ROYAL TRAVELS. - Book Taxi Oneway, Multicity Round Trips, Local and Outstation Taxis, South India Tour Packages in Online, Coimbatore Taxi, Ooty Taxi, Cabs / Taxi / Car Rental Services in Coimbatore, Ooty, Munnar, Kodaikanal, Bangalore, Madurai, Chennai, Rameshwaram, Kanyakumari Tours Travels and Hotel Packages
  •  
    • Customer Login
    • Travel Agent Login
  • Enquiry
  • Payment
  • Cancellation
  • 24X7 Call : +91 73738 12345
  • Online Cab Booking
  • Home
  • Tariff
    • Local Tariff - (Hour Basis)
    • Out Station Tariff - (Day Basis)
    • Out Station Tariff - (Km Basis)
    • One Way Dropping (Fixed)
    • One Way Dropping (Km Basis)
    • Corporate Bookings
  • Tour Packages
    • One Day Tour Packages
    • Two Days Tour Packages
    • Three Days Tour Packages
    • Four Days Tour Packages
    • Five Days Tour Packages
    • Six Days Tour Packages
    • Seven Days Tour Packages
    • Eight Days Tour Packages
    • Nine Days Tour Packages
    • Honey Moon Packages
    • Navagraha Temple Packages
    • Coimbatore Temple Packages
    • Pilgrimage Tour Packages
    • Customized Tour Package
  • Tour Planner
  • Hotel
  • Booking Status
  • Testimonials
  • Tour Info
  • Contact us

Coimbatore Taxi Home >> News & Promotions

About Security Testing

News & Promotions

About Security Testing
21-Sep-2012.

COIMBATORETAXI NEWS

 

Some key terms used in security testing

What is “Vulnerability”?
This is a weakness in the web application. The cause of such a “weakness” can be bugs in the application, an injection (SQL/ script code) or the presence of viruses.

What is “URL manipulation”?
Some web applications communicate additional information between the client (browser) and the server in the URL. Changing some information in the URL may sometimes lead to unintended behavior by the server.

What is “SQL injection”?
This is the process of inserting SQL statements through the web application user interface into some query that is then executed by the server.

What is “XSS (Cross Site Scripting)”?
When a user inserts HTML/ client-side script in the user interface of a web application and this insertion is visible to other users, it is called XSS.

What is “Spoofing”?
The creation of hoax look-alike websites or emails is called spoofing.
Security testing approach:

In order to perform a useful security test of a web application, the security tester should have good knowledge of the HTTP protocol. It is important to have an understanding of how the client (browser) and the server communicate using HTTP. Additionally, the tester should at least know the basics of SQL injection and XSS. Hopefully, the number of security defects present in the web application will not be high. However, being able to accurately describe the security defects with all the required details to all concerned will definitely help.

1. Password cracking:

The security testing on a web application can be kicked off by “password cracking”. In order to log in to the private areas of the application, one can either guess a username/ password or use some password cracker tool for the same. Lists of common usernames and passwords are available along with open source password crackers. If the web application does not enforce a complex password (e.g. with alphabets, number and special characters, with at least a required number of characters), it may not take very long to crack the username and password.

If username or password is stored in cookies without encrypting, attacker can use different methods to steal the cookies and then information stored in the cookies like username and password.

For more details see article on “Website cookie testing”.

2. URL manipulation through HTTP GET methods:

The tester should check if the application passes important information in the querystring. This happens when the application uses the HTTP GET method to pass information between the client and the server. The information is passed in parameters in the querystring. The tester can modify a parameter value in the querystring to check if the server accepts it.

Via HTTP GET request user information is passed to server for authentication or fetching data. Attacker can manipulate every input variable passed from this GET request to server in order to get the required information or to corrupt the data. In such conditions any unusual behavior by application or web server is the doorway for the attacker to get into the application.

3. SQL Injection:

The next thing that should be checked is SQL injection. Entering a single quote (‘) in any textbox should be rejected by the application. Instead, if the tester encounters a database error, it means that the user input is inserted in some query which is then executed by the application. In such a case, the application is vulnerable to SQL injection.

SQL injection attacks are very critical as attacker can get vital information from server database. To check SQL injection entry points into your web application, find out code from your code base where direct MySQL queries are executed on database by accepting some user inputs.

If user input data is crafted in SQL queries to query the database, attacker can inject SQL statements or part of SQL statements as user inputs to extract vital information from database. Even if attacker is successful to crash the application, from the SQL query error shown on browser, attacker can get the information they are looking for. Special characters from user inputs should be handled/escaped properly in such cases.

4. Cross Site Scripting (XSS):

The tester should additionally check the web application for XSS (Cross site scripting). Any HTML e.g. <HTML> or any script e.g. <SCRIPT> should not be accepted by the application. If it is, the application can be prone to an attack by Cross Site Scripting.

Attacker can use this method to execute malicious script or URL on victim’s browser. Using cross-site scripting, attacker can use scripts like JavaScript to steal user cookies and information stored in the cookies.

Many web applications get some user information and pass this information in some variables from different pages.

E.g.: http://www.examplesite.com/index.php?userid=123&query=xyz

Attacker can easily pass some malicious input or <script> as a ‘&query’ parameter which can explore important user/server data on browser.

Important: During security testing, the tester should be very careful not to modify any of the following:

  •  Configuration of the application or the server
  •  Services running on the server
  •  Existing user or customer data hosted by the application

Additionally, a security test should be avoided on a production system.

The purpose of the security test is to discover the vulnerabilities of the web application so that the developers can then remove these vulnerabilities from the application and make the web application and data safe from unauthorized actions.

COIMBATORETAXI NEWS




Back to Home Page  |   Back to NEWS List


Our Tariffs
  • Local Tariff - (Hour Basis)
  • Out Station Tariff - (Day Basis)
  • Out Station Tariff - (Km Basis)
  • One Way Dropping - (Fixed)
  • One Way Dropping - (Km Basis)
  • Corporate Bookings
Tour Packages
  • One Day Tour Packages
  • Two Days Tour Packages
  • Three Days Tour Packages
  • Four Days Tour Packages
  • Five Days Tour Packages
  • Six Days Tour Packages
  • Seven Days Tour Packages
  • Eight Days Tour Packages
  • Nine Days Tour Packages
  • Honey Moon Packages
  • Navagraha Temple Packages
  • Coimbatore Temple Packages
  • Pilgrimage Tour Packages
  • Customized Tour Package
Testimonial

Dr divya

  • posted by
  • 2023-04-15

Wonderful experience booking wd royal travels coimbatore to ooty in ac innova neat n clean very well maintained wd highly recommend dis travels Last but not d least many many thanks to our driver Mr Muvendran a very decent humble human being who showed us all d points explaining in wonderful way His Driving skill was EXCELLENT Above all he was very Caring Wud definitely book wd U again Royal Travels n wud like to avail f services of Mr Muvendran

Readmore

POOJA MANGUKIA

  • posted by
  • 2022-11-27

I hired a taxi for 2 days to cover all the local temples in Coimbatore and Ooty as well. The car was in good condition. Mr. Satish was our driver and he is very good driver also he explained us all the places along with the history behind the place. The journey was very safe for me and my family. I am fully satisfied with all the services. One can also hire a cab from Royal Travels. They are providing hassle free services.

Readmore

Sudish C S

  • posted by
  • 2022-11-20

I would like to thank Royal Travels & Mr. Sravanan (the driver) for the excellent service provided during our visit to Palani Temple from Coimbatore & back on 11/11/2022. I was travelling along with my mother & aunty (both senior citizens). We were provided with Toyota Innova, which was in excellent condition. As far as Mr. Sravanan - our driver is concerned, he is very humble, having good control over driving and lot of patience. Also Mr. Sravanan has good knowledge of the route and restaurants I will recommended Royal Travels & Mr. Sravanan for their excellent service.

Readmore

News & Promotions
  • posted by
  • 2023-02-07

Coimbatore Railway station to Isha Yoga Center Cab Fare:

Read more



Quick Links
  • About Us
  • Testimonial
  • Payment
  • Cancellation
  • Terms & Conditions
  • Cancel & Refund Policy
  • Privacy Policy
  • Disclaimer Policy
  • Privacy Policy For Payment Through Razorpay
Book Taxi
  • Ooty Taxi
  • Mysore Taxi
  • Kodaikanal Taxi
  • Tirupur Taxi
  • Munnar Taxi
  • Madurai Taxi
  • Rameshwaram Taxi
  • Kozhikode Taxi
  • Tiruchirappalli Taxi
  • Chennai Taxi
Cab Booking
  • Karur Taxi
  • Erode Taxi
  • Trichy Taxi
  • Bengaluru Taxi
  • Palani Taxi
  • Kanyakumari Taxi
  • Mettupalayam Taxi
  • Dindigul Taxi
  • Kumbakonam Taxi
  • Hyderabad Taxi
Taxi Services
  • Cochin Taxi
  • Coonoor Taxi
  • Guruvayur Taxi
  • Trivandrum Taxi
  • Thiruchendur Taxi
  • Thekkady Taxi
  • Coimbatore Taxi
  • Tiruvannamalai Taxi
  • Kanchipuram Taxi
  • Coorg Taxi
Car Rental
  • Wayanad Taxi
  • Yercuad Taxi
  • Valparai Taxi
  • Sabarimala Taxi
  • Nagercoil Taxi
  • Topslip Taxi
  • Thoothukudi Taxi
  • Tirunelveli Taxi
  • Puducherry Taxi
  • Pollachi Taxi
Packages
  • Palakkad Taxi
  • Tirupati Taxi
  • Tirunelveli Taxi
  • Thrissur Taxi
  • Salem Taxi
  • Pondicherry Airport
  • Namakkal Taxi
  • Madurai Airport
  • Coimbatore Airport
  • Topslip Resorts

All cards payment & UPI are accepted

Copyright © 2008-2022 - Royal Travels, All Rights Reserved

Send WP Details