OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: The Owasp Project (owaspowasp.org)
Date: Mon Jan 21 2002 - 21:23:02 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    We have captured most of the dicsussion last week
    (white-box vs black box etc) although not yet got it
    up in the site. Give us a few weeks, things very
    hectic. So far I think we have a good first draft of
    most of the Why test ? What to test ? and How to
    test ? with an exception about how to plan a test. I
    know how I do it (paying special attention to legal
    contracts, project plans, permissions, laws etc) but
    it would be really good if other people share how
    they plan a test.

    We will get this first section written up by mid-Feb
    (with some details about Attack Trees so they can be
    used in descriptions) and we can then start the
    technical details about testing for specifics like
    cross site scripting etc

    So how do you plan a test ?