Security testing sales, marketing websites |
 |
EXPERT RESPONSE FROM: Caleb Sima

|
 |
|


|
| > |
QUESTION POSED ON: 05 December 2008
When testing online sales and marketing software for vulnerabilities, is there a particular testing technique that should be used?
|
|
| > |
In general, no, there isn't a particular security testing technique for online sales and marketing software. The same vulnerabilities that affect all online applications apply the same for sales or marketing.
I will say, though, that the type of data that is considered "sensitive" changes. For example, marketing websites usually have a location where the public can view press releases. With many of these websites, when you view the press release and look at the URL will see something similar to this:
http://marketingsite.com/pressrelease.aspx?id=23
A common vulnerability that can exist here is that an attack can gain access to the press release before it is released to the public by just incrementing the ID in the URL, e.g., http://marketingsite.com/pressrelease.aspx?id=24, which although not public yet can now be viewed. I don't have to explain to you the impact of what that can cause.
|
|
|
');
// -->

|
|
 |

 |
 |
Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and
answer pairs from more than 250 TechTarget industry experts.
|
 |
 |
 |
|
 |
 |
 |
|
 |
|
 |