Web application penetration testing: Difference between revisions

Content deleted Content added
SmackBot (talk | contribs)
m Date the maintenance tags using AWB
RussBot (talk | contribs)
m Robot: Fixing double-redirect -"Penetration testing" +"Penetration test"
 
(3 intermediate revisions by 3 users not shown)
Line 1:
*#REDIRECT [[Penetration testingtest]]
{{Mergeto|penetration testing|date=December 2006}}
'''Web application penetration testing''' refers to a set of services used to detect various security issues with [[web applications]].
 
==Overview==
 
Enterprises across the world are performing their business on the web, yet only a meager percentage of websites are regularly and professionally tested for vulnerabilities. This increases the chances of website attacks and eventually leads to compromise of applications.
 
Web Application Penetration Testing services help identify issues related to:
 
* Vulnerabilities and risks in your web applications
* Known and unknown vulnerabilities (0-day) to combat against the threat until your security vendor provides the appropriate solution.
* Technical vulnerabilities: [[URL]] manipulation, [[SQL injection]], cross site scripting, back-end authentication, password in memory, session hijacking, web server configuration, credential management etc,
* Business Risks: Day-to-Day threat analysis, unauthorized logins, Personal information modification, pricelist modification, unauthorized funds transfer, breach of customer trust etc.
 
==See also==
 
* [[Penetration testing]]
 
[[Category:Web applications]]
[[Category:World Wide Web]]
 
 
{{computer-stub}}