Web Application Tests
The number of UK businesses transacting on-line is at an all-time high. Whether it is on-line retailers selling direct to consumers, or businesses providing extranet type services to their trading partners, there is a growing trend to bring more and more functionality to the Internet browser. Many of these transactions are delivered over secure HTTPS connection streams. Although this brings more security to the end user, it does mean that a malicious user can send encrypted traffic to the web server that cannot be seen by many traditional security controls.
|
|
||
|
||
|
|
||
|
Web Server Tests are designed to assess all types of web server, ranging from static brochure ware websites to all-encompassing transactional e-commerce environments. Nettitude focuses on looking at the application logic that has been built in to the website, and pays particular attention to any aspect of the environment that allows a user to enter input. Web Server tests will assess an environment for server side attacks such as SQL injection and Blind SQL injection. In addition tests will assess an environment for client side attacks, such as Cross Site Scripting exposures which could allow an attacker to manipulate the clients that access your infrastructure. Nettitude will assess the design of a web infrastructure, including the use of cookies and logon forms, as well as the way in which data is encrypted, the way in which content is displayed, and the error messages that are displayed when invalid pages, commands or input is entered in to the environment.
Nettitude can provide advice and guidance on how you can improve the security of your web application software. In many instance, we can provide software development services to fix application logic or write input validation controls to protect the environment from malicious Internet users. |
Nettitude can provide comprehensive testing of web 2.0 environments that make extensive use of AJAX and flash. We look to conduct client and server side tests of your environment including thick clients used to access published web services. Nettitude is a CREST organisation with rigorous methodology behind all of our testing programmes. To find out more about how Nettitude can help you with your Security Testing requirements, please complete our contact form, and a Consultant will respond to your enquiry. |
|
- Web Security Tests
- Database Penetration Tests
- VoIP Penetration Tests
- Wireless Penetration Tests
- VPN Penetration Tests
- BlackBerry Penetration Tests