
Use Our Offense to Inform Your Defense
Web-based security assessments help an organization gain a clear understanding of the risks facing their information assets where they tend to be most accessible – via web applications, web services, thick clients, and legacy applications.
Whether a high-level overview or a thorough, in-depth review is desired, DISD works with your staff to produce prioritized findings, recommendations, and remediation or mitigation steps to fit your organization's profile.
DISD performs web application security assessments according to a well-developed and refined methodology, in order to provide thorough, accurate, and reproducible results covering the web application, platform, and server. Testing initially focuses at the network and server levels, to identify extraneous services, known software vulnerabilities, and mis-configurations. Consultants then focus on enumerating application-level functionality and settings, and use these details to conduct tailored, manual testing in areas such as input validation, session state management, and privilege separation.
DISD uses a combination of well-known tools such as Nikto, Burp Suite, skipfish, w3af, and ratproxy; internally-developed scripts to improve the efficiency and accuracy of tests; and attentive manual web application testing techniques.
Areas of testing focus in a web application security assessment include, but are not limited to:
Web services testing involves many of the same activities and techniques, but often requires different tools compatible with web services protocols and data interchange formats.
In addition to the traditional web application testing activities described above, web services testing often includes:
DISD works with our customers to identify the goals of security assessments prior to testing, and is available to assist in remediation efforts upon request.
Contact Us to Learn More, or Receive A Quote.