<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Jopi</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Jopi"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Jopi"/>
		<updated>2026-05-28T08:40:57Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Testing_Guide_v2_Table_of_Contents&amp;diff=16471</id>
		<title>OWASP Testing Guide v2 Table of Contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Testing_Guide_v2_Table_of_Contents&amp;diff=16471"/>
				<updated>2007-02-14T11:43:03Z</updated>
		
		<summary type="html">&lt;p&gt;Jopi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
==[[Testing Guide Foreword|Foreword by OWASP Chair]]==&lt;br /&gt;
&lt;br /&gt;
==[[Testing Guide Frontispiece |1. Frontispiece]]==&lt;br /&gt;
&lt;br /&gt;
'''[[Testing Guide Frontispiece|1.1 About the OWASP Testing Guide Project]]'''&lt;br /&gt;
&lt;br /&gt;
1.1.1 Copyright&lt;br /&gt;
&lt;br /&gt;
1.1.2 Editors&lt;br /&gt;
&lt;br /&gt;
1.1.3 Authors and Reviewers&lt;br /&gt;
&lt;br /&gt;
1.1.4 Revision History&lt;br /&gt;
&lt;br /&gt;
1.1.5 Trademarks&lt;br /&gt;
&lt;br /&gt;
'''[[About The Open Web Application Security Project|1.2 About The Open Web Application Security Project]]'''&lt;br /&gt;
&lt;br /&gt;
1.2.1 Overview&lt;br /&gt;
&lt;br /&gt;
1.2.2 Structure&lt;br /&gt;
&lt;br /&gt;
1.2.3 Licensing&lt;br /&gt;
&lt;br /&gt;
1.2.4 Participation and Membership&lt;br /&gt;
&lt;br /&gt;
1.2.5 Projects&lt;br /&gt;
&lt;br /&gt;
1.2.6 OWASP Privacy Policy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[Testing Guide Introduction|2. Introduction]]==&lt;br /&gt;
&lt;br /&gt;
'''2.1 The OWASP Testing Project'''&lt;br /&gt;
&lt;br /&gt;
'''2.2 Principles of Testing'''&lt;br /&gt;
&lt;br /&gt;
'''2.3 Testing Techniques Explained''' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[The OWASP Testing Framework|3. The OWASP Testing Framework]]==&lt;br /&gt;
&lt;br /&gt;
'''3.1. Overview'''&lt;br /&gt;
&lt;br /&gt;
'''3.2. Phase 1: Before Development Begins '''&lt;br /&gt;
&lt;br /&gt;
'''3.3. Phase 2: During Definition and Design'''&lt;br /&gt;
&lt;br /&gt;
'''3.4. Phase 3: During Development'''&lt;br /&gt;
&lt;br /&gt;
'''3.5. Phase 4: During Deployment'''&lt;br /&gt;
&lt;br /&gt;
'''3.6. Phase 5: Maintenance and Operations'''&lt;br /&gt;
&lt;br /&gt;
'''3.7. A Typical SDLC Testing Workflow '''&lt;br /&gt;
&lt;br /&gt;
==[[Web Application Penetration Testing |4. Web Application Penetration Testing ]]==&lt;br /&gt;
&lt;br /&gt;
[[Testing: Introduction and objectives|'''4.1 Introduction and Objectives''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing: Information Gathering|'''4.2 Information Gathering''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Web Application Fingerprint|4.2.1 Testing Web Application Fingerprint]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Application Discovery|4.2.2 Application Discovery]]&lt;br /&gt;
&lt;br /&gt;
[[Testing: Spidering and googling|4.2.3 Spidering and Googling]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Error Code|4.2.4 Analysis of Error Codes]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for infrastructure configuration management|4.2.5 Infrastructure &lt;br /&gt;
Configuration Management Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SSL-TLS|4.2.5.1 SSL/TLS Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DB Listener|4.2.5.2 DB Listener Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for application configuration management|4.2.6 Application Configuration Management Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for file extensions handling|4.2.6.1 Testing for File Extensions Handling]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for old_file|4.2.6.2 Old, backup and unreferenced files]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for business logic|'''4.3 Business Logic Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for authentication|'''4.4 Authentication Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Default or Guessable User Account|4.4.1 Testing for Guessable (Dictionary) User Account]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Brute Force|4.4.2 Brute Force Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Bypassing Authentication Schema|4.4.3 Testing for bypassing authentication schema]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Directory Traversal|4.4.4 Testing for directory traversal/file include]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Vulnerable Remember Password and Pwd Reset|4.4.5 Testing for vulnerable remember &lt;br /&gt;
password and pwd reset]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Logout and Browser Cache Management|4.4.6 Testing for Logout and Browser Cache Management Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Session Management|'''4.5 Session Management Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Session_Management_Schema|4.5.1 Testing for Session Management Schema]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Cookie and Session Token Manipulation|4.5.2 Testing for Cookie and Session Token Manipulation]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Exposed Session Variables|4.5.3 Testing for Exposed Session Variables ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for CSRF|4.5.4 Testing for CSRF]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for HTTP Exploit|4.5.5 Testing for HTTP Exploit ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Data Validation|'''4.6 Data Validation Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Cross site scripting|4.6.1 Testing for Cross Site Scripting]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for HTTP Methods and XST|4.6.1.1 Testing for HTTP Methods and XST ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SQL Injection|4.6.2 Testing for SQL Injection ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Oracle|4.6.2.1 Oracle Testing ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for MySQL|4.6.2.2 MySQL Testing ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SQL Server|4.6.2.3 SQL Server Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for LDAP Injection|4.6.3 Testing for LDAP Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for ORM Injection|4.6.4 Testing for ORM Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XML Injection|4.6.5 Testing for XML Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SSI Injection|4.6.6 Testing for SSI Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XPath Injection|4.6.7 Testing for XPath Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for IMAP/SMTP Injection|4.6.8 IMAP/SMTP Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Code Injection|4.6.9 Testing for Code Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Command Injection|4.6.10 Testing for Command Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Buffer Overflow|4.6.11 Testing for Buffer overflow]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Heap Overflow|4.6.11.1 Testing for Heap overflow]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Stack Overflow|4.6.11.2 Testing for Stack overflow]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Format String|4.6.11.3 Testing for Format string]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Incubated Vulnerability|4.6.12 Testing for incubated vulnerabilities]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Denial of Service|'''4.7 Testing for Denial of Service''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS Locking Customer Accounts|4.7.1 Testing for DoS Locking Customer Accounts]]	&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS Buffer Overflows|4.7.2 Testing for DoS Buffer Overflows]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS User Specified Object Allocation|4.7.3 Testing for DoS User Specified Object Allocation]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for User Input as a Loop Counter|4.7.4 Testing for User Input as a Loop Counter]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Writing User Provided Data to Disk|4.7.5 Testing for Writing User Provided Data to Disk]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS Failure to Release Resources|4.7.6 Testing for DoS Failure to Release Resources]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Storing too Much Data in Session|4.7.7 Testing for Storing too Much Data in Session]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Web Services|'''4.8 Web Services Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XML Structural|4.8.1 XML Structural Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XML Content-Level|4.8.2 XML Content-level Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for WS HTTP GET parameters/REST attacks|4.8.3 HTTP GET parameters/REST Testing ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Naughty SOAP Attachments|4.8.4 Testing for Naughty SOAP attachments]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for WS Replay|4.8.5 WS Replay Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing_for_AJAX:_introduction|'''4.9 AJAX Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for AJAX Vulnerabilities|4.9.1 AJAX Vulnerabilities]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for AJAX|4.9.2 How to test AJAX]]&lt;br /&gt;
&lt;br /&gt;
==[[Writing Reports: value the real risk |5. Writing Reports: value the real risk ]]==&lt;br /&gt;
&lt;br /&gt;
[[How to value the real risk |5.1 How to value the real risk]]&lt;br /&gt;
&lt;br /&gt;
[[How to write the report of the testing |5.2 How to write the report of the testing]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[Appendix A: Testing Tools |Appendix A: Testing Tools ]]==&lt;br /&gt;
&lt;br /&gt;
* Black Box Testing Tools&lt;br /&gt;
* Source Code Analyzers&lt;br /&gt;
* Other Tools&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[OWASP Testing Guide Appendix B: Suggested Reading | Appendix B: Suggested Reading]]==&lt;br /&gt;
* Whitepapers&lt;br /&gt;
* Books&lt;br /&gt;
* Useful Websites&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[OWASP Testing Guide Appendix C: Fuzz Vectors | Appendix C: Fuzz Vectors]]==&lt;br /&gt;
&lt;br /&gt;
* Fuzz Categories&lt;br /&gt;
** Recursive fuzzing&lt;br /&gt;
** Replasive fuzzing&lt;br /&gt;
* Cross Site Scripting (XSS)&lt;br /&gt;
* Buffer Overflows and Format String Errors&lt;br /&gt;
** Buffer Overflows (BFO)&lt;br /&gt;
** Format String Errors (FSE)&lt;br /&gt;
** Integer Overflows (INT)&lt;br /&gt;
* SQL Injection&lt;br /&gt;
** Passive SQL Injection (SQP)&lt;br /&gt;
** Active SQL Injection (SQI)&lt;br /&gt;
* LDAP Injection&lt;br /&gt;
* XPATH Injection&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Testing Project]]&lt;/div&gt;</summary>
		<author><name>Jopi</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Testing_Guide_v2_Table_of_Contents&amp;diff=16470</id>
		<title>OWASP Testing Guide v2 Table of Contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Testing_Guide_v2_Table_of_Contents&amp;diff=16470"/>
				<updated>2007-02-14T11:40:26Z</updated>
		
		<summary type="html">&lt;p&gt;Jopi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
==[[Testing Guide Foreword|Foreword by OWASP Chair]]==&lt;br /&gt;
&lt;br /&gt;
==[[Testing Guide Frontispiece |1. Frontispiece]]==&lt;br /&gt;
&lt;br /&gt;
'''[[Testing Guide Frontispiece|1.1 About the OWASP Testing Guide Project]]'''&lt;br /&gt;
&lt;br /&gt;
1.1.1 Copyright&lt;br /&gt;
&lt;br /&gt;
1.1.2 Editors&lt;br /&gt;
&lt;br /&gt;
1.1.3 Authors and Reviewers&lt;br /&gt;
&lt;br /&gt;
1.1.4 Revision History&lt;br /&gt;
&lt;br /&gt;
1.1.5 Trademarks&lt;br /&gt;
&lt;br /&gt;
'''[[About The Open Web Application Security Project|1.2 About The Open Web Application Security Project]]'''&lt;br /&gt;
&lt;br /&gt;
1.2.1 Overview&lt;br /&gt;
&lt;br /&gt;
1.2.2 Structure&lt;br /&gt;
&lt;br /&gt;
1.2.3 Licensing&lt;br /&gt;
&lt;br /&gt;
1.2.4 Participation and Membership&lt;br /&gt;
&lt;br /&gt;
1.2.5 Projects&lt;br /&gt;
&lt;br /&gt;
1.2.6 OWASP Privacy Policy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[Testing Guide Introduction|2. Introduction]]==&lt;br /&gt;
&lt;br /&gt;
'''2.1 The OWASP Testing Project'''&lt;br /&gt;
&lt;br /&gt;
'''2.2 Principles of Testing'''&lt;br /&gt;
&lt;br /&gt;
'''2.3 Testing Techniques Explained''' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[The OWASP Testing Framework|3. The OWASP Testing Framework]]==&lt;br /&gt;
&lt;br /&gt;
'''3.1. Overview'''&lt;br /&gt;
&lt;br /&gt;
'''3.2. Phase 1: Before Development Begins '''&lt;br /&gt;
&lt;br /&gt;
'''3.3. Phase 2: During Definition and Design'''&lt;br /&gt;
&lt;br /&gt;
'''3.4. Phase 3: During Development'''&lt;br /&gt;
&lt;br /&gt;
'''3.5. Phase 4: During Deployment'''&lt;br /&gt;
&lt;br /&gt;
'''3.6. Phase 5: Maintenance and Operations'''&lt;br /&gt;
&lt;br /&gt;
'''3.7. A Typical SDLC Testing Workflow '''&lt;br /&gt;
&lt;br /&gt;
==[[Web Application Penetration Testing |4. Web Application Penetration Testing ]]==&lt;br /&gt;
&lt;br /&gt;
[[Testing: Introduction and objectives|'''4.1 Introduction and Objectives''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing: Information Gathering|'''4.2 Information Gathering''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Web Application Fingerprint|4.2.1 Testing Web Application Fingerprint]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Application Discovery|4.2.2 Application Discovery]]&lt;br /&gt;
&lt;br /&gt;
[[Testing: Spidering and googling|4.2.3 Spidering and Googling]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Error Code|4.2.4 Analysis of Error Codes]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for infrastructure configuration management|4.2.5 Infrastructure &lt;br /&gt;
Configuration Management Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SSL-TLS|4.2.5.1 SSL/TLS Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DB Listener|4.2.5.2 DB Listener Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for application configuration management|4.2.6 Application Configuration Management Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for file extensions handling|4.2.6.1 Testing for File Extensions Handling]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for old_file|4.2.6.2 Old, backup and unreferenced files]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for business logic|'''4.3 Business Logic Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for authentication|'''4.4 Authentication Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Default or Guessable User Account|4.4.1 Testing for Guessable (Dictionary) User Account]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Brute Force|4.4.2 Brute Force Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Bypassing Authentication Schema|4.4.3 Testing for bypassing authentication schema]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Directory Traversal|4.4.4 Testing for directory traversal/file include]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Vulnerable Remember Password and Pwd Reset|4.4.5 Testing for vulnerable remember &lt;br /&gt;
password and pwd reset]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Logout and Browser Cache Management|4.4.6 Testing for Logout and Browser Cache Management Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Session Management|'''4.5 Session Management Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Session_Management_Schema|4.5.1 Testing for Session Management Schema]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Cookie and Session Token Manipulation|4.5.2 Testing for Cookie and Session Token Manipulation]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Exposed Session Variables|4.5.3 Testing for Exposed Session Variables ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for CSRF|4.5.4 Testing for CSRF]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for HTTP Exploit|4.5.5 Testing for HTTP Exploit ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Data Validation|'''4.6 Data Validation Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Cross site scripting|4.6.1 Testing for Cross Site Scripting]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for HTTP Methods and XST|4.6.1.1 Testing for HTTP Methods and XST ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SQL Injection|4.6.2 Testing for SQL Injection ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Oracle|4.6.2.1 Oracle Testing ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for MySQL|4.6.2.2 MySQL Testing ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SQL Server|4.6.2.3 SQL Server Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for LDAP Injection|4.6.3 Testing for LDAP Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for ORM Injection|4.6.4 Testing for ORM Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XML Injection|4.6.5 Testing for XML Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for SSI Injection|4.6.6 Testing for SSI Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XPath Injection|4.6.7 Testing for XPath Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for IMAP/SMTP Injection|4.6.8 IMAP/SMTP Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Code Injection|4.6.9 Testing for Code Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Command Injection|4.6.10 Testing for Command Injection]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Buffer Overflow|4.6.11 Testing for Buffer overflow]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Heap Overflow|4.6.11.1 Testing for Heap overflow]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Stack Overflow|4.6.11.2 Testing for Stack overflow]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Format String|4.6.11.3 Testing for Format string]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Incubated Vulnerability|4.6.12 Testing for incubated vulnerabilities]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Denial of Service|'''4.7 Testing for Denial of Service''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS Locking Customer Accounts|4.7.1 Testing for DoS Locking Customer Accounts]]	&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS Buffer Overflows|4.7.2 Testing for DoS Buffer Overflows]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS User Specified Object Allocation|4.7.3 Testing for DoS User Specified Object Allocation]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for User Input as a Loop Counter|4.7.4 Testing for User Input as a Loop Counter]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Writing User Provided Data to Disk|4.7.5 Testing for Writing User Provided Data to Disk]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for DoS Failure to Release Resources|4.7.6 Testing for DoS Failure to Release Resources]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Storing too Much Data in Session|4.7.7 Testing for Storing too Much Data in Session]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Web Services|'''4.8 Web Services Testing''']]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XML Structural|4.8.1 XML Structural Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for XML Content-Level|4.8.2 XML Content-level Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for WS HTTP GET parameters/REST attacks|4.8.3 HTTP GET parameters/REST Testing ]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for Naughty SOAP Attachments|4.8.4 Testing for Naughty SOAP attachments]]&lt;br /&gt;
&lt;br /&gt;
[[Testing for WS Replay|4.8.5 WS Replay Testing]]&lt;br /&gt;
&lt;br /&gt;
[[Pruebas_de_AJAX:_introduccion|'''4.9 Pruebas de AJAX''']]&lt;br /&gt;
&lt;br /&gt;
[[Pruebas de Vulnerabilidades de AJAX|4.9.1 Vulnerabilidades en AJAX]]&lt;br /&gt;
&lt;br /&gt;
[[Pruebas en AJAX|4.9.2 Como probar AJAX]]&lt;br /&gt;
&lt;br /&gt;
==[[Writing Reports: value the real risk |5. Writing Reports: value the real risk ]]==&lt;br /&gt;
&lt;br /&gt;
[[How to value the real risk |5.1 How to value the real risk]]&lt;br /&gt;
&lt;br /&gt;
[[How to write the report of the testing |5.2 How to write the report of the testing]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[Appendix A: Testing Tools |Appendix A: Testing Tools ]]==&lt;br /&gt;
&lt;br /&gt;
* Black Box Testing Tools&lt;br /&gt;
* Source Code Analyzers&lt;br /&gt;
* Other Tools&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[OWASP Testing Guide Appendix B: Suggested Reading | Appendix B: Suggested Reading]]==&lt;br /&gt;
* Whitepapers&lt;br /&gt;
* Books&lt;br /&gt;
* Useful Websites&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==[[OWASP Testing Guide Appendix C: Fuzz Vectors | Appendix C: Fuzz Vectors]]==&lt;br /&gt;
&lt;br /&gt;
* Fuzz Categories&lt;br /&gt;
** Recursive fuzzing&lt;br /&gt;
** Replasive fuzzing&lt;br /&gt;
* Cross Site Scripting (XSS)&lt;br /&gt;
* Buffer Overflows and Format String Errors&lt;br /&gt;
** Buffer Overflows (BFO)&lt;br /&gt;
** Format String Errors (FSE)&lt;br /&gt;
** Integer Overflows (INT)&lt;br /&gt;
* SQL Injection&lt;br /&gt;
** Passive SQL Injection (SQP)&lt;br /&gt;
** Active SQL Injection (SQI)&lt;br /&gt;
* LDAP Injection&lt;br /&gt;
* XPATH Injection&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Testing Project]]&lt;/div&gt;</summary>
		<author><name>Jopi</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_Testing_Project_v2.0_-_Review_Guidelines&amp;diff=15291</id>
		<title>Talk:OWASP Testing Project v2.0 - Review Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_Testing_Project_v2.0_-_Review_Guidelines&amp;diff=15291"/>
				<updated>2007-01-12T12:48:28Z</updated>
		
		<summary type="html">&lt;p&gt;Jopi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Typos'''&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Hi all. I ´ ve been having a look at Owasp guide pages and contents, and I&lt;br /&gt;
have&lt;br /&gt;
doubts because of typos or perhaps not completely well explained facts. In&lt;br /&gt;
Dinis Cruz first announcement mail you can read:&lt;br /&gt;
&lt;br /&gt;
'' The current plan is to create a 'published' version of this guide on the&lt;br /&gt;
10th&lt;br /&gt;
of February which will be sent as a book to all OWASP members''&lt;br /&gt;
&lt;br /&gt;
But in that same email, the linked page that targets to reviewing guidelines, I&lt;br /&gt;
found different dates to the email message. At first I read in&lt;br /&gt;
[http://www.owasp.org/index.php/OWASP_Testing_Project_v2.0_-_Review_Guidelines#Timelines&lt;br /&gt;
timelines] section&lt;br /&gt;
&lt;br /&gt;
 #  11th January 2007: Review process begins&lt;br /&gt;
 # 11th January 2007: Review process ends&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
That I am almost completely secure it is wrong, and so I edited te page to put&lt;br /&gt;
February the 11th in the reviewing process end. But it keeps mismatching with&lt;br /&gt;
the time the email says, may you please address this issue? Thank you very&lt;br /&gt;
much.&lt;br /&gt;
&lt;br /&gt;
I send a copy of this message both to wiki discussion page and email to the&lt;br /&gt;
guide responsibles.&lt;/div&gt;</summary>
		<author><name>Jopi</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category_talk:OWASP_Testing_Project&amp;diff=15290</id>
		<title>Category talk:OWASP Testing Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category_talk:OWASP_Testing_Project&amp;diff=15290"/>
				<updated>2007-01-12T12:05:57Z</updated>
		
		<summary type="html">&lt;p&gt;Jopi: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Typos]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Hi all. I ´ ve been having a look at Owasp guide pages and contents, and I have doubts because of typos or perhaps not completely well explained facts. In Dinis Cruz first announcement mail you can read:&lt;br /&gt;
&lt;br /&gt;
'' The current plan is to create a 'published' version of this guide on the 10th of February which will be sent as a book to all OWASP members''&lt;br /&gt;
&lt;br /&gt;
But in that same email, the linked page that targets to reviewing guidelines, I found different dates to the email message. At first I read in [http://www.owasp.org/index.php/OWASP_Testing_Project_v2.0_-_Review_Guidelines#Timelines timelines] section&lt;br /&gt;
&lt;br /&gt;
 #  11th January 2007: Review process begins&lt;br /&gt;
 # 11th January 2007: Review process ends&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
That I am almost completely secure it is wrong, and so I edited te page to put February the 11th in the reviewing process end. But it keeps mismatching with the time the email says, may you please address this issue? Thank you very much.&lt;br /&gt;
&lt;br /&gt;
I send a copy of this message both to wiki discussion page and email to the guide responsibles.&lt;/div&gt;</summary>
		<author><name>Jopi</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Testing_Project_v2.0_-_Review_Guidelines&amp;diff=15289</id>
		<title>OWASP Testing Project v2.0 - Review Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Testing_Project_v2.0_-_Review_Guidelines&amp;diff=15289"/>
				<updated>2007-01-12T11:40:24Z</updated>
		
		<summary type="html">&lt;p&gt;Jopi: /* FAQ */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is a support page for the [[:Category:OWASP Testing Project]] V2.0 Review effort. In here you will find more details on how to participate in this collaborative review process.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Request for Review ==&lt;br /&gt;
&lt;br /&gt;
Now that the The OWASP Testing Guide v2.0 has reached the 'Release Candidate 1 milestone, the time has come to make sure that everything is 100% and that there is nothing major missing.&lt;br /&gt;
&lt;br /&gt;
During the next month we invite you all to review the current version of the OWASP Testing Guide, which is available in WIKI format here: [[OWASP_Testing_Guide_v2_Table_of_Contents]]&lt;br /&gt;
&lt;br /&gt;
For your conveinience this version is also available in [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_RC1_pdf.zip Adobe PDF format] or [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_RC1_doc.zip Ms Doc format]&lt;br /&gt;
&lt;br /&gt;
The current plan is to create a 'published' version of this guide on the 10th of February which will be sent to all OWASP members in book format.&lt;br /&gt;
&lt;br /&gt;
== Timelines ==&lt;br /&gt;
&lt;br /&gt;
* 01th January 2007: Owasp Testing Guide reaches Release Candidate 1 milestone&lt;br /&gt;
* 11th January 2007: Review process begins&lt;br /&gt;
* 11th February 2007: Review process ends&lt;br /&gt;
* 11th March 2007: Book is created and starts to be shipped to current OWASP members&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
* '''Q: Which are the main points of contact for this project'''&lt;br /&gt;
* A: The main contacts are: [[User:EoinKeary|Eoin Keary]] (OWASP Testing Project Leader) [[User:Mmeucci|Matteo Meucci]] (OWASP Testing Guide AoC 2006 lead) and [[User:Dinis.cruz|Dinis Cruz]] (Chief Owasp Evangelist). You can also join the [http://lists.owasp.org/mailman/listinfo/owasp-testing OWASP Testing mailing list] and ask your question there.&lt;br /&gt;
&lt;br /&gt;
* '''Q: If I find a mistake in a WIKI page can I just edit it?'''&lt;br /&gt;
* A: Yes of course, just use your account (free to create) and click on 'edit'&lt;br /&gt;
&lt;br /&gt;
*''' Q: Where do I add comments about a particular page?'''&lt;br /&gt;
* A: Either use the 'Discussion' page that exists for every content page, or add your comment to the ''General Area for general Comments'' below&lt;br /&gt;
&lt;br /&gt;
*''' Q: If I have sugestions for the next version of the Guide, where do I place them?'''&lt;br /&gt;
* A: use the ''Wish List for next version'' area below&lt;br /&gt;
&lt;br /&gt;
== Wish List for next version ==&lt;br /&gt;
* {put here your wish list for the next version (we will try to release a new version every 6 to 9 months.)}&lt;br /&gt;
&lt;br /&gt;
== General Area for general Comments ==&lt;br /&gt;
&lt;br /&gt;
* {if you have a general comments or specific question, feel free to place it here}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Testing Project]]&lt;/div&gt;</summary>
		<author><name>Jopi</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Testing_Project_v2.0_-_Review_Guidelines&amp;diff=15285</id>
		<title>OWASP Testing Project v2.0 - Review Guidelines</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Testing_Project_v2.0_-_Review_Guidelines&amp;diff=15285"/>
				<updated>2007-01-12T09:01:30Z</updated>
		
		<summary type="html">&lt;p&gt;Jopi: /* Timelines */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is a support page for the [[:Category:OWASP Testing Project]] V2.0 Review effort. In here you will find more details on how to participate in this collaborative review process.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Request for Review ==&lt;br /&gt;
&lt;br /&gt;
Now that the The OWASP Testing Guide v2.0 has reached the 'Release Candidate 1 milestone, the time has come to make sure that everything is 100% and that there is nothing major missing.&lt;br /&gt;
&lt;br /&gt;
During the next month we invite you all to review the current version of the OWASP Testing Guide, which is available in WIKI format here: [[OWASP_Testing_Guide_v2_Table_of_Contents]]&lt;br /&gt;
&lt;br /&gt;
For your conveinience this version is also available in [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_RC1_pdf.zip Adobe PDF format] or [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_RC1_doc.zip Ms Doc format]&lt;br /&gt;
&lt;br /&gt;
The current plan is to create a 'published' version of this guide on the 10th of February which will be sent to all OWASP members in book format.&lt;br /&gt;
&lt;br /&gt;
== Timelines ==&lt;br /&gt;
&lt;br /&gt;
* 01th January 2007: Owasp Testing Guide reaches Release Candidate 1 milestone&lt;br /&gt;
* 11th January 2007: Review process begins&lt;br /&gt;
* 11th February 2007: Review process ends&lt;br /&gt;
* 11th March 2007: Book is created and starts to be shipped to current OWASP members&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
* '''Q: What are the main points of contact for this project'''&lt;br /&gt;
* A: The main contacts are: [[User:EoinKeary|Eoin Keary]] (OWASP Testing Project Leader) [[User:Mmeucci|Matteo Meucci]] (OWASP Testing Guide AoC 2006 lead) and [[User:Dinis.cruz|Dinis Cruz]] (Chief Owasp Evangelist). You can also join the [http://lists.owasp.org/mailman/listinfo/owasp-testing OWASP Testing mailing list] and ask your question there.&lt;br /&gt;
&lt;br /&gt;
* '''Q:If I find a mistake in a WIKI page can I just edit it?'''&lt;br /&gt;
* A: Yes of course, just use your account (free to create) and click on 'edit'&lt;br /&gt;
&lt;br /&gt;
*''' Q:Where do I add comments about a particular page?'''&lt;br /&gt;
* A: Use the 'Discussion' page that exists for every content page, or add your comment to the ''General Area for general Comments'' below&lt;br /&gt;
&lt;br /&gt;
*''' Q:If I have sugestions for the next version of the Guide where do I place them?'''&lt;br /&gt;
* A: use the ''Wish List for next version'' area below&lt;br /&gt;
&lt;br /&gt;
== Wish List for next version ==&lt;br /&gt;
* {put here your wish list for the next version (we will try to release a new version every 6 to 9 months.)}&lt;br /&gt;
&lt;br /&gt;
== General Area for general Comments ==&lt;br /&gt;
&lt;br /&gt;
* {if you have a general comments or specific question, feel free to place it here}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Testing Project]]&lt;/div&gt;</summary>
		<author><name>Jopi</name></author>	</entry>

	</feed>