1, the Safety test application scope
2. Safety Test process Diagram
3. Safety Test Path
3.1, automated vulnerability Scanning Tool AppScan, etc.
3.2, Server account permissions test, port scan
3.3. HTTP protocol basic method test: Put, delete, trace, move, copy
3.4. Web server version information (known exploit)
3.5, Dirbuster tool Way Sensitive Interface traversal (enumeration method)
3.6, the Robots way Sensitive interface lookup
3.7. Web Console weak password test
3.8, Dirbuster directory list test
3.9, Server file archiving test (temporary file access)
3.10 Certification Test
3.11 Session Management
3.12 Rights Management
3.13 File Upload Download
3.14 Information Disclosure
3.15 input data
3.16 Cross-Site scripting attacks
3.17 Logical Test
3.18 Search engine Information collection (Googlehack)
3.19webservice Test
3.20class file decompile