Demonstrate your knowledge of testing security controls aligned with Input validation and business logic. You will also use the recommended OWASP testing guide reporting format to report your test findings.

profilepatterson
FollowtheGradingRubric.docx

Grading Rubric:

Attribute Meets Reflected Cross site scripting 10 points Tests for Reflected Cross site scripting (OTG-INVAL-001) as applied to the sample tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (1 point)

Discusses and demonstrates if a user can place a simple JavaScript alert. (4 points) Stored Cross site scripting 10 points Tests for Stored Cross site scripting (OTG-INVAL-002) as applied to the sample tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (2 points)

Discusses and demonstrates if a user can introduce Stored Cross site scripting and attempt to add a pop-up window. (3 points) SQL Injection 20 points Tests for SQL injection (OTGINPVAL-005) as applied to the sample tutor application. (5 points)

Names two or more mitigation steps according to reading or other research. (5 points)

Fixes and tests at least one discovered SQL injection - and displays source code changes and resulting test output.

(10 points) Code Injection 10 points Tests for Code Injection (OTGINVAL-012) as applied to the sample tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (1 point)

Names two or more mitigation steps according to reading or other research. (1 point)

Discusses and demonstrates if a user can introduce some simple HTML code and exploit Remote File Inclusion (RFI). (3 points) Business logic data validation 10 points Tests business logic data validation (OTG-BUSLOGIC-001) as applied to the sample tutor application. (5 points)

Discusses and demonstrates two or more logic errors. (5 points)

Discusses how to mitigate logic errors. (2 points) Integrity checks 10 points Tests integrity checks (OTGBUSLOGIC-003) as applied to the sample tutor application. (5 points)

Discusses and demonstrates if drop-down menus exist and are sufficient for the application. (3 points)

Discusses the use of password AUTOCOMPLETE functionality and its importance. (2 points)

Defenses against application misuse

10 points Tests defenses against application misuse (OTGBUSLOGIC-007) as applied to the sample tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (1 point)

Discusses and demonstrates if additional characters can be added in at least 2 instances to cause unexpected results. (4 points) Documentation and Submission 20 points Documents the results for the tests and your comments, and recommendations for improved security for each security control tested in a Word or PDF document. (5 points)

Uses the format that is recommended in Chapter 5 of the OWASP testing guide. (5 points)

Screen captures are clearly labeled indicating exactly what the screen capture represents. (5 points)

Document is well-organized, includes page numbers, includes all references used, and contains minimal spelling and grammatical errors. (5 points)

Gr

ading Rubric:

Attribute Meets Reflected Cross site scripting 10 points Tests for Reflected Cross site scripting (OTG

-

INVAL

-

001) as applied to the sample tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (1 point

)

Discusses and demonstrates if a user can place a simple JavaScript alert. (4 points) Stored Cross site

scripting 10 points Tests for Stored Cross site scripting (OTG

-

INVAL

-

002) as applied to the sample tutor

application. (5 points)

Discusses the

importance of testing for this vulnerability. (2 points)

Discusses and demonstrates if a user can introduce Stored Cross site scripting and attempt to add a pop

-

up window. (3 points) SQL Injection 20 points Tests for SQL injection (OTGINPVAL

-

005) as a

pplied to the

sample tutor application. (5 points)

Names two or more mitigation steps according to reading or other research. (5 points)

Fixes and tests at least one discovered SQL injection

-

and displays source code changes and resulting

test out

put.

(10 points) Code Injection 10 points Tests for Code Injection (OTGINVAL

-

012) as applied to the sample

tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (1 point)

Names two or more mitigation steps acco

rding to reading or other research. (1 point)

Discusses and demonstrates if a user can introduce some simple HTML code and exploit Remote File

Inclusion (RFI). (3 points) Business logic data validation 10 points Tests business logic data validation

(O

TG

-

BUSLOGIC

-

001) as applied to the sample tutor application. (5 points)

Discusses and demonstrates two or more logic errors. (5 points)

Grading Rubric:

Attribute Meets Reflected Cross site scripting 10 points Tests for Reflected Cross site scripting (OTG-

INVAL-001) as applied to the sample tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (1 point)

Discusses and demonstrates if a user can place a simple JavaScript alert. (4 points) Stored Cross site

scripting 10 points Tests for Stored Cross site scripting (OTG-INVAL-002) as applied to the sample tutor

application. (5 points)

Discusses the importance of testing for this vulnerability. (2 points)

Discusses and demonstrates if a user can introduce Stored Cross site scripting and attempt to add a pop-

up window. (3 points) SQL Injection 20 points Tests for SQL injection (OTGINPVAL-005) as applied to the

sample tutor application. (5 points)

Names two or more mitigation steps according to reading or other research. (5 points)

Fixes and tests at least one discovered SQL injection - and displays source code changes and resulting

test output.

(10 points) Code Injection 10 points Tests for Code Injection (OTGINVAL-012) as applied to the sample

tutor application. (5 points)

Discusses the importance of testing for this vulnerability. (1 point)

Names two or more mitigation steps according to reading or other research. (1 point)

Discusses and demonstrates if a user can introduce some simple HTML code and exploit Remote File

Inclusion (RFI). (3 points) Business logic data validation 10 points Tests business logic data validation

(OTG-BUSLOGIC-001) as applied to the sample tutor application. (5 points)

Discusses and demonstrates two or more logic errors. (5 points)