Security Assessment.

We provide information testing, initial tests, reports & post-hardening tests.

2

Security Posture Assessment (SPA).

To perform simulated load testing to identify the crash point or the point where the perceptible slowdown is noticed in the request processing.

  • To address OWASP Top 10 Vulnerability:
  1. Injection
  2. Broken Authentication and Session Management (XSS)
  3. Cross Site Scripting (XSS)
  4. Insecure Direct Object References
  5. Security Misconfiguration
  6. Sensitive Data Exposure
  7. Missing Function Level Access Control
  8. Cross Site Request Forgery (CSRF)
  9. Using Components with Known Vulnerabilities
  10. Unvalidated Redirects and Forwards

Penetration Test 

  • To identify:
  1. Common Holes in Web
  2. Bad Password
  3. Directory Traversal
  4. Old Directory/Folder
  5. SQL/MySQL injection
  6. Blind SQL/ MySQL injection – Cross site scripting
  7. Cross site forgery
  8. Bad Configuration
  9. CGI-BIN Exploit & etc.
  • To identify:
  1. Network Mis-configuration
  2. Open Port In Client Network – Unknown Port
  3. Weird Connections
  4. Firewall Configurations & etc.

Server Security Assessment 

  • to identify:
  1. Weak Server Configuration
  2. Weak Password Implementation
  3. Unpatched services
  4. Old Account
  5. Unused account
  6. Possible Denial of Service (DOS/DDOS) & etc.

 

Database Security Assessment

  • to identify:
  1. SQL/MySQL/Oracle/MS Access/Postgres
  2. Default configuration (setting & setup)
  3. Connection settings
  4. Database settings
  5. User Account settings & etc.