Uploaded image for project: 'New Features 2017'
  1. New Features 2017
  2. NF-2714

Vulnerability Assessment and Penetration Testing for Workterra on Azure US environment.

    Details

    • Type: Task
    • Status: To Do
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: UI Refresh
    • Labels:
      None
    • Module:
      BenAdmin
    • Reported by:
      Harbinger
    • Issue Importance:
      Q2
    • Severity:
      Simple

      Description

      Vulnerability Assessment and Penetration Testing for Workterra Web Application

      Environment : Azure US
      Company : Beta Security Test
      Modules : BenAdmin
      Execution : Manual + Tools (ZAP, Tamper Data, SQLMap)

      • Vulnerability Assessment and Security Testing of
        WORKTERRA web application
        selected static and dynamic pages
        Testing between SA,Partner,CA,Employee user roles
      • Application Security Verification Standard:
        o Authentication
        o Session Management
        o Access Control
        o Malicious Input Handling
        o Error Handling and Logging
        o Data Protection
        o Communications Security
        o Malicious Controls
        o File and Resource
      • Comparison to OWASP Top 10 List
      • Verification of Last Years bug fixes

      CC : Rakesh RoySamirVijayendra ShindeBharti Satputeshyam sharmaVijay Siddha

        Attachments

          Issue Links

            Activity

            prasadp Prasad Pise (Inactive) logged work - 12/Jun/17 02:16 PM
            • Time Spent:
              6h
               

              Company Setup, Sanity Tetsing on Company
              Admin Flow, Employee Flow
              Admin flow record for ZAP active Scan

            prasadp Prasad Pise (Inactive) created issue -
            prasadp Prasad Pise (Inactive) logged work - 13/Jun/17 02:15 PM
            • Time Spent:
              1.5h
               
              <No comment>
            prasadp Prasad Pise (Inactive) made changes -
            Field Original Value New Value
            Remaining Estimate 80h [ 288000 ]
            Original Estimate 80h [ 288000 ]
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 80h [ 288000 ] 78.5h [ 282600 ]
            Time Spent 1.5h [ 5400 ]
            Worklog Id 54707 [ 54707 ]
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 78.5h [ 282600 ] 72.5h [ 261000 ]
            Time Spent 1.5h [ 5400 ] 7.5h [ 27000 ]
            Worklog Id 54708 [ 54708 ]
            prasadp Prasad Pise (Inactive) logged work - 14/Jun/17 04:39 PM
            • Time Spent:
              0.75h
               

              HTML report Review

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 72.5h [ 261000 ] 71.75h [ 258300 ]
            Time Spent 7.5h [ 27000 ] 8.25h [ 29700 ]
            Worklog Id 55131 [ 55131 ]
            prasadp Prasad Pise (Inactive) logged work - 15/Jun/17 12:44 PM
            • Time Spent:
              2.5h
               

              Login Page, Forgot Pwd Page testing

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 71.75h [ 258300 ] 69.25h [ 249300 ]
            Time Spent 8.25h [ 29700 ] 10.75h [ 38700 ]
            Worklog Id 55872 [ 55872 ]
            prasadp Prasad Pise (Inactive) logged work - 16/Jun/17 03:52 PM
            • Time Spent:
              2.5h
               

              Azure Testing for SSM

            prasadp Prasad Pise (Inactive) logged work - 19/Jun/17 02:25 PM
            • Time Spent:
              3h
               

              Azure US Testing

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 69.25h [ 249300 ] 66.75h [ 240300 ]
            Time Spent 10.75h [ 38700 ] 13.25h [ 47700 ]
            Worklog Id 56428 [ 56428 ]
            prasadp Prasad Pise (Inactive) logged work - 20/Jun/17 02:37 PM
            • Time Spent:
              3h
               

              Testing for employee SSM

            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-9842 [ WT-9842 ]
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 66.75h [ 240300 ] 63.75h [ 229500 ]
            Time Spent 13.25h [ 47700 ] 16.25h [ 58500 ]
            Worklog Id 57280 [ 57280 ]
            prasadp Prasad Pise (Inactive) logged work - 21/Jun/17 02:38 PM
            • Time Spent:
              4h
               

              Testing on Azure for Employee Pages & Authorization failures

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 63.75h [ 229500 ] 60.75h [ 218700 ]
            Time Spent 16.25h [ 58500 ] 19.25h [ 69300 ]
            Worklog Id 57281 [ 57281 ]
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 60.75h [ 218700 ] 56.75h [ 204300 ]
            Time Spent 19.25h [ 69300 ] 23.25h [ 83700 ]
            Worklog Id 57282 [ 57282 ]
            prasadp Prasad Pise (Inactive) logged work - 22/Jun/17 02:59 PM
            • Time Spent:
              4h
               

              Tried Interception on Change Passoword, Welcome Page, Demographics page

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 56.75h [ 204300 ] 52.75h [ 189900 ]
            Time Spent 23.25h [ 83700 ] 27.25h [ 98100 ]
            Worklog Id 58060 [ 58060 ]
            prasadp Prasad Pise (Inactive) logged work - 28/Jun/17 01:17 PM
            • Time Spent:
              2h
               

              Demographics Page

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 52.75h [ 189900 ] 50.75h [ 182700 ]
            Time Spent 27.25h [ 98100 ] 29.25h [ 105300 ]
            Worklog Id 59457 [ 59457 ]
            prasadp Prasad Pise (Inactive) logged work - 17/Jul/17 02:14 PM
            • Time Spent:
              4h
               

              Worked on Enroll Now page interceptions for cost and coverage.

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 50.75h [ 182700 ] 46.75h [ 168300 ]
            Time Spent 29.25h [ 105300 ] 33.25h [ 119700 ]
            Worklog Id 64034 [ 64034 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to NF-2965 [ NF-2965 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to NF-2334 [ NF-2334 ]
            prasadp Prasad Pise (Inactive) logged work - 18/Jul/17 03:15 PM
            • Time Spent:
              3.5h
               

              Enroll Now page testing

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 46.75h [ 168300 ] 43.25h [ 155700 ]
            Time Spent 33.25h [ 119700 ] 36.75h [ 132300 ]
            Worklog Id 64417 [ 64417 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to NF-3852 [ NF-3852 ]
            prasadp Prasad Pise (Inactive) logged work - 20/Jul/17 12:46 PM
            • Time Spent:
              0.5h
               

              JIRA Updates

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 43.25h [ 155700 ] 42.75h [ 153900 ]
            Time Spent 36.75h [ 132300 ] 37.25h [ 134100 ]
            Worklog Id 65056 [ 65056 ]
            prasadp Prasad Pise (Inactive) logged work - 01/Aug/17 01:42 PM
            • Time Spent:
              3h
               

              Test Plan for Stage/Production Security Testing -
              Employee Pages

              • Login Page
              • Static Pages
            prasadp Prasad Pise (Inactive) logged work - 04/Aug/17 01:38 PM
            • Time Spent:
              3h
               

              Stage Environment
              Testing for Employee SSM -
              Upload document Page
              Employee Beneficiary Page
              Enroll Now Pages

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 42.75h [ 153900 ] 39.75h [ 143100 ]
            Time Spent 37.25h [ 134100 ] 40.25h [ 144900 ]
            Worklog Id 69594 [ 69594 ]
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 39.75h [ 143100 ] 36.75h [ 132300 ]
            Time Spent 40.25h [ 144900 ] 43.25h [ 155700 ]
            Worklog Id 69595 [ 69595 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-10522 [ WT-10522 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-10523 [ WT-10523 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-10524 [ WT-10524 ]
            prasadp Prasad Pise (Inactive) logged work - 09/Aug/17 12:59 PM
            • Time Spent:
              3h
               

              Testing on Stage for Forgot Password Page
              and Static pages

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 36.75h [ 132300 ] 33.75h [ 121500 ]
            Time Spent 43.25h [ 155700 ] 46.25h [ 166500 ]
            Worklog Id 70531 [ 70531 ]
            prasadp Prasad Pise (Inactive) logged work - 11/Aug/17 11:11 AM
            • Time Spent:
              1.75h
               

              Testing for Onboard Tour Page URLs

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 33.75h [ 121500 ] 32h [ 115200 ]
            Time Spent 46.25h [ 166500 ] 48h [ 172800 ]
            Worklog Id 71416 [ 71416 ]
            prasadp Prasad Pise (Inactive) logged work - 16/Oct/17 02:09 PM
            • Time Spent:
              2h
               

              Test Plan, Authentication Test

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 32h [ 115200 ] 30h [ 108000 ]
            Time Spent 48h [ 172800 ] 50h [ 180000 ]
            Worklog Id 85332 [ 85332 ]
            prasadp Prasad Pise (Inactive) logged work - 30/Oct/17 01:32 PM
            • Time Spent:
              1.5h
               

              Internal Discussion with Rakesh
              Test Plan Update
              Discussion with Anirudha J for Task understanding
              Internal discussion for Access Rights on company

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 30h [ 108000 ] 28.5h [ 102600 ]
            Time Spent 50h [ 180000 ] 51.5h [ 185400 ]
            Worklog Id 87844 [ 87844 ]
            anirudha.joshi anirudha joshi (Inactive) logged work - 30/Oct/17 05:00 PM - edited
            • Time Spent:
              5h
               

              Security team discussion. Knowledge sharing

              Tested below points on production with different user logins.

              Error Handling & Logging
              Access Control

            anirudha.joshi anirudha joshi (Inactive) made changes -
            Remaining Estimate 28.5h [ 102600 ] 20.5h [ 73800 ]
            Time Spent 51.5h [ 185400 ] 59.5h [ 214200 ]
            Worklog Id 88384 [ 88384 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Remaining Estimate 20.5h [ 73800 ] 15.5h [ 55800 ]
            Time Spent 59.5h [ 214200 ] 64.5h [ 232200 ]
            Worklog Id 88385 [ 88385 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Worklog Id 88385 [ 88385 ]
            prasadp Prasad Pise (Inactive) logged work - 31/Oct/17 02:02 PM
            • Time Spent:
              1.5h
               
              <No comment>
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 15.5h [ 55800 ] 14h [ 50400 ]
            Time Spent 64.5h [ 232200 ] 66h [ 237600 ]
            Worklog Id 88391 [ 88391 ]
            anirudha.joshi anirudha joshi (Inactive) logged work - 31/Oct/17 05:00 PM
            • Time Spent:
              8h
               

              Tested below points on production with different user logins.

              Error Handling & Logging
              Access Control

            prasadp Prasad Pise (Inactive) logged work - 01/Nov/17 04:07 PM
            • Time Spent:
              2.25h
               

              Discussion with Anirudha
              Malicious input handling test

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 14h [ 50400 ] 11.75h [ 42300 ]
            Time Spent 66h [ 237600 ] 68.25h [ 245700 ]
            Worklog Id 88670 [ 88670 ]
            prasadp Prasad Pise (Inactive) logged work - 02/Nov/17 01:31 PM
            • Time Spent:
              2h
               

              Security Test Access Control, Input Validations

            prasadp Prasad Pise (Inactive) logged work - 03/Nov/17 01:22 PM
            • Time Spent:
              1h
               

              Data Protection

            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 11.75h [ 42300 ] 10.75h [ 38700 ]
            Time Spent 68.25h [ 245700 ] 69.25h [ 249300 ]
            Worklog Id 89074 [ 89074 ]
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 10.75h [ 38700 ] 8.75h [ 31500 ]
            Time Spent 69.25h [ 249300 ] 71.25h [ 256500 ]
            Worklog Id 89078 [ 89078 ]
            anirudha.joshi anirudha joshi (Inactive) logged work - 08/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Security team discussion. Knowledge sharing
              Tested below points on production with different user logins.
              Communication

            prasadp Prasad Pise (Inactive) logged work - 09/Nov/17 02:14 PM
            • Time Spent:
              3h
               
              <No comment>
            anirudha.joshi anirudha joshi (Inactive) logged work - 09/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Security team discussion. Knowledge sharing
              Tested below points on production with different user logins.
              HTTP

            prasadp Prasad Pise (Inactive) logged work - 10/Nov/17 02:13 PM - edited
            • Time Spent:
              2.5h
               
              <No comment>
            anirudha.joshi anirudha joshi (Inactive) logged work - 10/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Security team discussion. Knowledge sharing
              Tested below points on production with different user logins.
              Business Logic

            prasadp Prasad Pise (Inactive) logged work - 13/Nov/17 01:30 PM
            • Time Spent:
              3h
               

              Employee Flow Verification through ZAP

            anirudha.joshi anirudha joshi (Inactive) made changes -
            Remaining Estimate 8.75h [ 31500 ] 0.75h [ 2700 ]
            Time Spent 71.25h [ 256500 ] 79.25h [ 285300 ]
            Worklog Id 90730 [ 90730 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Remaining Estimate 0.75h [ 2700 ] 0h [ 0 ]
            Time Spent 79.25h [ 285300 ] 87.25h [ 314100 ]
            Worklog Id 90732 [ 90732 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 87.25h [ 314100 ] 95.25h [ 342900 ]
            Worklog Id 90733 [ 90733 ]
            prasadp Prasad Pise (Inactive) logged work - 14/Nov/17 01:21 PM
            • Time Spent:
              3.75h
               

              Internal Discussion with Anirudha for ZAP flow verification
              Security Test Execution

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 95.25h [ 342900 ] 98.25h [ 353700 ]
            Worklog Id 90798 [ 90798 ]
            prasadp Prasad Pise (Inactive) logged work - 15/Nov/17 01:26 PM
            • Time Spent:
              4h
               

              Fuzzing, Spider & Active Scan

            anirudha.joshi anirudha joshi (Inactive) logged work - 15/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Recorded different scenarios with OWASP ZAP and found vulnerabilities which are reported in the "JIRA ID: WT-12154 Security alerts reported during ZAP Spidering of the production application with partner login"

              Also, attached the ZAP reports to the JIRA ID: WT-12154

            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12170 [ WT-12170 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12171 [ WT-12171 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12172 [ WT-12172 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12173 [ WT-12173 ]
            prasadp Prasad Pise (Inactive) logged work - 16/Nov/17 01:41 PM
            • Time Spent:
              3h
               

              Security test Scan
              Issues & Reports
              Internal Discusison

            anirudha.joshi anirudha joshi (Inactive) logged work - 16/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Recorded different scenarios with OWASP ZAP and found vulnerabilities which are reported in the "JIRA ID: WT-12154 Security alerts reported during ZAP Spidering of the production application with partner login"

              Also, attached the ZAP reports to the JIRA ID: WT-12154

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 98.25h [ 353700 ] 102h [ 367200 ]
            Worklog Id 91442 [ 91442 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 102h [ 367200 ] 106h [ 381600 ]
            Worklog Id 91449 [ 91449 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 106h [ 381600 ] 109h [ 392400 ]
            Worklog Id 91454 [ 91454 ]
            prasadp Prasad Pise (Inactive) logged work - 17/Nov/17 02:10 PM
            • Time Spent:
              1h
               

              Discussionw with santosh for ZAP issues

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 109h [ 392400 ] 110h [ 396000 ]
            Worklog Id 91483 [ 91483 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 110h [ 396000 ] 113h [ 406800 ]
            Worklog Id 91486 [ 91486 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 113h [ 406800 ] 116h [ 417600 ]
            Worklog Id 91487 [ 91487 ]
            prasadp Prasad Pise (Inactive) made changes -
            Remaining Estimate 0h [ 0 ] 0.5h [ 1800 ]
            Time Spent 116h [ 417600 ] 115.5h [ 415800 ]
            Worklog Id 91486 [ 91486 ]
            anirudha.joshi anirudha joshi (Inactive) logged work - 17/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Recorded different scenarios with OWASP ZAP and found vulnerabilities which are reported in the "JIRA ID: WT-12154 Security alerts reported during ZAP Spidering of the production application with partner login"

              Also, attached the ZAP reports to the JIRA ID: WT-12154

            anirudha.joshi anirudha joshi (Inactive) made changes -
            Remaining Estimate 0.5h [ 1800 ] 0h [ 0 ]
            Time Spent 115.5h [ 415800 ] 123.5h [ 444600 ]
            Worklog Id 92026 [ 92026 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 123.5h [ 444600 ] 131.5h [ 473400 ]
            Worklog Id 92027 [ 92027 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 131.5h [ 473400 ] 139.5h [ 502200 ]
            Worklog Id 92028 [ 92028 ]
            prasadp Prasad Pise (Inactive) logged work - 23/Nov/17 01:24 PM
            • Time Spent:
              1h
               

              Internal Discussions iwth Santosh and Anirudha

            prasadp Prasad Pise (Inactive) logged work - 28/Nov/17 01:14 PM
            • Time Spent:
              1h
               

              Test Plan for Security- Azure

            prasadp Prasad Pise (Inactive) logged work - 29/Nov/17 01:05 PM
            • Time Spent:
              1h
               

              Internal Discussion with Santosh, Samir
              Internal Discussion Anirudha
              Project Plan Updates

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 139.5h [ 502200 ] 140.5h [ 505800 ]
            Worklog Id 93557 [ 93557 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 140.5h [ 505800 ] 141.5h [ 509400 ]
            Worklog Id 93578 [ 93578 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 141.5h [ 509400 ] 142.5h [ 513000 ]
            Worklog Id 93602 [ 93602 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12633 [ WT-12633 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12634 [ WT-12634 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12635 [ WT-12635 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12636 [ WT-12636 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12637 [ WT-12637 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to WT-12639 [ WT-12639 ]
            anirudha.joshi anirudha joshi (Inactive) logged work - 11/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'Login Page', 'Change Password', 'Localization Pages' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

              Reported defect related to login page vulnerability in the JIRA ID, NF-5482: [Security] Login page : Server Error with stack trace displayed on login page.

            anirudha.joshi anirudha joshi (Inactive) logged work - 12/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'Partner Dashboard', 'Configure Dashboard' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            prasadp Prasad Pise (Inactive) logged work - 13/Dec/17 03:30 PM
            • Time Spent:
              4h
               
              <No comment>
            anirudha.joshi anirudha joshi (Inactive) logged work - 13/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'User Access Policies' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            anirudha.joshi anirudha joshi (Inactive) logged work - 14/Dec/17 06:00 PM - edited
            • Time Spent:
              8h
               

              Tested 'Add Company', 'Search company' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 142.5h [ 513000 ] 150.5h [ 541800 ]
            Worklog Id 96343 [ 96343 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Worklog Id 96343 [ 96343 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 150.5h [ 541800 ] 158.5h [ 570600 ]
            Worklog Id 96344 [ 96344 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 158.5h [ 570600 ] 166.5h [ 599400 ]
            Worklog Id 96347 [ 96347 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 166.5h [ 599400 ] 174.5h [ 628200 ]
            Worklog Id 96348 [ 96348 ]
            anirudha.joshi anirudha joshi (Inactive) made changes -
            Time Spent 174.5h [ 628200 ] 182.5h [ 657000 ]
            Worklog Id 96356 [ 96356 ]
            anirudha.joshi anirudha joshi (Inactive) logged work - 15/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'Change Employee Password', 'Change Employee Status', 'User Credentials Settings' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            prasadp Prasad Pise (Inactive) logged work - 18/Dec/17 01:36 PM
            • Time Spent:
              4h
               

              Security Testing 4h

            prasadp Prasad Pise (Inactive) logged work - 19/Dec/17 01:33 PM
            • Time Spent:
              5h
               

              Security Testing 5h

            prasadp Prasad Pise (Inactive) logged work - 20/Dec/17 01:27 PM
            • Time Spent:
              3h
               

              Security Test
              Internal Discussions
              ZAP Scan

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 21/Dec/17 10:57 AM
            • Time Spent:
              5h
               

              1. Discussion regarding the security testing for the mobile Application
              2. Review the mobile security testing points shared by Prasad

            prasadp Prasad Pise (Inactive) logged work - 21/Dec/17 01:25 PM
            • Time Spent:
              4h
               

              PreProd Security testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 22/Dec/17 10:58 AM
            • Time Spent:
              3h
               

              Review the mobile security testing points shared by Prasad

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 182.5h [ 657000 ] 186.5h [ 671400 ]
            Worklog Id 98363 [ 98363 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 186.5h [ 671400 ] 189.5h [ 682200 ]
            Worklog Id 98365 [ 98365 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 189.5h [ 682200 ] 194.5h [ 700200 ]
            Worklog Id 98368 [ 98368 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 194.5h [ 700200 ] 198.5h [ 714600 ]
            Worklog Id 98373 [ 98373 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 198.5h [ 714600 ] 202.5h [ 729000 ]
            Worklog Id 98398 [ 98398 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 202.5h [ 729000 ] 207.5h [ 747000 ]
            Worklog Id 98727 [ 98727 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 207.5h [ 747000 ] 210.5h [ 757800 ]
            Worklog Id 98729 [ 98729 ]
            prasadp Prasad Pise (Inactive) logged work - 03/Jan/18 01:24 PM
            • Time Spent:
              3.5h
               

              Employee Level Testing

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 210.5h [ 757800 ] 214h [ 770400 ]
            Worklog Id 99199 [ 99199 ]
            prasadp Prasad Pise (Inactive) logged work - 04/Jan/18 01:13 PM
            • Time Spent:
              2.5h
               

              Employee level test

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 214h [ 770400 ] 216.5h [ 779400 ]
            Worklog Id 99384 [ 99384 ]
            prasadp Prasad Pise (Inactive) logged work - 08/Jan/18 01:16 PM
            • Time Spent:
              2h
               
              <No comment>
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 216.5h [ 779400 ] 218.5h [ 786600 ]
            Worklog Id 99799 [ 99799 ]
            prasadp Prasad Pise (Inactive) logged work - 09/Jan/18 02:37 PM
            • Time Spent:
              3h
               

              Web App Security Test

            prasadp Prasad Pise (Inactive) logged work - 10/Jan/18 02:42 PM - edited
            • Time Spent:
              4h
               

              Web App Security Test

            prasadp Prasad Pise (Inactive) logged work - 12/Jan/18 02:09 PM
            • Time Spent:
              3h
               

              Web App Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 16/Jan/18 11:32 AM
            • Time Spent:
              5h
               

              1. Discussion with the mobile team regarding the APK installation
              2. Started Security testing on the Android mobile

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 17/Jan/18 11:32 AM
            • Time Spent:
              5h
               

              1. Self Serve Mode Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 218.5h [ 786600 ] 223.5h [ 804600 ]
            Worklog Id 101135 [ 101135 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 223.5h [ 804600 ] 228.5h [ 822600 ]
            Worklog Id 101136 [ 101136 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 19/Jan/18 01:17 PM
            • Time Spent:
              8h
               

              Mobile Security Testing

            prasadp Prasad Pise (Inactive) logged work - 22/Jan/18 09:19 AM
            • Time Spent:
              4h
               

              Testing for Mobile Security

            prasadp Prasad Pise (Inactive) logged work - 23/Jan/18 02:24 PM
            • Time Spent:
              2.5h
               

              Mobile Secutity Testing for Android and Ios

            prasadp Prasad Pise (Inactive) logged work - 24/Jan/18 02:39 PM
            • Time Spent:
              4h
               

              Mobile Secutity Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 29/Jan/18 01:19 PM
            • Time Spent:
              2h
               

              Mobile Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 30/Jan/18 01:25 PM
            • Time Spent:
              8h
               

              Debugging the issues encountered during the testing of Mobile Security testing.

            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 228.5h [ 822600 ] 236.5h [ 851400 ]
            Worklog Id 102920 [ 102920 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 31/Jan/18 01:20 PM
            • Time Spent:
              8h
               

              Debugging the issues encountered during mobile Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 236.5h [ 851400 ] 238.5h [ 858600 ]
            Worklog Id 102928 [ 102928 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 238.5h [ 858600 ] 246.5h [ 887400 ]
            Worklog Id 102932 [ 102932 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 246.5h [ 887400 ] 254.5h [ 916200 ]
            Worklog Id 102935 [ 102935 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 01/Feb/18 12:01 PM
            • Time Spent:
              6.5h
               

              Mobile Security testing on Android device.

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 07/Feb/18 11:49 AM
            • Time Spent:
              8h
               

              Mobile Security Testing on Mobile Device.

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 08/Feb/18 11:46 AM
            • Time Spent:
              4h
               

              Mobile Security Testing on Android device.

            prasadp Prasad Pise (Inactive) logged work - 12/Feb/18 12:40 PM
            • Time Spent:
              2h
               

              IPad Security testing

            prasadp Prasad Pise (Inactive) logged work - 13/Feb/18 01:39 PM
            • Time Spent:
              2h
               

              IOS Security Test
              Build verification and Discusion with Rohan

            prasadp Prasad Pise (Inactive) logged work - 14/Feb/18 01:28 PM
            • Time Spent:
              2.5h
               

              Internal Discussion and Security test for ipad

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 254.5h [ 916200 ] 257.5h [ 927000 ]
            Worklog Id 104654 [ 104654 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 257.5h [ 927000 ] 261.5h [ 941400 ]
            Worklog Id 104659 [ 104659 ]
            prasadp Prasad Pise (Inactive) made changes -
            Worklog Id 104659 [ 104659 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 261.5h [ 941400 ] 264.5h [ 952200 ]
            Worklog Id 104673 [ 104673 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 264.5h [ 952200 ] 268.5h [ 966600 ]
            Worklog Id 104678 [ 104678 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 268.5h [ 966600 ] 271h [ 975600 ]
            Worklog Id 104681 [ 104681 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 271h [ 975600 ] 275h [ 990000 ]
            Worklog Id 104687 [ 104687 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 275h [ 990000 ] 277h [ 997200 ]
            Worklog Id 104769 [ 104769 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 277h [ 997200 ] 279.5h [ 1006200 ]
            Worklog Id 104811 [ 104811 ]
            prasadp Prasad Pise (Inactive) logged work - 15/Feb/18 01:37 PM
            • Time Spent:
              1.5h
               

              Security Testing for IOS

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 279.5h [ 1006200 ] 281h [ 1011600 ]
            Worklog Id 104815 [ 104815 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 281h [ 1011600 ] 283h [ 1018800 ]
            Worklog Id 104816 [ 104816 ]
            prasadp Prasad Pise (Inactive) logged work - 16/Feb/18 02:12 PM
            • Time Spent:
              4h
               

              Security TEst for remaining part of IOS app
              Internal Discusison with Shailesh and Mobile Team QA

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 19/Feb/18 11:37 AM
            • Time Spent:
              8h
               

              Mobile Security Testing on Android Device

            prasadp Prasad Pise (Inactive) logged work - 19/Feb/18 12:47 PM
            • Time Spent:
              3h
               

              Test Status meeting with Samir, Vijayendra and Santosh
              Discussion with Vijayendra and Pratap
              ZAP run and Analysis for findings to be shared on Reports

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 283h [ 1018800 ] 286h [ 1029600 ]
            Worklog Id 105351 [ 105351 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 21/Feb/18 11:32 AM - edited
            • Time Spent:
              7.5h
               

              Mobile Security testing on Android device

            prasadp Prasad Pise (Inactive) logged work - 21/Feb/18 02:15 PM
            • Time Spent:
              4h
               

              Web Remediation Plan Verification for Benchmarking of Security on Preprod environment

            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 286h [ 1029600 ] 294h [ 1058400 ]
            Worklog Id 105874 [ 105874 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Remaining Estimate 0h [ 0 ] 0.5h [ 1800 ]
            Time Spent 294h [ 1058400 ] 293.5h [ 1056600 ]
            Worklog Id 105874 [ 105874 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Remaining Estimate 0.5h [ 1800 ] 0h [ 0 ]
            Time Spent 293.5h [ 1056600 ] 301.5h [ 1085400 ]
            Worklog Id 105886 [ 105886 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 301.5h [ 1085400 ] 305.5h [ 1099800 ]
            Worklog Id 105903 [ 105903 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 305.5h [ 1099800 ] 313.5h [ 1128600 ]
            Worklog Id 105910 [ 105910 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 313.5h [ 1128600 ] 320h [ 1152000 ]
            Worklog Id 105929 [ 105929 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 22/Feb/18 12:03 PM
            • Time Spent:
              8h
               

              Security Testing on Android Device.

            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 320h [ 1152000 ] 328h [ 1180800 ]
            Worklog Id 105931 [ 105931 ]
            prasadp Prasad Pise (Inactive) logged work - 22/Feb/18 01:19 PM
            • Time Spent:
              5h
               

              Remediation Sheet test scenarios Verification
              Internal Discussions

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 328h [ 1180800 ] 333h [ 1198800 ]
            Worklog Id 105992 [ 105992 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 23/Feb/18 01:18 PM
            • Time Spent:
              8h
               

              1. Manual Execution of Security Testing Scenarios on Mobile application Android device
              2. Preparing the Security testing report for Manual execution

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 333h [ 1198800 ] 337h [ 1213200 ]
            Worklog Id 106331 [ 106331 ]
            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 337h [ 1213200 ] 341h [ 1227600 ]
            Worklog Id 106332 [ 106332 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to MOB-3423 [ MOB-3423 ]
            prasadp Prasad Pise (Inactive) made changes -
            Link This issue relates to MOB-3422 [ MOB-3422 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 27/Feb/18 01:30 PM
            • Time Spent:
              8h
               

              1. ZAP Scenario Record and scheduling active scan
              2. Created two employees on the PreProd environment to record the scenario

            prasadp Prasad Pise (Inactive) logged work - 27/Feb/18 01:47 PM
            • Time Spent:
              2h
               

              Mobile Team - ZAP Scenario reocrd, Active Scan,

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 341h [ 1227600 ] 343h [ 1234800 ]
            Worklog Id 106486 [ 106486 ]
            santosh.balid Santosh Balid (Inactive) logged work - 27/Feb/18 02:11 PM
            • Time Spent:
              4.5h
               
              <No comment>
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 343h [ 1234800 ] 351h [ 1263600 ]
            Worklog Id 106702 [ 106702 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 28/Feb/18 01:24 PM
            • Time Spent:
              8h
               

              1. ZAP Scenario Record and scheduling active scan
              2. Created two employees on the PreProd environment to record the scenario

            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 351h [ 1263600 ] 359h [ 1292400 ]
            Worklog Id 106703 [ 106703 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 359h [ 1292400 ] 367h [ 1321200 ]
            Worklog Id 106707 [ 106707 ]
            santosh.balid Santosh Balid (Inactive) made changes -
            Time Spent 367h [ 1321200 ] 371.5h [ 1337400 ]
            Worklog Id 106727 [ 106727 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 01/Mar/18 06:57 AM
            • Time Spent:
              8h
               
              1. Analysis of security test execution report
              2. Understanding of ZAP tool.
            prasadp Prasad Pise (Inactive) logged work - 01/Mar/18 01:17 PM
            • Time Spent:
              1.5h
               

              ZAP Report for IOS
              Discussion and Verification with Shailesh

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 371.5h [ 1337400 ] 373h [ 1342800 ]
            Worklog Id 106903 [ 106903 ]
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 05/Mar/18 05:01 AM
            • Time Spent:
              8h
               

              1. Exploring the ZAP tool for Web Security testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 06/Mar/18 05:02 AM
            • Time Spent:
              8h
               

              1. Exploring the ZAP tool for Web Security testing

            prasadp Prasad Pise (Inactive) logged work - 22/Mar/18 01:31 PM
            • Time Spent:
              4h
               

              Security PPTs and Reports documentation
              OLD Issue closure

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 373h [ 1342800 ] 377h [ 1357200 ]
            Worklog Id 109356 [ 109356 ]
            prasadp Prasad Pise (Inactive) logged work - 23/Mar/18 10:21 AM
            • Time Spent:
              2h
               

              Security PPTs updates for Presentation
              Test Report Document
              PenTest Tools Read

            prasadp Prasad Pise (Inactive) made changes -
            Time Spent 377h [ 1357200 ] 379h [ 1364400 ]
            Worklog Id 109500 [ 109500 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 379h [ 1364400 ] 387h [ 1393200 ]
            Worklog Id 110435 [ 110435 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 387h [ 1393200 ] 395h [ 1422000 ]
            Worklog Id 111358 [ 111358 ]
            shailesh.chikate Shailesh Chikate (Inactive) made changes -
            Time Spent 395h [ 1422000 ] 403h [ 1450800 ]
            Worklog Id 111359 [ 111359 ]
            prasadp Prasad Pise (Inactive) made changes -
            Assignee Prasad Pise [ prasadp ] Jayshree Nagpure [ jayshree.nagpure ]
            prasadp Prasad Pise (Inactive) made changes -
            Assignee Jayshree Nagpure [ jayshree.nagpure ] Prasad Pise [ prasadp ]
            sachin.hingole Sachin Hingole (Inactive) made changes -
            Assignee Prasad Pise [ prasadp ] Jayshree Nagpure [ jayshree.nagpure ]

              People

              Assignee:
              jayshree.nagpure Jayshree Nagpure (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              QA:
              Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:

                  Time Tracking

                  Estimated:
                  Original Estimate - 80h Original Estimate - 80h
                  80h
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 403h
                  403h