Tema: security-testing
-
Comparing parser handoff decisions without building an exploit payload
Test whether successive components agree on the security-relevant meaning of a benign request fixture. The proposal focuses on interpretation differences at a handoff, using local instrumentation and inert marker values.
-
Checking outbound credential attachment with a local destination recorder
Verify that an application attaches a credential only to destinations authorized for that credential. This proposal uses a fake credential and local request recorders so evidence never requires transmitting a real secret.
-
Checking preview and dry-run modes with a side-effect ledger
Verify a product’s promise that a preview does not commit protected changes. This proposed security regression makes the allowed and forbidden effects observable instead of trusting the presence of a dry-run flag.
-
Calibrating a scanner result with a vulnerable fixture and a safe twin
Determine whether a security scanner distinguishes the behavior it claims to detect. This original method uses controlled fixtures to interpret a finding, not to certify the scanner or rank products.
-
Testing recovery contact changes as a state transition
Check which recovery destinations become effective during a contact-change workflow. This proposal treats old, pending, and confirmed destinations as separate states instead of assuming that a saved field is already trusted.
-
Testing whether counts and summaries respect hidden-record visibility
Check whether derived responses follow the product’s visibility rules for protected records. The proposal distinguishes a permitted aggregate from an unintended disclosure instead of assuming every count must be private.
-
Verifying archive extraction containment with a disposable directory ledger
Test an extraction feature’s promised write boundary using an isolated filesystem and inert fixture files. This original methodology focuses on where writes occur, without assuming any particular archive library is safe or unsafe.
-
Detecting security tests that accidentally run with administrator authority
Ensure a security test is exercising the intended low-privilege identity rather than a privileged fixture default. This original method checks effective authority before trusting a denied-access assertion or a successful user workflow.
-
Observing sharing-link revocation without assuming immediate consistency
Give a sharing-link revocation claim a concrete test oracle and observation window. The proposed method separates the intended revocation contract from assumptions about when every retrieval path must stop serving content.
Legible por máquina: JSON