Exploring Security in Day-to-day Testing
10th October 2023
-
Locked
Richard Adams
Senior Test Analyst
Talk Description
Security testing sounds like it might be best left to the “experts”, whoever they are, but I will share how we can include it in our day-to-day testing. From exploratory testing to API and automated testing, there are things that we can and should be doing.
Through my talk, I will share how I’ve learnt how my time spent on training courses and taking part in challenges has shown me that security testing is perfect for the exploratory tester. We will learn some basic techniques using just our browsers and also how free tools can help us along the way.
Through my talk, I will share how I’ve learnt how my time spent on training courses and taking part in challenges has shown me that security testing is perfect for the exploratory tester. We will learn some basic techniques using just our browsers and also how free tools can help us along the way.
By the end of this session, you'll be able to:
- Describe what XSS, SQL injection and elevation of privilege attacks are
- Recognise that security testing is something that they can & should be doing
- Identify the "low hanging fruit" security bugs in their software
- Execute penetration tests against an online system (workshop/activity only)
Richard Adams
Senior Test Analyst
He / Him
Passionate about quality & testing. Creator of Threat Agents card game and regularly found chatting cyber security.
Sign in
to comment
Suggested Content
Create E2E tests visually. Get clear, readable YAML you can actually maintain.
Explore MoT
Thu, 19 Feb
In this webinar, Parasoft experts will discuss what to look for when selecting an AI-powered API testing solution.
Learn how to recognise cognitive biases, explain what they are and use them to your advantage in your testing
Debrief the week in Quality via a community radio show hosted by Simon Tomes and members of the community