# Check the URL셲 encryption. Except main page all other branches and sensitive pages should be encrypted in URL
# Check the Cookies, all sensitive cookies should be removed automatically when the application get closed
# Sensitive information stored in the cookies must be encrypted
# For authentication kind of site, the cache must be cleared on exit
# If we edit the cookies while the application is on run, then it should not affect the system; instead it should restore its original (proper) state when the next action happens in the application
# All password and user셲 sensitive information transaction should be encrypted
# Encryption should be in the simple way to identify. Typically it should be the mix of special characters, numerals and alphabets(both cases A/a)
# Folder level access should not be allowed. Eg: if the url opens a page inside a specific folder, then if any one deleted the file name and tried with that folder name should not be able to open that folder
# Internal and external IP address mapped with the URL should be secured.

Share
Related Documents
  1. [Free] WebGoat : Security Testing Tool (2332)
  2. [Ebook] Linux 101 Hacks (2750)
  3. OWASP Top 10 - 2010 (Security Testing) (1900)
  4. Password Recovery for Security Testing (1525)
  5. New Advanced SQL Injection For Advanced Security Testing (1889)
  6. Security Testing Reference : SQL Injection (2348)
  7. [Ebook] Google Hacks : 2nd Edition (2576)
  8. [Ebook] Hacker Attack (2781)
  9. [Free] Security Software Testing Suite (SSTS) : Application-based security testing (1842)
  10. Using JTest for Security Testing (2222)
  11. Security Testing Reference : Cross-Site Scripting (XSS) (2261)
  12. How to Secure CXF Web Services with SSL/TLS and WS-Security (1665)
  13. Putting Security Into Your Virtual World (668)
  14. OWASP Testing Guide (2618)
  15. 2010-10-27, SecureWorld Expo @ USA (1542)
  16. [Paid] Sunbelt Network Security Inspector : Network Vulnerability Assessment Scanning (1629)
  17. SQL - injection: How to Test web applications against SQL attacks (2272)
  18. [Video] Software Security Testing: Strengthening Your Defense Strategy (906)
  19. Software Security: Building Security In (980)
  20. Types of Web Security Testing? (1235)