際際滷

際際滷Share a Scribd company logo
Conference on web security  overview- 2013
Vote of thanks
 Co-organizers
IT Professional Forum
FOSS Nepal Community
Vote of thanks
 Prime Sponsor
World Distribution Nepal Pvt. Ltd.
Vote of thanks
 Sponsors
Eminence Ways
Entrust Solutions Nepal
Braindigit IT Solution Pvt. Ltd.
Alternative Solutions Pvt. Ltd.
Aryan Education
Vote of thanks
 Supporters
OWASP Nepal
Acunetix
ITS Nepal
Sparrow SMS
Open Knowledge Foundation
Nepal Russia ICT Society
Mozilla Nepal
Vote of thanks
 Supporters
Google Developers Nepal
ASPNet Community
PHP Developers Nepal
WordPress Nepal
Python Developers Nepal
NSH(Nite Shadow Hack)
Nep Security
Introduction to SQA Enthusiast
What SQA Enthusiast Does?
 Awareness on Software Quality
 Classes, Presentations, Discussions on
Software Quality Assurance
 Functional, Performance Test, Security Testing
ideas
 Research on web security, Performance tuning
What is Web Security Testing
Campaign?
 This is collection of special days where we test
web sites against various types of
vulnerabilities
 Campaign that has been running from last 4
months and will be for other 2 months.
 Site registration, Testing, Verification,
Reporting, Fixing, Retesting .
 Improvement of websites security level.
Why this campaign?
 To test web sites against vulnerabilities.
 To aware people and organizations to focus
highly on quality and less on cost.
 To introduce Nepal as a center of quality
software development.
 To make a great improvement in the
ecosystem of software development.
Agenda for today?
 We will be sharing our knowledge on few
vulnerabilities and how are they exploited
(strictly not to teach cracking)
 See Learn Prevent motto
 Site Registration for test
What will be there tomorrow?
 Site test procedure starts
 Authorization to test, test, verify, report, fix.
 Other training sessions will be started.
 (Web, desktop, mobile app testing).
 Other events on security audit.
Presented by
Narayan Koirala
On behalf of
Team SQA Enthusiast
https://www.facebook.com/sqa.enthusiast
https://www.facebook.com/groups/sqapro/
http://www.slideshare.net/sqaenthusiast
https://twitter.com/sqaenthusiast

More Related Content

Similar to Conference on web security overview- 2013 (20)

Social values of open source - By Issa Mahasneh
Social values of open source - By Issa MahasnehSocial values of open source - By Issa Mahasneh
Social values of open source - By Issa Mahasneh
Jordan Open Source Association
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG: connecting the knowledge community
Digital And New Media Strategy using Web 2.0
Digital And New Media Strategy using Web 2.0Digital And New Media Strategy using Web 2.0
Digital And New Media Strategy using Web 2.0
Mahesh Patwardhan
RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation RA21 Charleston Library Conference Presentation
RA21 Charleston Library Conference Presentation
National Information Standards Organization (NISO)
Mozilla intro & how to contribute
Mozilla intro & how to contributeMozilla intro & how to contribute
Mozilla intro & how to contribute
Srikar Ananthula
Four Kitchens: We make BIG websites
Four Kitchens: We make BIG websitesFour Kitchens: We make BIG websites
Four Kitchens: We make BIG websites
Four Kitchens
Security and Banking Sector of Nepal
Security and Banking Sector of NepalSecurity and Banking Sector of Nepal
Security and Banking Sector of Nepal
Abartan Dhakal
WE16 - Navigating the Seas of Open Source Projects
WE16 - Navigating the Seas of Open Source ProjectsWE16 - Navigating the Seas of Open Source Projects
WE16 - Navigating the Seas of Open Source Projects
Society of Women Engineers
Virtual Marketing Ecosystems - at Great Lakes Institute of Management, Chennai
Virtual Marketing Ecosystems - at Great Lakes Institute of Management, ChennaiVirtual Marketing Ecosystems - at Great Lakes Institute of Management, Chennai
Virtual Marketing Ecosystems - at Great Lakes Institute of Management, Chennai
Sorav Jain
Open Source as a Viable Business Model
Open Source as a Viable Business ModelOpen Source as a Viable Business Model
Open Source as a Viable Business Model
Tien-Soon Law
What's new at Crossref - Ed Pentz - London LIVE 2017
What's new at Crossref - Ed Pentz - London LIVE 2017What's new at Crossref - Ed Pentz - London LIVE 2017
What's new at Crossref - Ed Pentz - London LIVE 2017
Crossref
Agile Testing Alliance - Chapter Details 2.4 - 2014
Agile Testing Alliance - Chapter Details 2.4 - 2014Agile Testing Alliance - Chapter Details 2.4 - 2014
Agile Testing Alliance - Chapter Details 2.4 - 2014
Agile Testing Alliance
NodeJS in Naypyitaw
NodeJS in NaypyitawNodeJS in Naypyitaw
NodeJS in Naypyitaw
Nicholas Doiron
How To Win Startup Weekend
How To Win Startup WeekendHow To Win Startup Weekend
How To Win Startup Weekend
Marsh Sutherland
Peter Kobes - What you should know about a professional Software Company
Peter Kobes - What you should know about a professional Software CompanyPeter Kobes - What you should know about a professional Software Company
Peter Kobes - What you should know about a professional Software Company
Davinci software
Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]
Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]
Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]
APNIC
Building the creative commons community in nigeria
Building the creative commons community in nigeriaBuilding the creative commons community in nigeria
Building the creative commons community in nigeria
Kayode Yussuf
APAN 44: Security outreach at APNIC
APAN 44: Security outreach at APNICAPAN 44: Security outreach at APNIC
APAN 44: Security outreach at APNIC
APNIC
Global impact of OpenStack
Global impact of OpenStack   Global impact of OpenStack
Global impact of OpenStack
openstackindia
Learn How You Can Get Involved in the UiPath Community Part 2
Learn How You Can Get Involved in the UiPath Community Part 2Learn How You Can Get Involved in the UiPath Community Part 2
Learn How You Can Get Involved in the UiPath Community Part 2
DianaGray10
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG webinar: Authentication technology update: RA21 and OpenAthens with Josh...
UKSG: connecting the knowledge community
Digital And New Media Strategy using Web 2.0
Digital And New Media Strategy using Web 2.0Digital And New Media Strategy using Web 2.0
Digital And New Media Strategy using Web 2.0
Mahesh Patwardhan
Mozilla intro & how to contribute
Mozilla intro & how to contributeMozilla intro & how to contribute
Mozilla intro & how to contribute
Srikar Ananthula
Four Kitchens: We make BIG websites
Four Kitchens: We make BIG websitesFour Kitchens: We make BIG websites
Four Kitchens: We make BIG websites
Four Kitchens
Security and Banking Sector of Nepal
Security and Banking Sector of NepalSecurity and Banking Sector of Nepal
Security and Banking Sector of Nepal
Abartan Dhakal
WE16 - Navigating the Seas of Open Source Projects
WE16 - Navigating the Seas of Open Source ProjectsWE16 - Navigating the Seas of Open Source Projects
WE16 - Navigating the Seas of Open Source Projects
Society of Women Engineers
Virtual Marketing Ecosystems - at Great Lakes Institute of Management, Chennai
Virtual Marketing Ecosystems - at Great Lakes Institute of Management, ChennaiVirtual Marketing Ecosystems - at Great Lakes Institute of Management, Chennai
Virtual Marketing Ecosystems - at Great Lakes Institute of Management, Chennai
Sorav Jain
Open Source as a Viable Business Model
Open Source as a Viable Business ModelOpen Source as a Viable Business Model
Open Source as a Viable Business Model
Tien-Soon Law
What's new at Crossref - Ed Pentz - London LIVE 2017
What's new at Crossref - Ed Pentz - London LIVE 2017What's new at Crossref - Ed Pentz - London LIVE 2017
What's new at Crossref - Ed Pentz - London LIVE 2017
Crossref
Agile Testing Alliance - Chapter Details 2.4 - 2014
Agile Testing Alliance - Chapter Details 2.4 - 2014Agile Testing Alliance - Chapter Details 2.4 - 2014
Agile Testing Alliance - Chapter Details 2.4 - 2014
Agile Testing Alliance
How To Win Startup Weekend
How To Win Startup WeekendHow To Win Startup Weekend
How To Win Startup Weekend
Marsh Sutherland
Peter Kobes - What you should know about a professional Software Company
Peter Kobes - What you should know about a professional Software CompanyPeter Kobes - What you should know about a professional Software Company
Peter Kobes - What you should know about a professional Software Company
Davinci software
Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]
Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]
Training and more: Development services at APNIC, by Duncan Macintosh [APNIC 38]
APNIC
Building the creative commons community in nigeria
Building the creative commons community in nigeriaBuilding the creative commons community in nigeria
Building the creative commons community in nigeria
Kayode Yussuf
APAN 44: Security outreach at APNIC
APAN 44: Security outreach at APNICAPAN 44: Security outreach at APNIC
APAN 44: Security outreach at APNIC
APNIC
Global impact of OpenStack
Global impact of OpenStack   Global impact of OpenStack
Global impact of OpenStack
openstackindia
Learn How You Can Get Involved in the UiPath Community Part 2
Learn How You Can Get Involved in the UiPath Community Part 2Learn How You Can Get Involved in the UiPath Community Part 2
Learn How You Can Get Involved in the UiPath Community Part 2
DianaGray10

Recently uploaded (20)

How to Manage Maintenance Request in Odoo 18
How to Manage Maintenance Request in Odoo 18How to Manage Maintenance Request in Odoo 18
How to Manage Maintenance Request in Odoo 18
Celine George
Fatman Book HD Pdf by aayush songare.pdf
Fatman Book  HD Pdf by aayush songare.pdfFatman Book  HD Pdf by aayush songare.pdf
Fatman Book HD Pdf by aayush songare.pdf
Aayush Songare
Strengthened Senior High School - Landas Tool Kit.pptx
Strengthened Senior High School - Landas Tool Kit.pptxStrengthened Senior High School - Landas Tool Kit.pptx
Strengthened Senior High School - Landas Tool Kit.pptx
SteffMusniQuiballo
Different pricelists for different shops in odoo Point of Sale in Odoo 17
Different pricelists for different shops in odoo Point of Sale in Odoo 17Different pricelists for different shops in odoo Point of Sale in Odoo 17
Different pricelists for different shops in odoo Point of Sale in Odoo 17
Celine George
Hemiptera & Neuroptera: Insect Diversity.pptx
Hemiptera & Neuroptera: Insect Diversity.pptxHemiptera & Neuroptera: Insect Diversity.pptx
Hemiptera & Neuroptera: Insect Diversity.pptx
Arshad Shaikh
EUPHORIA GENERAL QUIZ FINALS | QUIZ CLUB OF PSGCAS | 21 MARCH 2025
EUPHORIA GENERAL QUIZ FINALS | QUIZ CLUB OF PSGCAS | 21 MARCH 2025EUPHORIA GENERAL QUIZ FINALS | QUIZ CLUB OF PSGCAS | 21 MARCH 2025
EUPHORIA GENERAL QUIZ FINALS | QUIZ CLUB OF PSGCAS | 21 MARCH 2025
Quiz Club of PSG College of Arts & Science
Trends Spotting Strategic foresight for tomorrows education systems - Debora...
Trends Spotting Strategic foresight for tomorrows education systems - Debora...Trends Spotting Strategic foresight for tomorrows education systems - Debora...
Trends Spotting Strategic foresight for tomorrows education systems - Debora...
EduSkills OECD
LDMMIA Reiki Yoga Next Week Grad Updates
LDMMIA Reiki Yoga Next Week Grad UpdatesLDMMIA Reiki Yoga Next Week Grad Updates
LDMMIA Reiki Yoga Next Week Grad Updates
LDM & Mia eStudios
How to Create a Rainbow Man Effect in Odoo 18
How to Create a Rainbow Man Effect in Odoo 18How to Create a Rainbow Man Effect in Odoo 18
How to Create a Rainbow Man Effect in Odoo 18
Celine George
Nice Dream.pdf /
Nice Dream.pdf                              /Nice Dream.pdf                              /
Nice Dream.pdf /
ErinUsher3
TV Shows and web-series quiz | QUIZ CLUB OF PSGCAS | 13TH MARCH 2025
TV Shows and web-series quiz | QUIZ CLUB OF PSGCAS | 13TH MARCH 2025TV Shows and web-series quiz | QUIZ CLUB OF PSGCAS | 13TH MARCH 2025
TV Shows and web-series quiz | QUIZ CLUB OF PSGCAS | 13TH MARCH 2025
Quiz Club of PSG College of Arts & Science
How to Manage Allocations in Odoo 18 Time Off
How to Manage Allocations in Odoo 18 Time OffHow to Manage Allocations in Odoo 18 Time Off
How to Manage Allocations in Odoo 18 Time Off
Celine George
Parenting Teens: Supporting Trust, resilience and independence
Parenting Teens: Supporting Trust, resilience and independenceParenting Teens: Supporting Trust, resilience and independence
Parenting Teens: Supporting Trust, resilience and independence
Pooky Knightsmith
IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...
IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...
IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...
SweetytamannaMohapat
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
Gibson "Secrets to Changing Behaviour in Scholarly Communication: A 2025 NISO...
National Information Standards Organization (NISO)
"Hymenoptera: A Diverse and Fascinating Order".pptx
"Hymenoptera: A Diverse and Fascinating Order".pptx"Hymenoptera: A Diverse and Fascinating Order".pptx
"Hymenoptera: A Diverse and Fascinating Order".pptx
Arshad Shaikh
Pests of Rice: Damage, Identification, Life history, and Management.pptx
Pests of Rice: Damage, Identification, Life history, and Management.pptxPests of Rice: Damage, Identification, Life history, and Management.pptx
Pests of Rice: Damage, Identification, Life history, and Management.pptx
Arshad Shaikh
Artificial intelligence Presented by JM.
Artificial intelligence Presented by JM.Artificial intelligence Presented by JM.
Artificial intelligence Presented by JM.
jmansha170
Cloud Computing ..PPT ( Faizan ALTAF )..
Cloud Computing ..PPT ( Faizan ALTAF )..Cloud Computing ..PPT ( Faizan ALTAF )..
Cloud Computing ..PPT ( Faizan ALTAF )..
faizanaltaf231
Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...
Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...
Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...
GeorgeDiamandis11
How to Manage Maintenance Request in Odoo 18
How to Manage Maintenance Request in Odoo 18How to Manage Maintenance Request in Odoo 18
How to Manage Maintenance Request in Odoo 18
Celine George
Fatman Book HD Pdf by aayush songare.pdf
Fatman Book  HD Pdf by aayush songare.pdfFatman Book  HD Pdf by aayush songare.pdf
Fatman Book HD Pdf by aayush songare.pdf
Aayush Songare
Strengthened Senior High School - Landas Tool Kit.pptx
Strengthened Senior High School - Landas Tool Kit.pptxStrengthened Senior High School - Landas Tool Kit.pptx
Strengthened Senior High School - Landas Tool Kit.pptx
SteffMusniQuiballo
Different pricelists for different shops in odoo Point of Sale in Odoo 17
Different pricelists for different shops in odoo Point of Sale in Odoo 17Different pricelists for different shops in odoo Point of Sale in Odoo 17
Different pricelists for different shops in odoo Point of Sale in Odoo 17
Celine George
Hemiptera & Neuroptera: Insect Diversity.pptx
Hemiptera & Neuroptera: Insect Diversity.pptxHemiptera & Neuroptera: Insect Diversity.pptx
Hemiptera & Neuroptera: Insect Diversity.pptx
Arshad Shaikh
Trends Spotting Strategic foresight for tomorrows education systems - Debora...
Trends Spotting Strategic foresight for tomorrows education systems - Debora...Trends Spotting Strategic foresight for tomorrows education systems - Debora...
Trends Spotting Strategic foresight for tomorrows education systems - Debora...
EduSkills OECD
LDMMIA Reiki Yoga Next Week Grad Updates
LDMMIA Reiki Yoga Next Week Grad UpdatesLDMMIA Reiki Yoga Next Week Grad Updates
LDMMIA Reiki Yoga Next Week Grad Updates
LDM & Mia eStudios
How to Create a Rainbow Man Effect in Odoo 18
How to Create a Rainbow Man Effect in Odoo 18How to Create a Rainbow Man Effect in Odoo 18
How to Create a Rainbow Man Effect in Odoo 18
Celine George
Nice Dream.pdf /
Nice Dream.pdf                              /Nice Dream.pdf                              /
Nice Dream.pdf /
ErinUsher3
How to Manage Allocations in Odoo 18 Time Off
How to Manage Allocations in Odoo 18 Time OffHow to Manage Allocations in Odoo 18 Time Off
How to Manage Allocations in Odoo 18 Time Off
Celine George
Parenting Teens: Supporting Trust, resilience and independence
Parenting Teens: Supporting Trust, resilience and independenceParenting Teens: Supporting Trust, resilience and independence
Parenting Teens: Supporting Trust, resilience and independence
Pooky Knightsmith
IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...
IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...
IDSP(INTEGRATED DISEASE SURVEILLANCE PROGRAMME...
SweetytamannaMohapat
"Hymenoptera: A Diverse and Fascinating Order".pptx
"Hymenoptera: A Diverse and Fascinating Order".pptx"Hymenoptera: A Diverse and Fascinating Order".pptx
"Hymenoptera: A Diverse and Fascinating Order".pptx
Arshad Shaikh
Pests of Rice: Damage, Identification, Life history, and Management.pptx
Pests of Rice: Damage, Identification, Life history, and Management.pptxPests of Rice: Damage, Identification, Life history, and Management.pptx
Pests of Rice: Damage, Identification, Life history, and Management.pptx
Arshad Shaikh
Artificial intelligence Presented by JM.
Artificial intelligence Presented by JM.Artificial intelligence Presented by JM.
Artificial intelligence Presented by JM.
jmansha170
Cloud Computing ..PPT ( Faizan ALTAF )..
Cloud Computing ..PPT ( Faizan ALTAF )..Cloud Computing ..PPT ( Faizan ALTAF )..
Cloud Computing ..PPT ( Faizan ALTAF )..
faizanaltaf231
Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...
Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...
Module 4 Presentation - Enhancing Competencies and Engagement Strategies in Y...
GeorgeDiamandis11
Ad

Conference on web security overview- 2013

  • 2. Vote of thanks Co-organizers IT Professional Forum FOSS Nepal Community
  • 3. Vote of thanks Prime Sponsor World Distribution Nepal Pvt. Ltd.
  • 4. Vote of thanks Sponsors Eminence Ways Entrust Solutions Nepal Braindigit IT Solution Pvt. Ltd. Alternative Solutions Pvt. Ltd. Aryan Education
  • 5. Vote of thanks Supporters OWASP Nepal Acunetix ITS Nepal Sparrow SMS Open Knowledge Foundation Nepal Russia ICT Society Mozilla Nepal
  • 6. Vote of thanks Supporters Google Developers Nepal ASPNet Community PHP Developers Nepal WordPress Nepal Python Developers Nepal NSH(Nite Shadow Hack) Nep Security
  • 7. Introduction to SQA Enthusiast
  • 8. What SQA Enthusiast Does? Awareness on Software Quality Classes, Presentations, Discussions on Software Quality Assurance Functional, Performance Test, Security Testing ideas Research on web security, Performance tuning
  • 9. What is Web Security Testing Campaign? This is collection of special days where we test web sites against various types of vulnerabilities Campaign that has been running from last 4 months and will be for other 2 months. Site registration, Testing, Verification, Reporting, Fixing, Retesting . Improvement of websites security level.
  • 10. Why this campaign? To test web sites against vulnerabilities. To aware people and organizations to focus highly on quality and less on cost. To introduce Nepal as a center of quality software development. To make a great improvement in the ecosystem of software development.
  • 11. Agenda for today? We will be sharing our knowledge on few vulnerabilities and how are they exploited (strictly not to teach cracking) See Learn Prevent motto Site Registration for test
  • 12. What will be there tomorrow? Site test procedure starts Authorization to test, test, verify, report, fix. Other training sessions will be started. (Web, desktop, mobile app testing). Other events on security audit.
  • 13. Presented by Narayan Koirala On behalf of Team SQA Enthusiast https://www.facebook.com/sqa.enthusiast https://www.facebook.com/groups/sqapro/ http://www.slideshare.net/sqaenthusiast https://twitter.com/sqaenthusiast