Penetration Testing news, help and research - SearchSoftwareQuality.com

Penetration Testing

  • SQL injection flaw is a welcome mat for black hats on file-sharing site

    Recently, a group of hackers was able to gain access to user's personal files on a file-sharing site via SQL injection flaws. The group was able to view and edit personal information further proving that SQL injection is a major problem. 

  • VisibleThread aims to boost IT documentation quality, improve processes

    Start-up VisibleThread's new document structure and quality analysis tool has uses ranging from requirements management to documentation quality enforcer. VisibleThread's software structure and quality detection capabilities can improve development a... 

  • Blueprint rolls out Requirements Center 2010

    Blueprint Requirements Center 2010 from Toronto-based Blueprint launched this week with new features targeting the needs of distributed teams and offering enhanced stakeholder collaboration. According to Tony Higgins, VP of products at Blueprint, fou... 

  • Agile aims to bridge software requirements communications gap

    Agile software development bridges the software requirements communications gap by embracing flexibility and face-to-face communication rather than depending on documents to communicate, agile practitioners say. 

  • Software requirements sign-off essential for solid QA

    Not properly signing off on a software project's requirements limits the quality assurance (QA) team's ability to ensure that the software does as it's intended. 

  • Poor business requirements process leads to high project costs, study finds

    A recent IAG Consulting study finds that companies that have poor business requirements processes can expect to spend 49% more money and 39% more time on a project. 

  • From use case diagrams to context diagrams

    It's tempting to consider use case diagrams as context diagrams because they do show context. But having one diagram for both will result in an unreadable cloud of bubbles. 

  • Agile development: Don't forget the documentation

    Eliminating documentation may speed software development, but it will create problems at the end as supporting groups try to figure out what the product actually does. 

  • The pros and cons of use case diagrams

    Putting too much into a use case diagram can often render the otherwise useful technique of use cases almost useless. Kevlin Henney recommends a more balanced and restrained approach in order to not lose readers in a myriad of bubbles and microscopic... 

  • How to document use cases

    Ideally use cases capture the functional requirements of a system in terms of identifiable and testable goals. The trick is writing and documenting them so that they offer value not just for requirements gathering but also for software design and tes... 

  • See More: News on Penetration Testing
  • requirements analysis (requirements engineering)

    Requirements analysis, also called requirements engineering, is the process of determining user expectations for a new or modified product... (Continued) 

  • Wirth's Law

    Wirth's Law states that computer software increases in complexity faster than does the ability of available hardware to run it... (Continued) 

  • software requirements specification (SRS)

    A software requirements specification (SRS) is a comprehensive description of the intended purpose and environment for software under development. The SRS fully describes what the software will do and how it will be expected to perform... (Continued)... 

  • Software Engineering Institute (SEI)

    The Software Engineering Institute (SEI) is a research, development and training center involved in computer software and network security. The SEI works with industry, academic institutions and the United States government to improve the performance... 

  • functional specification

     

About Penetration Testing

Penetration testing is a method of testing to simulate a breach of security or an attack from a malicious source. The system is analyzed for potential weaknesses or vulnerabilities and examined from the viewpoint of a potential attacker. The testing will work to actively exploit security vulnerabilities and will report back to the system owner risks, feasibility for an attack, and recommended steps to mitigate the risks of an attack. Penetration testing can be performed as a white-box test, where system internals are known, or as a black-box test, which would be similar to a malicious user with no knowledge of the infrastructure being tested.