SlideShare a Scribd company logo
OWASP TESTING GUIDE 3.0 Release
FOREWORD
The problem of insecure software is perhaps the most important technical challenge of our time.
Security is now the key limiting factor on what we are able to create with information technology. At
The Open Web Application Security Project (OWASP), we're trying to make the world a place where
insecure software is the anomaly, not the norm, and the OWASP Testing Guide is an important piece
of the puzzle.
It goes without saying that you can't build a secure application without performing security testing on it.
Yet many software development organizations do not include security testing as part of their standard
software development process. Still, security testing, by itself, isn't a particularly good measure of how
secure an application is, because there are an infinite number of ways that an attacker might be able
to make an application break, and it simply isn't possible to test them all. However, security testing has
the unique power to absolutely convince naysayers that there is a problem. So security testing has
proven itself as a key ingredient in any organization that needs to trust the software it produces or
uses.

WHO?
Software developers – you need to use this guide to make sure the code you deliver is not
vulnerable to attack. You cannot rely on downstream testers or security groups to do this for you.
Those groups will never understand your software as well as you do, and therefore will never be able
to test your software as effectively as you can. The responsibility for the security of your code is
emphatically yours!
Software testers – you should use this guide to enhance your testing abilities. While security testing
has been a dark art for a long time, OWASP is working hard to making this knowledge free and open
for everyone. Many of the tests described in this guide are not that complicated, and don’t require
special skills or tools. You can help your company and enhance your career by learning about security.
Security specialists – you have a special responsibility to ensure that applications do not go live with
vulnerabilities. You can use this guide to help ensure the coverage and rigor of your security testing.
Don’t fall victim to the trap of simply looking for a few holes. Your job is to verify the security of the
entire application. We strongly recommend using the OWASP Application Security Verification
Standard (ASVS) as a guide as well.

THE OWASP GUIDES
OWASP has produced several Guides that work together to capture the application security
knowledgebase:
OWASP Application Security Desk Reference – The ASDR contains basic definitions and
descriptions of all the important principles, threat agents, attacks, vulnerabilities, countermeasures,
technical impacts, and business impacts in application security. This is the foundational reference work
for all the other Guides, and is referred to frequently by these other volumes.
OWASP Developer’s Guide – The Developer’s Guide covers all the security controls that software
developers should put in place. These are the ‘positive’ protections that developers must build into
their applications. While there are hundreds of types of software vulnerabilities, they can all be
prevented with a handful of strong security controls.
OWASP Testing Guide – The Testing Guide you are reading covers the procedures and tools for
testing the security of applications. The best use of this guide is as part of a comprehensive
application security verification.
OWASP Code Review Guide – The Code Review Guide is best used alongside the Testing Guide.
Verifying applications with code review is often far more cost-effective than testing, and you can
choose the most effective approach for the application you are working on.
Taken together, OWASP's guides are a great start towards building and maintaining secure
applications. I highly recommend using these guides as part of your application security initiatives.

WHY OWASP?
Creating a guide like this is a massive undertaking, representing the expertise of hundreds of people
around the world. There are many different ways to test for security flaws and this guide captures the
consensus of the leading experts on how to perform this testing quickly, accurately, and efficiently.
It's impossible to underestimate the importance of having this guide available in a completely free and
open way. Security should not be a black art that only a few can practice. Much of the available
security guidance is only detailed enough to get people worried about a problem, without providing
enough information to find, diagnose, and solve security problems. The project to build this guide
keeps this expertise in the hands of the people who need it.
This guide must make its way into the hands of developers and software testers. There are not nearly
enough application security experts in the world to make any significant dent in the overall
problem.The initial responsibility for application security must fall on the shoulders of the developers. It
shouldn't be a surprise that developers aren't producing secure code if they're not testing for it.
Keeping this information up to date is a critical aspect of this guide project. By adopting the wiki
approach, the OWASP community can evolve and expand the information in this guide to keep pace
with the fast moving application security threat landscape.
PRIORITIZING
This guide is best viewed as a set of techniques that you can use to find different types of security
holes. But not all the techniques are equally important. Try to avoid using the guide as a checklist.
Probably the most important aspect of application security testing to keep in mind is that you will have
limited time and you need to provide as much coverage as possible. I strongly recommend that you do
not just flip open this book and start testing. Ideally, you would do some threat modeling to determine
what the most important security concerns to your enterprise. You should end up with a prioritized list
of security requirements to verify.
The next step is to decide how to verify these requirements. There are a number of different options.
You can use manual security testing or manual code review. You can also use automated vulnerability
scanning or automated code scanning (static analysis). You might even use security architecture
review or discussions with developers and architects to verify these requirements. The important thing
is to decide which of these techniques will be the most accurate and efficient for your particular
application.

THE ROLE OF AUTOMATED TOOLS
The automated approaches are seductive. It seems like they will provide reasonable coverage in a
relatively short time period. Unfortunately, these assumptions are far less true for application security
than they are for network security.
First, the coverage isn’t very good because these tools are generic - meaning that they are not
designed for your custom code. That means that while they can find some generic problems, they do
not have enough knowledge of your application to allow them to detect most flaws. Also, in my
experience, the most serious security issues are the ones that are not generic, but deeply intertwined
in your business logic and custom application design.
Second, the automated tools aren’t even necessarily faster than manual methods. Actually running the
tools doesn't take much time, but the time before and after can be significant. To setup, you have to
teach the tools about all the ins and outs of the application – possibly thousands of fields. Then
afterwards, it can take a significant amount of time to diagnose each of the sometimes thousands of
reported issues, which are frequently non-issues.
If the goal is to find and eliminate the most serious flaws as quickly as possible, choose the most
effective technique for different types of vulnerabilities. Automated tools can be quite effective on
certain issues. Used wisely, they can support your overall processes to produce more secure code.
CALL TO ACTION
If you're building software, I strongly encourage you to get familiar with the security testing guidance in
this document. If you find errors, please add a note to the discussion page or make the change
yourself. You'll be helping thousands of others who use this guide.
Please consider joining us as an individual or corporate member so that we can continue to produce
materials like this testing guide and all the other great projects at OWASP. Thank you to all the past
and future contributors to this guide, your work will help to make applications worldwide more secure.

Jeff Williams
OWASP Chair
January 18, 2009

More Related Content

What's hot

Bab 1
Bab 1Bab 1
7 testing principles
7 testing principles7 testing principles
7 testing principles
Testing Expert
 
Fundamental of testing (what is testing)
Fundamental of testing (what is testing)Fundamental of testing (what is testing)
Fundamental of testing (what is testing)
helfa safitri
 
Top Agile Myths & Misconceptions
Top Agile Myths & MisconceptionsTop Agile Myths & Misconceptions
Top Agile Myths & Misconceptions
David Tzemach
 
fundamentals of testing (Fundamental of testing what)
fundamentals of testing (Fundamental of testing what)fundamentals of testing (Fundamental of testing what)
fundamentals of testing (Fundamental of testing what)
diana fitri, S.Kom
 
FADHILLA ELITA Ppt Chapter 1
FADHILLA ELITA Ppt Chapter 1FADHILLA ELITA Ppt Chapter 1
FADHILLA ELITA Ppt Chapter 1
fadhilla elita
 
How to build app sec team & culture in your organization the hack summi...
How to build app sec team & culture in your organization   the hack summi...How to build app sec team & culture in your organization   the hack summi...
How to build app sec team & culture in your organization the hack summi...
kunwaratul hax0r
 
Innovating Faster with Continuous Application Security
Innovating Faster with Continuous Application Security Innovating Faster with Continuous Application Security
Innovating Faster with Continuous Application Security
Jeff Williams
 
Principles of software testing
Principles of software testingPrinciples of software testing
Principles of software testing
Software Testing Books
 
Overcoming The Challenges Faced in Exploratory Testing
Overcoming The Challenges Faced in Exploratory TestingOvercoming The Challenges Faced in Exploratory Testing
Overcoming The Challenges Faced in Exploratory Testing
Sarah Elson
 
2017-11 Three Ways of Security - OWASP London
2017-11 Three Ways of Security - OWASP London2017-11 Three Ways of Security - OWASP London
2017-11 Three Ways of Security - OWASP London
Jeff Williams
 
Building an AppSec Team Extended Cut
Building an AppSec Team Extended CutBuilding an AppSec Team Extended Cut
Building an AppSec Team Extended CutMike Spaulding
 
Succeeding-Marriage-Cybersecurity-DevOps final
Succeeding-Marriage-Cybersecurity-DevOps finalSucceeding-Marriage-Cybersecurity-DevOps final
Succeeding-Marriage-Cybersecurity-DevOps finalrkadayam
 
TDC PoA submission
TDC PoA submissionTDC PoA submission
TDC PoA submission
Marcelo Yuri Benesciutti
 
Application Security at DevOps Speed and Portfolio Scale
Application Security at DevOps Speed and Portfolio ScaleApplication Security at DevOps Speed and Portfolio Scale
Application Security at DevOps Speed and Portfolio Scale
Jeff Williams
 
Automating OWASP Tests in your CI/CD
Automating OWASP Tests in your CI/CDAutomating OWASP Tests in your CI/CD
Automating OWASP Tests in your CI/CD
rkadayam
 
Testing Principles
Testing PrinciplesTesting Principles
Testing Principles
Risma Rustiyan R
 
Do you know security flaws persist in java 7u10 update !
Do you know security flaws persist in java 7u10 update !Do you know security flaws persist in java 7u10 update !
Do you know security flaws persist in java 7u10 update !
Andolasoft Inc
 
State of selenium survey results
State of selenium survey resultsState of selenium survey results
State of selenium survey results
Tellurium
 

What's hot (20)

Bab 1
Bab 1Bab 1
Bab 1
 
7 testing principles
7 testing principles7 testing principles
7 testing principles
 
Fundamental of testing (what is testing)
Fundamental of testing (what is testing)Fundamental of testing (what is testing)
Fundamental of testing (what is testing)
 
Top Agile Myths & Misconceptions
Top Agile Myths & MisconceptionsTop Agile Myths & Misconceptions
Top Agile Myths & Misconceptions
 
fundamentals of testing (Fundamental of testing what)
fundamentals of testing (Fundamental of testing what)fundamentals of testing (Fundamental of testing what)
fundamentals of testing (Fundamental of testing what)
 
FADHILLA ELITA Ppt Chapter 1
FADHILLA ELITA Ppt Chapter 1FADHILLA ELITA Ppt Chapter 1
FADHILLA ELITA Ppt Chapter 1
 
How to build app sec team & culture in your organization the hack summi...
How to build app sec team & culture in your organization   the hack summi...How to build app sec team & culture in your organization   the hack summi...
How to build app sec team & culture in your organization the hack summi...
 
Innovating Faster with Continuous Application Security
Innovating Faster with Continuous Application Security Innovating Faster with Continuous Application Security
Innovating Faster with Continuous Application Security
 
Principles of software testing
Principles of software testingPrinciples of software testing
Principles of software testing
 
Overcoming The Challenges Faced in Exploratory Testing
Overcoming The Challenges Faced in Exploratory TestingOvercoming The Challenges Faced in Exploratory Testing
Overcoming The Challenges Faced in Exploratory Testing
 
2017-11 Three Ways of Security - OWASP London
2017-11 Three Ways of Security - OWASP London2017-11 Three Ways of Security - OWASP London
2017-11 Three Ways of Security - OWASP London
 
Building an AppSec Team Extended Cut
Building an AppSec Team Extended CutBuilding an AppSec Team Extended Cut
Building an AppSec Team Extended Cut
 
Software testing myths
Software testing mythsSoftware testing myths
Software testing myths
 
Succeeding-Marriage-Cybersecurity-DevOps final
Succeeding-Marriage-Cybersecurity-DevOps finalSucceeding-Marriage-Cybersecurity-DevOps final
Succeeding-Marriage-Cybersecurity-DevOps final
 
TDC PoA submission
TDC PoA submissionTDC PoA submission
TDC PoA submission
 
Application Security at DevOps Speed and Portfolio Scale
Application Security at DevOps Speed and Portfolio ScaleApplication Security at DevOps Speed and Portfolio Scale
Application Security at DevOps Speed and Portfolio Scale
 
Automating OWASP Tests in your CI/CD
Automating OWASP Tests in your CI/CDAutomating OWASP Tests in your CI/CD
Automating OWASP Tests in your CI/CD
 
Testing Principles
Testing PrinciplesTesting Principles
Testing Principles
 
Do you know security flaws persist in java 7u10 update !
Do you know security flaws persist in java 7u10 update !Do you know security flaws persist in java 7u10 update !
Do you know security flaws persist in java 7u10 update !
 
State of selenium survey results
State of selenium survey resultsState of selenium survey results
State of selenium survey results
 

Viewers also liked

Easy ENGLISH - 50 CLAVES - Gramática
Easy ENGLISH - 50 CLAVES - GramáticaEasy ENGLISH - 50 CLAVES - Gramática
Easy ENGLISH - 50 CLAVES - GramáticaFINA ORDORIKA
 
Gramatica en Esquemas
Gramatica en EsquemasGramatica en Esquemas
Gramatica en Esquemas
Jairo Alberto Galindo Cuesta
 
The ideal target audience
The ideal target audienceThe ideal target audience
The ideal target audienceFigen232
 
Sc informer
Sc informerSc informer
Sc informerDim Kin
 
Abate leite-couro-ovos 201404-publ_completa
Abate leite-couro-ovos 201404-publ_completaAbate leite-couro-ovos 201404-publ_completa
Abate leite-couro-ovos 201404-publ_completa
Lilliane Renata Defante
 
The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...
The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...
The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...
Benjamin Crucq
 
Creative writting official
Creative writting officialCreative writting official
Creative writting official
amgonzalezpineiro
 
Heineken - Urban Market Manager
Heineken - Urban Market Manager Heineken - Urban Market Manager
Heineken - Urban Market Manager John Romano
 
DNA Information and Creation
DNA Information and CreationDNA Information and Creation
DNA Information and Creation
Hans Rudolf Tremp
 
Copy of the story of the candy cane
Copy of the story of the candy caneCopy of the story of the candy cane
Copy of the story of the candy cane
Becky Kew
 
повышение компетентности кл.рук.
повышение компетентности кл.рук.повышение компетентности кл.рук.
повышение компетентности кл.рук.kravhenko
 
Open office manual
Open office manualOpen office manual
Open office manualDim Kin
 
Chaffey Secondary College
Chaffey Secondary College Chaffey Secondary College
Chaffey Secondary College
nmouvet
 
Qaep management system pwp
Qaep management system pwpQaep management system pwp
Qaep management system pwpBroto Mudjianto
 
Admin system security_guide
Admin system security_guideAdmin system security_guide
Admin system security_guideDim Kin
 
Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...
Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...
Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...nacionalaidentitate
 

Viewers also liked (20)

2.5 cuadros sinopticos
2.5 cuadros sinopticos2.5 cuadros sinopticos
2.5 cuadros sinopticos
 
Gramaticaeso
GramaticaesoGramaticaeso
Gramaticaeso
 
1.8 y 1.9 cognados y técnicas
1.8 y 1.9 cognados y técnicas1.8 y 1.9 cognados y técnicas
1.8 y 1.9 cognados y técnicas
 
Easy ENGLISH - 50 CLAVES - Gramática
Easy ENGLISH - 50 CLAVES - GramáticaEasy ENGLISH - 50 CLAVES - Gramática
Easy ENGLISH - 50 CLAVES - Gramática
 
Gramatica en Esquemas
Gramatica en EsquemasGramatica en Esquemas
Gramatica en Esquemas
 
labconsulting
labconsultinglabconsulting
labconsulting
 
The ideal target audience
The ideal target audienceThe ideal target audience
The ideal target audience
 
Sc informer
Sc informerSc informer
Sc informer
 
Abate leite-couro-ovos 201404-publ_completa
Abate leite-couro-ovos 201404-publ_completaAbate leite-couro-ovos 201404-publ_completa
Abate leite-couro-ovos 201404-publ_completa
 
The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...
The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...
The world at work: Jobs, pay and skills for 3,5 billion people. From McKinsey...
 
Creative writting official
Creative writting officialCreative writting official
Creative writting official
 
Heineken - Urban Market Manager
Heineken - Urban Market Manager Heineken - Urban Market Manager
Heineken - Urban Market Manager
 
DNA Information and Creation
DNA Information and CreationDNA Information and Creation
DNA Information and Creation
 
Copy of the story of the candy cane
Copy of the story of the candy caneCopy of the story of the candy cane
Copy of the story of the candy cane
 
повышение компетентности кл.рук.
повышение компетентности кл.рук.повышение компетентности кл.рук.
повышение компетентности кл.рук.
 
Open office manual
Open office manualOpen office manual
Open office manual
 
Chaffey Secondary College
Chaffey Secondary College Chaffey Secondary College
Chaffey Secondary College
 
Qaep management system pwp
Qaep management system pwpQaep management system pwp
Qaep management system pwp
 
Admin system security_guide
Admin system security_guideAdmin system security_guide
Admin system security_guide
 
Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...
Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...
Žurnālistikas atbildība un atbildīgums: profesionālās un nacionālās identitāt...
 

Similar to Texto de Ayuda Un2_Taller de ingles

_Best practices towards a well-polished DevSecOps environment (1).pdf
_Best practices towards a well-polished DevSecOps environment  (1).pdf_Best practices towards a well-polished DevSecOps environment  (1).pdf
_Best practices towards a well-polished DevSecOps environment (1).pdf
Enov8
 
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015
Minded Security
 
DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.
Techugo
 
DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.
Techugo
 
DevOps and Devsecops.pdf
DevOps and Devsecops.pdfDevOps and Devsecops.pdf
DevOps and Devsecops.pdf
Techugo
 
DevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdfDevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdf
Techugo
 
Enterprise Devsecops
Enterprise DevsecopsEnterprise Devsecops
Enterprise Devsecops
Enov8
 
How To Implement DevSecOps In Your Existing DevOps Workflow
How To Implement DevSecOps In Your Existing DevOps WorkflowHow To Implement DevSecOps In Your Existing DevOps Workflow
How To Implement DevSecOps In Your Existing DevOps Workflow
Enov8
 
White Paper: 7 Security Gaps in the Neglected 90% of your Applications
White Paper: 7 Security Gaps in the Neglected 90% of your ApplicationsWhite Paper: 7 Security Gaps in the Neglected 90% of your Applications
White Paper: 7 Security Gaps in the Neglected 90% of your Applications
Sonatype
 
How automation can help boost security
How automation can help boost securityHow automation can help boost security
How automation can help boost security
TestingXperts
 
Software risk management
Software risk managementSoftware risk management
Software risk management
Jose Javier M
 
Integration into the Secure SDLC Process.ppt
Integration into the Secure SDLC Process.pptIntegration into the Secure SDLC Process.ppt
Integration into the Secure SDLC Process.ppt
Imam Halim Mursyidin
 
6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf
6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf
6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf
Expert App Devs
 
DevSecOps Security: Is it Necessary?
DevSecOps Security: Is it Necessary?DevSecOps Security: Is it Necessary?
DevSecOps Security: Is it Necessary?
Enov8
 
Mike Spaulding - Building an Application Security Program
Mike Spaulding - Building an Application Security ProgramMike Spaulding - Building an Application Security Program
Mike Spaulding - Building an Application Security Program
centralohioissa
 
Overcoming Challenges in Dynamic Application Security Testing (DAST)
Overcoming Challenges in Dynamic Application Security Testing (DAST)Overcoming Challenges in Dynamic Application Security Testing (DAST)
Overcoming Challenges in Dynamic Application Security Testing (DAST)
Dev Software
 
10 Best DevSecOps Tools for 2023
10 Best DevSecOps Tools for 202310 Best DevSecOps Tools for 2023
10 Best DevSecOps Tools for 2023
SofiaCarter4
 
Why is software testing important
Why is software testing important Why is software testing important
Why is software testing important
Infowind Technologies (IT) Pvt Ltd
 
Why is software testing important
Why is software testing importantWhy is software testing important
Why is software testing important
Infowind Technologies (IT) Pvt Ltd
 

Similar to Texto de Ayuda Un2_Taller de ingles (20)

_Best practices towards a well-polished DevSecOps environment (1).pdf
_Best practices towards a well-polished DevSecOps environment  (1).pdf_Best practices towards a well-polished DevSecOps environment  (1).pdf
_Best practices towards a well-polished DevSecOps environment (1).pdf
 
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015
 
DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.
 
DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.
 
DevOps and Devsecops.pdf
DevOps and Devsecops.pdfDevOps and Devsecops.pdf
DevOps and Devsecops.pdf
 
DevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdfDevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdf
 
Enterprise Devsecops
Enterprise DevsecopsEnterprise Devsecops
Enterprise Devsecops
 
How To Implement DevSecOps In Your Existing DevOps Workflow
How To Implement DevSecOps In Your Existing DevOps WorkflowHow To Implement DevSecOps In Your Existing DevOps Workflow
How To Implement DevSecOps In Your Existing DevOps Workflow
 
White Paper: 7 Security Gaps in the Neglected 90% of your Applications
White Paper: 7 Security Gaps in the Neglected 90% of your ApplicationsWhite Paper: 7 Security Gaps in the Neglected 90% of your Applications
White Paper: 7 Security Gaps in the Neglected 90% of your Applications
 
How automation can help boost security
How automation can help boost securityHow automation can help boost security
How automation can help boost security
 
Software risk management
Software risk managementSoftware risk management
Software risk management
 
Integration into the Secure SDLC Process.ppt
Integration into the Secure SDLC Process.pptIntegration into the Secure SDLC Process.ppt
Integration into the Secure SDLC Process.ppt
 
VER_WP_CrackingCode_FINAL
VER_WP_CrackingCode_FINALVER_WP_CrackingCode_FINAL
VER_WP_CrackingCode_FINAL
 
6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf
6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf
6 Best Practices to Ensure Secure Web_Mobile Apps.pptx.pdf
 
DevSecOps Security: Is it Necessary?
DevSecOps Security: Is it Necessary?DevSecOps Security: Is it Necessary?
DevSecOps Security: Is it Necessary?
 
Mike Spaulding - Building an Application Security Program
Mike Spaulding - Building an Application Security ProgramMike Spaulding - Building an Application Security Program
Mike Spaulding - Building an Application Security Program
 
Overcoming Challenges in Dynamic Application Security Testing (DAST)
Overcoming Challenges in Dynamic Application Security Testing (DAST)Overcoming Challenges in Dynamic Application Security Testing (DAST)
Overcoming Challenges in Dynamic Application Security Testing (DAST)
 
10 Best DevSecOps Tools for 2023
10 Best DevSecOps Tools for 202310 Best DevSecOps Tools for 2023
10 Best DevSecOps Tools for 2023
 
Why is software testing important
Why is software testing important Why is software testing important
Why is software testing important
 
Why is software testing important
Why is software testing importantWhy is software testing important
Why is software testing important
 

More from Meztli Valeriano Orozco

Tutorial Edpuzzle.pdf
Tutorial Edpuzzle.pdfTutorial Edpuzzle.pdf
Tutorial Edpuzzle.pdf
Meztli Valeriano Orozco
 
Introducción al Sw Libre
Introducción al Sw LibreIntroducción al Sw Libre
Introducción al Sw Libre
Meztli Valeriano Orozco
 
Sesion13
Sesion13Sesion13
Entrevista Robert Mallet
Entrevista Robert MalletEntrevista Robert Mallet
Entrevista Robert Mallet
Meztli Valeriano Orozco
 
Entrevista robert m
Entrevista robert mEntrevista robert m
Entrevista robert m
Meztli Valeriano Orozco
 
Jane eyre
Jane eyreJane eyre
Sesion9
Sesion9Sesion9
Sesion7
Sesion7Sesion7
Sesion6
Sesion6Sesion6
Para traduccion
Para traduccionPara traduccion
Para traduccion
Meztli Valeriano Orozco
 
Sesion5
Sesion5Sesion5
Sesion3
Sesion3Sesion3
P carlos and cape town
P carlos and cape townP carlos and cape town
P carlos and cape town
Meztli Valeriano Orozco
 
Sesion2
Sesion2Sesion2
Sesion1
Sesion1Sesion1
Redaccion einstein
Redaccion einsteinRedaccion einstein
Redaccion einstein
Meztli Valeriano Orozco
 
New energy
New energyNew energy
Dubai's winter
Dubai's winterDubai's winter
Dubai's winter
Meztli Valeriano Orozco
 
Temario Nivel 4 Diplomado de Ingles
Temario Nivel 4 Diplomado de InglesTemario Nivel 4 Diplomado de Ingles
Temario Nivel 4 Diplomado de Ingles
Meztli Valeriano Orozco
 
Workbook sesion15
Workbook sesion15Workbook sesion15
Workbook sesion15
Meztli Valeriano Orozco
 

More from Meztli Valeriano Orozco (20)

Tutorial Edpuzzle.pdf
Tutorial Edpuzzle.pdfTutorial Edpuzzle.pdf
Tutorial Edpuzzle.pdf
 
Introducción al Sw Libre
Introducción al Sw LibreIntroducción al Sw Libre
Introducción al Sw Libre
 
Sesion13
Sesion13Sesion13
Sesion13
 
Entrevista Robert Mallet
Entrevista Robert MalletEntrevista Robert Mallet
Entrevista Robert Mallet
 
Entrevista robert m
Entrevista robert mEntrevista robert m
Entrevista robert m
 
Jane eyre
Jane eyreJane eyre
Jane eyre
 
Sesion9
Sesion9Sesion9
Sesion9
 
Sesion7
Sesion7Sesion7
Sesion7
 
Sesion6
Sesion6Sesion6
Sesion6
 
Para traduccion
Para traduccionPara traduccion
Para traduccion
 
Sesion5
Sesion5Sesion5
Sesion5
 
Sesion3
Sesion3Sesion3
Sesion3
 
P carlos and cape town
P carlos and cape townP carlos and cape town
P carlos and cape town
 
Sesion2
Sesion2Sesion2
Sesion2
 
Sesion1
Sesion1Sesion1
Sesion1
 
Redaccion einstein
Redaccion einsteinRedaccion einstein
Redaccion einstein
 
New energy
New energyNew energy
New energy
 
Dubai's winter
Dubai's winterDubai's winter
Dubai's winter
 
Temario Nivel 4 Diplomado de Ingles
Temario Nivel 4 Diplomado de InglesTemario Nivel 4 Diplomado de Ingles
Temario Nivel 4 Diplomado de Ingles
 
Workbook sesion15
Workbook sesion15Workbook sesion15
Workbook sesion15
 

Recently uploaded

Synthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptxSynthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptx
Pavel ( NSTU)
 
Best Digital Marketing Institute In NOIDA
Best Digital Marketing Institute In NOIDABest Digital Marketing Institute In NOIDA
Best Digital Marketing Institute In NOIDA
deeptiverma2406
 
Honest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptxHonest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptx
timhan337
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
DhatriParmar
 
Language Across the Curriculm LAC B.Ed.
Language Across the  Curriculm LAC B.Ed.Language Across the  Curriculm LAC B.Ed.
Language Across the Curriculm LAC B.Ed.
Atul Kumar Singh
 
Acetabularia Information For Class 9 .docx
Acetabularia Information For Class 9  .docxAcetabularia Information For Class 9  .docx
Acetabularia Information For Class 9 .docx
vaibhavrinwa19
 
2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...
Sandy Millin
 
Chapter -12, Antibiotics (One Page Notes).pdf
Chapter -12, Antibiotics (One Page Notes).pdfChapter -12, Antibiotics (One Page Notes).pdf
Chapter -12, Antibiotics (One Page Notes).pdf
Kartik Tiwari
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with Mechanism
DeeptiGupta154
 
Marketing internship report file for MBA
Marketing internship report file for MBAMarketing internship report file for MBA
Marketing internship report file for MBA
gb193092
 
How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17
Celine George
 
Operation Blue Star - Saka Neela Tara
Operation Blue Star   -  Saka Neela TaraOperation Blue Star   -  Saka Neela Tara
Operation Blue Star - Saka Neela Tara
Balvir Singh
 
Group Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana BuscigliopptxGroup Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana Buscigliopptx
ArianaBusciglio
 
How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...
Jisc
 
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
Nguyen Thanh Tu Collection
 
A Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in EducationA Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in Education
Peter Windle
 
Model Attribute Check Company Auto Property
Model Attribute  Check Company Auto PropertyModel Attribute  Check Company Auto Property
Model Attribute Check Company Auto Property
Celine George
 
1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx
JosvitaDsouza2
 
Embracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic ImperativeEmbracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic Imperative
Peter Windle
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
Levi Shapiro
 

Recently uploaded (20)

Synthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptxSynthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptx
 
Best Digital Marketing Institute In NOIDA
Best Digital Marketing Institute In NOIDABest Digital Marketing Institute In NOIDA
Best Digital Marketing Institute In NOIDA
 
Honest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptxHonest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptx
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
 
Language Across the Curriculm LAC B.Ed.
Language Across the  Curriculm LAC B.Ed.Language Across the  Curriculm LAC B.Ed.
Language Across the Curriculm LAC B.Ed.
 
Acetabularia Information For Class 9 .docx
Acetabularia Information For Class 9  .docxAcetabularia Information For Class 9  .docx
Acetabularia Information For Class 9 .docx
 
2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...2024.06.01 Introducing a competency framework for languag learning materials ...
2024.06.01 Introducing a competency framework for languag learning materials ...
 
Chapter -12, Antibiotics (One Page Notes).pdf
Chapter -12, Antibiotics (One Page Notes).pdfChapter -12, Antibiotics (One Page Notes).pdf
Chapter -12, Antibiotics (One Page Notes).pdf
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with Mechanism
 
Marketing internship report file for MBA
Marketing internship report file for MBAMarketing internship report file for MBA
Marketing internship report file for MBA
 
How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17
 
Operation Blue Star - Saka Neela Tara
Operation Blue Star   -  Saka Neela TaraOperation Blue Star   -  Saka Neela Tara
Operation Blue Star - Saka Neela Tara
 
Group Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana BuscigliopptxGroup Presentation 2 Economics.Ariana Buscigliopptx
Group Presentation 2 Economics.Ariana Buscigliopptx
 
How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...
 
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
BÀI TẬP BỔ TRỢ TIẾNG ANH GLOBAL SUCCESS LỚP 3 - CẢ NĂM (CÓ FILE NGHE VÀ ĐÁP Á...
 
A Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in EducationA Strategic Approach: GenAI in Education
A Strategic Approach: GenAI in Education
 
Model Attribute Check Company Auto Property
Model Attribute  Check Company Auto PropertyModel Attribute  Check Company Auto Property
Model Attribute Check Company Auto Property
 
1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx1.4 modern child centered education - mahatma gandhi-2.pptx
1.4 modern child centered education - mahatma gandhi-2.pptx
 
Embracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic ImperativeEmbracing GenAI - A Strategic Imperative
Embracing GenAI - A Strategic Imperative
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
 

Texto de Ayuda Un2_Taller de ingles

  • 1. OWASP TESTING GUIDE 3.0 Release FOREWORD The problem of insecure software is perhaps the most important technical challenge of our time. Security is now the key limiting factor on what we are able to create with information technology. At The Open Web Application Security Project (OWASP), we're trying to make the world a place where insecure software is the anomaly, not the norm, and the OWASP Testing Guide is an important piece of the puzzle. It goes without saying that you can't build a secure application without performing security testing on it. Yet many software development organizations do not include security testing as part of their standard software development process. Still, security testing, by itself, isn't a particularly good measure of how secure an application is, because there are an infinite number of ways that an attacker might be able to make an application break, and it simply isn't possible to test them all. However, security testing has the unique power to absolutely convince naysayers that there is a problem. So security testing has proven itself as a key ingredient in any organization that needs to trust the software it produces or uses. WHO? Software developers – you need to use this guide to make sure the code you deliver is not vulnerable to attack. You cannot rely on downstream testers or security groups to do this for you. Those groups will never understand your software as well as you do, and therefore will never be able to test your software as effectively as you can. The responsibility for the security of your code is emphatically yours! Software testers – you should use this guide to enhance your testing abilities. While security testing has been a dark art for a long time, OWASP is working hard to making this knowledge free and open for everyone. Many of the tests described in this guide are not that complicated, and don’t require special skills or tools. You can help your company and enhance your career by learning about security. Security specialists – you have a special responsibility to ensure that applications do not go live with vulnerabilities. You can use this guide to help ensure the coverage and rigor of your security testing. Don’t fall victim to the trap of simply looking for a few holes. Your job is to verify the security of the entire application. We strongly recommend using the OWASP Application Security Verification Standard (ASVS) as a guide as well. THE OWASP GUIDES OWASP has produced several Guides that work together to capture the application security knowledgebase:
  • 2. OWASP Application Security Desk Reference – The ASDR contains basic definitions and descriptions of all the important principles, threat agents, attacks, vulnerabilities, countermeasures, technical impacts, and business impacts in application security. This is the foundational reference work for all the other Guides, and is referred to frequently by these other volumes. OWASP Developer’s Guide – The Developer’s Guide covers all the security controls that software developers should put in place. These are the ‘positive’ protections that developers must build into their applications. While there are hundreds of types of software vulnerabilities, they can all be prevented with a handful of strong security controls. OWASP Testing Guide – The Testing Guide you are reading covers the procedures and tools for testing the security of applications. The best use of this guide is as part of a comprehensive application security verification. OWASP Code Review Guide – The Code Review Guide is best used alongside the Testing Guide. Verifying applications with code review is often far more cost-effective than testing, and you can choose the most effective approach for the application you are working on. Taken together, OWASP's guides are a great start towards building and maintaining secure applications. I highly recommend using these guides as part of your application security initiatives. WHY OWASP? Creating a guide like this is a massive undertaking, representing the expertise of hundreds of people around the world. There are many different ways to test for security flaws and this guide captures the consensus of the leading experts on how to perform this testing quickly, accurately, and efficiently. It's impossible to underestimate the importance of having this guide available in a completely free and open way. Security should not be a black art that only a few can practice. Much of the available security guidance is only detailed enough to get people worried about a problem, without providing enough information to find, diagnose, and solve security problems. The project to build this guide keeps this expertise in the hands of the people who need it. This guide must make its way into the hands of developers and software testers. There are not nearly enough application security experts in the world to make any significant dent in the overall problem.The initial responsibility for application security must fall on the shoulders of the developers. It shouldn't be a surprise that developers aren't producing secure code if they're not testing for it. Keeping this information up to date is a critical aspect of this guide project. By adopting the wiki approach, the OWASP community can evolve and expand the information in this guide to keep pace with the fast moving application security threat landscape.
  • 3. PRIORITIZING This guide is best viewed as a set of techniques that you can use to find different types of security holes. But not all the techniques are equally important. Try to avoid using the guide as a checklist. Probably the most important aspect of application security testing to keep in mind is that you will have limited time and you need to provide as much coverage as possible. I strongly recommend that you do not just flip open this book and start testing. Ideally, you would do some threat modeling to determine what the most important security concerns to your enterprise. You should end up with a prioritized list of security requirements to verify. The next step is to decide how to verify these requirements. There are a number of different options. You can use manual security testing or manual code review. You can also use automated vulnerability scanning or automated code scanning (static analysis). You might even use security architecture review or discussions with developers and architects to verify these requirements. The important thing is to decide which of these techniques will be the most accurate and efficient for your particular application. THE ROLE OF AUTOMATED TOOLS The automated approaches are seductive. It seems like they will provide reasonable coverage in a relatively short time period. Unfortunately, these assumptions are far less true for application security than they are for network security. First, the coverage isn’t very good because these tools are generic - meaning that they are not designed for your custom code. That means that while they can find some generic problems, they do not have enough knowledge of your application to allow them to detect most flaws. Also, in my experience, the most serious security issues are the ones that are not generic, but deeply intertwined in your business logic and custom application design. Second, the automated tools aren’t even necessarily faster than manual methods. Actually running the tools doesn't take much time, but the time before and after can be significant. To setup, you have to teach the tools about all the ins and outs of the application – possibly thousands of fields. Then afterwards, it can take a significant amount of time to diagnose each of the sometimes thousands of reported issues, which are frequently non-issues. If the goal is to find and eliminate the most serious flaws as quickly as possible, choose the most effective technique for different types of vulnerabilities. Automated tools can be quite effective on certain issues. Used wisely, they can support your overall processes to produce more secure code.
  • 4. CALL TO ACTION If you're building software, I strongly encourage you to get familiar with the security testing guidance in this document. If you find errors, please add a note to the discussion page or make the change yourself. You'll be helping thousands of others who use this guide. Please consider joining us as an individual or corporate member so that we can continue to produce materials like this testing guide and all the other great projects at OWASP. Thank you to all the past and future contributors to this guide, your work will help to make applications worldwide more secure. Jeff Williams OWASP Chair January 18, 2009