
Rp 7.800.000
Teras Digital Pro Media
Indonesia, Indonesia
<p><div class="blog-content"> <p><span style="color:rgb(120,125,133);">Web Application Penetration Testing services are derived from the the Open Web Application Security Project (OWASP) and heavily augmented by Real Time Dynamic Testing. OWASP is the de facto standard for designing and testing secure web applications. Netragard focuses on key areas of OWASP that include but are not limited to the following:</span><br/></p><p><span style="font-weight:bold;">A1 Injection</span></p><p>Can we send malicious code/scripts to the system?</p><p><br/></p><p><span style="font-weight:bold;">A2 Broken Authentication and Session Management</span></p><p>Secure authentication is hard. Can we exploit parts of the app, like: Logout, password management, timeouts, remember me, secret questions, account update, etc.</p><p><br/></p><p><span style="font-weight:bold;">A3 Cross-Site Scripting (XSS)</span></p><p>Can we untrusted data to exploit the interpreter in the browser? The most wide spread web application security flaw.</p><p><br/></p><p><span style="font-weight:bold;">A4 Insecure Direct Object Reference</span></p><p>Can we change parameters to gain access to unauthorized objects?</p><p><br/></p><p><span style="font-weight:bold;">A5 Security Misconfiguration</span></p><p>Can we access default accounts, unused pages, unpatched flaws, unprotected files or directories, etc. to gain unauthorized access to or knowledge of the system.</p><p><br/></p><p><span style="font-weight:bold;">A6 Sensitive Data Exposure</span></p><p>Can we get unencrypted or weakly encrypted sensitive data by a man in the middle attack, exploiting the browser, stealing keys, interception clear text in transit, etc.</p><p><br/></p><p><span style="font-weight:bold;">A7 Missing Function Level Access Control</span></p><p>Is access granted when a user changes parameters to access privileged functions?</p><p><br/></p><p><span style="font-weight:bold;">A8 Cross-Site Request Forgery (CSRF)</span></p><p>Can we forge an HTTP request and trick users into submitting them?</p><p><br/></p><p><span style="font-weight:bold;">A9 Using Components with Known Vulnerabilities</span></p><p>Can we use scanning or manual analysis to find a weak or bad components?</p><p><br/></p><p><span style="font-weight:bold;">A10 Invalid Redirects and Forwards</span></p><p>Can we use the system to redirect or forward the user to a phishing site or malicious URL?</p></div></p>