<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Narayan+Koirala</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Narayan+Koirala"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Narayan_Koirala"/>
		<updated>2026-05-09T13:03:21Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Nepal&amp;diff=134941</id>
		<title>Talk:Nepal</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Nepal&amp;diff=134941"/>
				<updated>2012-08-28T15:27:07Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: /* Importance of Dedicated QA Team for ensuring Web App Security */ new section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Tools and techniques that we use for checking the security level of web apps that we build. ==&lt;br /&gt;
&lt;br /&gt;
Lets share what we use&lt;br /&gt;
&lt;br /&gt;
Code Inspector&lt;br /&gt;
Vulnerability Scanner&lt;br /&gt;
&lt;br /&gt;
== Importance of Dedicated QA Team for ensuring Web App Security ==&lt;br /&gt;
&lt;br /&gt;
I have raised this topic as there are few companies that are comited to ensuring the security of their web applications&lt;br /&gt;
&lt;br /&gt;
What are the problems in Nepal regarding setup of security sqard&lt;br /&gt;
   Training houses&lt;br /&gt;
   idea about security threats&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Nepal&amp;diff=134940</id>
		<title>Talk:Nepal</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Nepal&amp;diff=134940"/>
				<updated>2012-08-28T15:18:41Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Tools and techniques that we use for checking the security level of web apps that we build. ==&lt;br /&gt;
&lt;br /&gt;
Lets share what we use&lt;br /&gt;
&lt;br /&gt;
Code Inspector&lt;br /&gt;
Vulnerability Scanner&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Nepal&amp;diff=134939</id>
		<title>Nepal</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Nepal&amp;diff=134939"/>
				<updated>2012-08-28T15:15:24Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Nepal  a local chapter of OWASP for Nepal. Here we can discuss on any topic , share tools and techniques related to web app security. Another purpose of creating this page is to bring the people working in web app security together.&lt;br /&gt;
&lt;br /&gt;
So lets get together and move for securing web applications..&lt;br /&gt;
&lt;br /&gt;
We have created a group and page in facebook for better communication and better knowledge sharing&lt;br /&gt;
              facebook group  :- https://www.facebook.com/groups/owasp.nepal  &lt;br /&gt;
              and a facebook page :- https://www.facebook.com/OWASPNepal&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Nepal|extra=The chapter leader is [mailto:Bhupal.sapkota@owasp.org Bhupal Sapkota]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Nepal|emailarchives=http://lists.owasp.org/pipermail/owasp-Nepal}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category: Asia]]&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Nepal&amp;diff=134938</id>
		<title>Nepal</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Nepal&amp;diff=134938"/>
				<updated>2012-08-28T15:13:33Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Nepal  a local chapter of OWASP for Nepal. Here we can discuss on any topic , share tools and techniques related to web app security. Another purpose of creating this page is to bring the people working in web app security together.&lt;br /&gt;
&lt;br /&gt;
So lets get together and move for securing web applications..&lt;br /&gt;
&lt;br /&gt;
We have created a facebook group  :- https://www.facebook.com/groups/owasp.nepal&lt;br /&gt;
              and a facebook page :- https://www.facebook.com/OWASPNepal&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Nepal|extra=The chapter leader is [mailto:Bhupal.sapkota@owasp.org Bhupal Sapkota]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Nepal|emailarchives=http://lists.owasp.org/pipermail/owasp-Nepal}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category: Asia]]&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:Nepal&amp;diff=134773</id>
		<title>Talk:Nepal</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:Nepal&amp;diff=134773"/>
				<updated>2012-08-27T05:20:43Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: Tools and techniques that we use for checking the security level of web apps that we build.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Tools and techniques that we use for checking the security level of web apps that we build. ==&lt;br /&gt;
&lt;br /&gt;
Lets share what we use&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Nepal&amp;diff=134772</id>
		<title>Nepal</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Nepal&amp;diff=134772"/>
				<updated>2012-08-27T05:11:44Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Nepal  a local chapter of OWASP for Nepal. Here we can discuss on any topic , share tools and techniques related to web app security. Another purpose of creating this page is to bring the people working in web app security together.&lt;br /&gt;
&lt;br /&gt;
So lets get together and move for securing web applications..&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Nepal|extra=The chapter leader is [mailto:Bhupal.sapkota@owasp.org Bhupal Sapkota]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Nepal|emailarchives=http://lists.owasp.org/pipermail/owasp-Nepal}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category: Asia]]&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Narayan_Koirala&amp;diff=134771</id>
		<title>User:Narayan Koirala</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Narayan_Koirala&amp;diff=134771"/>
				<updated>2012-08-27T04:23:13Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Software Engineer and Software Quality Assurance Enthusiast. I am working as Software Quality Assurance Incharge at Braindigit IT Solutions Pvt. Ltd. Nepal&lt;br /&gt;
&lt;br /&gt;
Find discussions and topics i have shared. Hope to get feed backs and comments from you all.&lt;br /&gt;
&lt;br /&gt;
You can get me@&lt;br /&gt;
&lt;br /&gt;
Twitter  :- https://twitter.com/narainko&lt;br /&gt;
LinkedIn :- http://np.linkedin.com/pub/er-narayan-koirala/12/538/959&lt;br /&gt;
Facebook :- https://www.facebook.com/narainko&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Narayan_Koirala&amp;diff=134763</id>
		<title>User:Narayan Koirala</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Narayan_Koirala&amp;diff=134763"/>
				<updated>2012-08-26T09:36:56Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Software Engineer and Software Quality Assurance Enthusiast. I am working as Software Quality Assurance Incharge at Braindigit IT Solutions Pvt. Ltd. Nepal&lt;br /&gt;
&lt;br /&gt;
Find discussions and topics i have shared. Hope to get feed backs and comments from you all.&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Narayan_Koirala&amp;diff=134762</id>
		<title>User talk:Narayan Koirala</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Narayan_Koirala&amp;diff=134762"/>
				<updated>2012-08-26T09:35:16Z</updated>
		
		<summary type="html">&lt;p&gt;Narayan Koirala: /* Understanding False Positive and False Negative */ new section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well.&lt;br /&gt;
You will probably want to read the [[Help:Contents|help pages]].&lt;br /&gt;
Again, welcome and have fun! [[User:KateHartmann|KateHartmann]] 19:12, 14 August 2012 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Understanding False Positive and False Negative ==&lt;br /&gt;
&lt;br /&gt;
False positive and False negative are two terms that we should know and be careful about at all times during software testing. Basically &lt;br /&gt;
Both of these are harmful but false negative is more dangerous.These both can be found in both Manual Testing or Automated testing. In brief&lt;br /&gt;
&lt;br /&gt;
'''False positive:-'''&lt;br /&gt;
Test is marked as failed even in reality it is passed, or the functionality works properly&lt;br /&gt;
&lt;br /&gt;
[[How it can occur]] :-It occurs when a test engineer(during manual testing) reports a bug to correctly working function due to mistake or negligence.  Similarly in case of automated testing the test tool may report an &amp;quot;SQL Injection vulnerability&amp;quot; where SQL injection is not possible at all.or a load testing tool may report the failure of loading sites even the hit is from just 50 virtual users(during a test on real users of 50 if it passes), which actually may be false. &lt;br /&gt;
&lt;br /&gt;
[[Problems due to false positive]]:-  This can lead the Senior test engineer who is responsible for verification to confusion or adds a extra burden to check at different levels, or even if the bug is submitted to developer for fix, he/she may be irritated for reporting bug to the function that has no problem and works correctly. Which leads conflicts and may work as a barrier in healthy relation between test engineers or test engineers and developers which is never good for and organization.&lt;br /&gt;
&lt;br /&gt;
How to Handel False Positives:- In manual testing:- Verification of test system before submitting&lt;br /&gt;
                                                    Ensure revision to test  or verification by higher personal ( senior test engineer)&lt;br /&gt;
                                In Automated Testing:-Review the report properly.&lt;br /&gt;
                                                      Check each bugs reported by tool manually for conformation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''False Negative:-''' &lt;br /&gt;
Test is marked as passed even in reality it is failed or there is some problem in functionality or there is a bug &lt;br /&gt;
&lt;br /&gt;
[[How it can occur]] :- In manual testing the function to be tested where there is a bug may  be missed due to  various reasons, or the function may be working correctly during first iteration and  due to some other fixes the function may not be working correctly now.&lt;br /&gt;
In case of automated testing  the tool may miss the  path to test the functionality, due to which a vulnerable system may be marked as passed, or in some cases it may not detect it in its test too.&lt;br /&gt;
&lt;br /&gt;
[[Problems due to false negatives]]:- False negatives are more dangerous than false positives because it can lead to sever problem after the software is released or in case of web apps the site may  be hacked  or user data may be compromised.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
How to Handel False Negatives:- In manual testing:- Ensure better test environment, test plan and cases for testing&lt;br /&gt;
                                                    Add a process of verification by senior test engineer so he many find the hidden bugs.&lt;br /&gt;
                                In Automated Testing:-Do not trust on every tool you use blindly&lt;br /&gt;
                                                      Understand there may be some techniques to reduce the false negatives such as &amp;quot;[[Acusensor technology used    by Acunetix]]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
lastly do not trust manual testing alone or Automated testing alone, Go for both testing  one after another so that you are petty sure there are no false positives or false negatives in the system.&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Happy Testing !!!&amp;quot;&lt;/div&gt;</summary>
		<author><name>Narayan Koirala</name></author>	</entry>

	</feed>