersion
Geographical dispersion of the team members as well as resources which results in an uneven distribution of the vendor support, access to expertise and cause a hindrance in the use of software development practices which need a face to face interaction.
6. Technical Problems
Sharing of the artifact as well as information about the development plan and software becomes quite a difficult job.
7. Management of Knowledge
This is a consequence of lack of communication or poor communication among the team members, lack of proper documentation, repositories and so on.
8. Availability of Open Source Software
- Open source softwares that facilitate the exchange of information and artifact among the developers and provide means for the modification of the code should be made available to all involved in the development process.
- Such open source softwares help in unifying the distributed development process.
Posted by
Sunflower
at
3/10/2012 11:31:00 AM
0
comments
Labels: Application, Communication, Cooperation, Coordination, Development, Efficiency, Information, Outsourcing, Problems, Quality, Skills, Software development, Solutions, Strategic, Technology
|
| Subscribe by Email |
|
Friday, March 9, 2012
What is meant by storm worm?
Storm worm? You may not recognize this worm at the first instance since you might be knowing it by one of the following other names:
1. Small. Dam
2. Trojan- downloader. Win 32. Small. Dam
3. F secure as dubbed by the finnish company.
4. W32/ Numwar@MM
5. Downloader BAI (McAfee’s specific variant)
6. Trojan. DL. Tibs. Gen! Pact13
7. Trojan. Peacomm (Symantec)
8. Win32/ Nuwar (ESET)
9. W32/ Zhelatin (kaspersky, F secure)
10. Trojan. Peed (Bit Defender)
11. Trojan. Tibs (Bit Defender)
12. Win32/ Nuwar. N@MM! CME- 711 (windows live one care)
13. TROJ_SMALL. EDW (trend micro)
14. Trojan. Downloader – 647
15. Loland Mal/ Dorf (sophos)
16. CME- 711 (mitre)
Evolution of Storm Worm
- It was recognized as a back door Trojan horse that had most of its impact on the computer systems that use the Microsoft operating systems or applications or extensions.
- This worm was first observed on the date of 17th January in the year of 2007.
- The storm worm first took its affect in the countries of the United States and Europe infecting millions of computer systems starting on the date of 19th January 2007.
- It was usually sent to the users as an e-mail message having the subject as a headline about the recent weather disaster like “230 dead as storm batters Europe”.
- At the starting of this cyber epidemic, there were around 6 waves of attack subsequently.
- At the end of the January 2007, the storm worm was said to account for 8 percent of all the world wide malware infections.
- According to the PC world, the history or origin of the storm worm can be traced back to a Russian business network.
- Mostly the European wind storm “kyrill” was used as the subject of the infected e- mails.
- This email usually had an attachment accompanying it which when opened, automatically installed this malware on to the system of the users.
Steps involved in installing the Malware
The malware was installed via the following steps:
1. Installation of the wincom32 service
2. Injection of payload
3. Passing of the packets to destinations as mentioned in the malware code.
4. Download and run the W32. Mixor. Q@mm worm and Trojan. Abwiz. F Trojan.
These downloaded Trojans then attached themselves to spam like flashcard.exe, postcard.exe and so on. Other changes regarding the original attack wave were made as the mutation of the attack carried on. Below mentioned are some other prominent spam attachments:
1. Ecard.exe
2. Fullstory.exe
3. Read more. Exe
4. Greeting postcard.exe
5. Read more.exe
6. Full news.exe
7. Arcade world.exe
8. Fullvideo.exe
9. Video.exe
10. Full clip.exe
11. More here.exe
12. Click here.exe
13. Nfl stat tracker.exe
14. Arcade world game.exe
Later the storm worm came to be spread by subjects regarding love such as “touched by love”, “love birds” and so on. These e- mails had the links referring to the malicious web sites containing virus like:
1. With love.exe
2. With_love.exe
3. From me to you.exe
4. Fck2008.exe
5. Fck2009.exe
6. Love.exe
7. Iheart you.exe
The storm worm has an exceptional ability to stay resilient. The affected machine or system used to become a part of botnet networks which was controlled through a central server. A botnet is seeded by the storm worm that acts as a P2P network without any control. The connected systems then act as a host and share the list of other hosts. One peculiarity was observed in the working of these machines which is that none of them shared the whole list of botnets.
Posted by
Sunflower
at
3/09/2012 10:57:00 PM
0
comments
Labels: Application, Computer system, Connected systems, Control, Destination, Hosts, Impact, Infection, Installation, Machines, Malware, Network, Packets, Security, Source, Storm Worm, Trojan Horse, Users
|
| Subscribe by Email |
|
What is the difference between re-test and regression testing?
Software re- testing and regression testing are the two concepts which are often misunderstood by the people. These two software testing concepts will be focused up on in this article. These two terms are often mistaken as the same thing but, it is not so. There is a considerable difference between the two.
Concepts of Re-testing
- As we all know, the field of software testing is continually improving, it becomes necessary to modify and re- test the existing software components to make them compatible with the new advanced technology.
- It becomes necessary to retest those old software components to check how much they have been affected by the changes and what all improvements and modifications are needed to make them at par with the new technology.
- So we see that testing a software component for another time is called re- testing.
Concepts of Regression Testing
- Testing these software components again and again for the sake of improvement and modification is what is called regression testing.
- We can formally define the regression testing as the software testing methodology that seeks to dig out new errors and bugs after the all other types of software testing have been carried out on the system and the required changes have been made to root out those bugs and flaws.
- It is mostly emphasized on testing the patches, enhancements and of course configuration changes.
- Regression testing is aimed at determining whether or not the modifications or enhancements have introduced new bugs and errors.
- Another purpose of carrying out regression testing is to ensure that the any changes in one component do not affect the functioning of the other components of the software system or application.
- Executing the already executed tests and observing the behavior as well as the outcome of the program, is the most common approach to the regression testing.
- Regression testing also sees to it that the faults that were fixed previously do not occur again.
- Regression testing like any other testing also consumes so much of time and effort.
- Therefore, in order to cut down the testing time and improve the efficiency of regression testing, the tester can select only few of the required test cases and execute them once again.
- Regression testing is the most costly software testing methodology that is ever employed in a software testing life cycle.
- An aggressive research has been carried out on the regression testing and many issues have been discovered with the regression testing.
Process may be either of deployment or development, because of both of them changes are made in the software system like adaptation to changes, enhancement of functionality and bug fixing etc.
Retesting and regression testing are seen as one of the most expensive software testing processes.
- These two testing processes can take up to 80 percent of the total budget of the software testing and accounts for 50 percent of the total project budget.
- For normal development processes, it is ok if the regression testing is carried after the changes have been made to the software system for every regular builds or before the final release of the software.
- But, for the agile development processes, the regression testing should be carried out after every time the software program is compiled and saved.
- For other types of development, the regression testing can be carried out before the release of the patches like security patches and so on.
- In whatever way or on whatever time the regression testing might be performed, its aim is always the same i.e., giving the assurance that the changes made to the software act as expected and do not affect the other components of the program.
Posted by
Sunflower
at
3/09/2012 10:00:00 AM
0
comments
Labels: Application, Bugs, Components, Concepts, Defects, Development, Enhancements, Errors, Flaws, Functional, Modifications, Re-test, Re-testing, Regression, Regression Testing, Software testing, Technology
|
| Subscribe by Email |
|
Thursday, March 8, 2012
What is meant by negative testing?
Negative testing is one of the most sought after software testing methodology. Negative testing is the counterpart of positive testing.
Facts about Negative Testing
- Negative testing is really very helpful when it comes to handling the invalid input test data and abnormal behavior of the software system or application.
- The purpose of the negative testing is to prevent such situations in which the invalid data might be taken by the system and which in turn may disrupt the functioning of the whole software system or application.
- For example, when a user tries to enter numerical data in the alphabetic field, the software system displays a message like “incorrect data type”.
- Such response from the software system or application is required since it avoids the crashing or hanging of the whole system by preventing input of invalid data.
- Not only this, the negative testing helps one improve the quality of the software system or application by knocking out its weak points.
- In positive testing, giving some invalid data as input to the system is considered to be an exception but this is not so in the case of negative testing.
- In negative testing, giving some exceptional input to the software system or application is treated just like a normal event.
- Negative testing is all about testing the exceptions.
- Usually for a better software testing results, both the negative testing as well as positive testing are combined together and implemented.
- Using such a testing methodology provides greater test coverage rather than using just one of the either mentioned software testing methodologies.
Situations which are typically tested by the negative testing:
1. Filling up fields by user
- Most of the web sites as well as web applications require the user to fill up all the fields that are marked compulsory.
- To test this functionality, leave all the marked fields blank and hit the submit button and observe the response of the site or the application.
- The expected outcome here can be a message asking you to fill up all the compulsory fields.
2.Checking correspondence between field and data type
- Negative testing also checks the correspondence between the field and data types.
- For example, the different fields in a form can accept the specified type of data. - To test this, you can enter various sorts of invalid data types in to those fields and check the behavior of the application.
3. Checks allowed limits and data bounds
- It also checks for the allowed limits and allowed data bounds.
- Fields in a form can accept data only within a specified data range and not above or below that.
- This can be tested in two ways. You can either enter value that is less than the lower range of the data or you can enter value that is above the specified range.
- Another example can be of text box which accepts only a finite number of characters.
- You can test it by inputting less or more number of characters.
4. Checking reason ability of input data. - Negative testing is also an effective tool for checking the reasonability of the input data.
- The age fields in some web forms etc do not allow any negative integers and also no floating point value.
- This can be tested by simply putting in the wrong data types like a negative integer.
5. Tests the web sessions
- Negative testing can also be used to test the web sessions either for timing or for log-in purposes.
- There are some web pages for viewing which you first have to log in.
- This can be tested by trying to open that web page without logging in.
Negative testing is pretty easy to be carried out manually, but still you can find many automation tools for it.
Posted by
Sunflower
at
3/08/2012 11:55:00 PM
0
comments
Labels: Coverage, Data, Events, Functional, Invalid, Limits, Messages, Methodology, Negative, Negative Testing, Positive Testing, Purpose, Response, Software testing, Tests, Valid, Web Applications, Websites
|
| Subscribe by Email |
|
What are different phases of web application testing?
What is a web application actually? How do we define it? Let us put it in very simple words!
" A web application is much like any other normal application, the only difference being that a web application can be accessed only over an internet connection."
So only the accessibility makes it different form the other types of applications.
What is Web Application?
- A web application can be purely an individual application with its own spate existence over the web.
- But, there are several other kinds of web applications which are written in the Java script and are embedded in a web page or web site.
- The scripts that are used to write these web applications should be supportable by the web browsers.
- The scripts are usually a combination of Java and HTML codes and can be executed only with the help of a web browser and otherwise not possible.
What makes these web applications so popular among today’s generation?
- It is nothing else but the ubiquity of the web browsers.
- The web applications make use of the web browsers as a running client.
- Most of the web applications display the property of the cross platform compatibility i.e., they can be used on multiple platforms and across multiple browsers.
- This further makes them very much popular.
- Web applications like online retail sales and wikis are gaining so much of popularity world wide.
- As the number of users of the web applications keep on increasing the more vulnerable its following aspects become: security, reliability and quality.
These are some of the most crucial factors responsible for the success of a web application.
What can be done to improve their efficiency?
- Effective testing is one such measure which can improve the performance of any web application.
- Performing a web application testing is kind of tough task and requires great skills since the tester has got no direct control over the working of the web application.
Phases of Web Application testing
A typical web application testing comprises of three main phases:
1.1st phase: Testing of the Web tier
This phase involves the testing of the web application for the cross browser compatibility. The web application is checked the commonly and widely used web browsers.
2. 2nd phase: Testing of the middle tier
This phase involves the testing of the security related aspects as well as the functionality and features of the web application.
3. 3rd phase: Testing of the Data base tier
This phase involves the determination of the integrity of the data base of the web application as well its components. This phase is also concerned with the verification of the components of the web application.
Steps followed in each phase are:
Whichever the phase may be, there are common steps that are followed in every phase.
- First step is usually the loading of the web application on to a web server. The testing is not concerned with the location of the server! It might be known or unknown, it doesn’t matters.
- After this step, the second step involves the installation of this web application on the client side server.
- The web application is tested on the client’s side. The following mentioned aspects are foremost tested:
1. Browser compatibility
2. Operating system compatibility
3. Error testing
4. Static pages
5. Validation of the CSS and HTML code (either by checking the URL or by uploading)
6. Load testing and
7. Back end testing.
Posted by
Sunflower
at
3/08/2012 01:39:00 PM
0
comments
Labels: Application, Client, Code, Efficiency, Internet, Middle, Phases, Platforms, Quality, Reliability, Security, Steps, Test Scripts, Web Applications, Web browser, Web page, Web tier, WebApps, Websites
|
| Subscribe by Email |
|