Recent Articles

Sysadmin Caught With Crazy Amount Of Stolen...
We've talked a lot about data theft in recent months, and now a mention of hardware theft seems worthwhile. It turns out, you see, that a system administrator managed to take 19,709 items from the U.S. Naval Research...

Do SysAdmins Steal Data?
With the unprecedented melt down of Lehman Brothers yesterday, a huge EDS layoff, and even eBay looking at layoffs, one has to ask, who is minding the store on customer records and customer data?

Beware Of Wordpress .htaccess Hack
Just quick heads up for anybody who may have any older Wordpress installs running to check their .htaccess file hasn't been hacked. I had this happen to a major...

Simple System Administration Guidelines
A system administrator's job isn't too straightforward, and there are probably hundreds, if not thousands, of tips that could be applied to all the duties. Here's a more manageable handful that will hopefully hit the...

City System Admin Locks Out Everyone
Terry Childs is cooling his jets in jail, while the city of San Francisco tries to get back control of its FiberWan network, this is why no one single person should ever have total access to anything. Dark reading...

Sys-Admin Services Lacking Social Software
Social Software technologies can improve collaboration and networking within and beyond the enterprise, but a general dearth of system and administrative services brings greater long-term risks as customers look...


10.30.08

Test Cases In Your Browser With Selenium

By Dan Morrill

One of the hardest things to do is build out automated test cases for testing the security of your web server. Building out test harnesses is a pain to do, but something that needs to be done not just to stress your web server, but to check on conditionals and security flaws or even not called API strings within the confines of the web server.

Selenium is a new Firefox plug-in that will help you build out test cases by running through the test case in your browser, and then having the plug in record your actions for dumping into a test case later on. The good part is that as you do your security scanning, you can use this product to build out a number of repeatable test harnesses looking for common security flaws in your web app. There is an excellent Google Education channel talk on this right here.


Improve your competitive advantage with the white papers in this eKit: Download Now

With Selenium now a Firefox plug-in, this will automate your test harnesses in the longer run with the more common body of tests that you do and how they build up in the repository that you use for common tests. There are tests that you should always run, by adding common security tests, for cross site scripting, for CSRF, for bad API calls, bad limit calls, calls that are in the API but never used in the actual web page, you can automated much of your security testing, and move the common tests off to the testing group.

This is a very much so needed process and tool for security engineers who are doing web page hacking. Worth checking out, much of the Selenium site is not functioning today as they are rebuilding it, but there are tons of good videos, good tips on how to use the tool, and a great two minute overview movie of the product.

Comments


About the Author:
Dan Morrill has been in the information security field for 18 years, both civilian and military, and is currently working on his Doctor of Management. Dan shares his insights on the important security issues of today through his blog, Managing Intellectual Property & IT Security, and is an active participant in the ITtoolbox blogging community.
About SysAdminNews
SysAdminNews is a collection of articles, news and commentary designed to keep system administrators informed about the latest trends impacting their profession. Updates and Advice for System Administrators





SysAdminNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
SysAdminNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITManagementNews.com





-- SysAdminNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2008 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


Database Forum Updates and Advice for System Administrators SysAdminNews News Archives About Us Feedback SysAdminNews.com About Article Archive News Downloads WebProWorld Forums iEntry Advertise Contact Jayde