Uploaded image for project: 'New Features 2017'
  1. New Features 2017
  2. NF-2714

Vulnerability Assessment and Penetration Testing for Workterra on Azure US environment.

    Details

    • Type: Task
    • Status: To Do
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: UI Refresh
    • Labels:
      None
    • Module:
      BenAdmin
    • Reported by:
      Harbinger
    • Issue Importance:
      Q2
    • Severity:
      Simple

      Description

      Vulnerability Assessment and Penetration Testing for Workterra Web Application

      Environment : Azure US
      Company : Beta Security Test
      Modules : BenAdmin
      Execution : Manual + Tools (ZAP, Tamper Data, SQLMap)

      • Vulnerability Assessment and Security Testing of
        WORKTERRA web application
        selected static and dynamic pages
        Testing between SA,Partner,CA,Employee user roles
      • Application Security Verification Standard:
        o Authentication
        o Session Management
        o Access Control
        o Malicious Input Handling
        o Error Handling and Logging
        o Data Protection
        o Communications Security
        o Malicious Controls
        o File and Resource
      • Comparison to OWASP Top 10 List
      • Verification of Last Years bug fixes

      CC : Rakesh RoySamirVijayendra ShindeBharti Satputeshyam sharmaVijay Siddha

        Attachments

          Issue Links

            Activity

            prasadp Prasad Pise (Inactive) logged work - 12/Jun/17 02:16 PM
            • Time Spent:
              6h
               

              Company Setup, Sanity Tetsing on Company
              Admin Flow, Employee Flow
              Admin flow record for ZAP active Scan

            prasadp Prasad Pise (Inactive) logged work - 13/Jun/17 02:15 PM
            • Time Spent:
              1.5h
               
              <No comment>
            prasadp Prasad Pise (Inactive) logged work - 14/Jun/17 04:39 PM
            • Time Spent:
              0.75h
               

              HTML report Review

            prasadp Prasad Pise (Inactive) logged work - 15/Jun/17 12:44 PM
            • Time Spent:
              2.5h
               

              Login Page, Forgot Pwd Page testing

            prasadp Prasad Pise (Inactive) logged work - 16/Jun/17 03:52 PM
            • Time Spent:
              2.5h
               

              Azure Testing for SSM

            prasadp Prasad Pise (Inactive) logged work - 19/Jun/17 02:25 PM
            • Time Spent:
              3h
               

              Azure US Testing

            prasadp Prasad Pise (Inactive) logged work - 20/Jun/17 02:37 PM
            • Time Spent:
              3h
               

              Testing for employee SSM

            prasadp Prasad Pise (Inactive) logged work - 21/Jun/17 02:38 PM
            • Time Spent:
              4h
               

              Testing on Azure for Employee Pages & Authorization failures

            prasadp Prasad Pise (Inactive) logged work - 22/Jun/17 02:59 PM
            • Time Spent:
              4h
               

              Tried Interception on Change Passoword, Welcome Page, Demographics page

            prasadp Prasad Pise (Inactive) logged work - 28/Jun/17 01:17 PM
            • Time Spent:
              2h
               

              Demographics Page

            prasadp Prasad Pise (Inactive) logged work - 17/Jul/17 02:14 PM
            • Time Spent:
              4h
               

              Worked on Enroll Now page interceptions for cost and coverage.

            prasadp Prasad Pise (Inactive) logged work - 18/Jul/17 03:15 PM
            • Time Spent:
              3.5h
               

              Enroll Now page testing

            prasadp Prasad Pise (Inactive) logged work - 20/Jul/17 12:46 PM
            • Time Spent:
              0.5h
               

              JIRA Updates

            prasadp Prasad Pise (Inactive) logged work - 01/Aug/17 01:42 PM
            • Time Spent:
              3h
               

              Test Plan for Stage/Production Security Testing -
              Employee Pages

              • Login Page
              • Static Pages
            prasadp Prasad Pise (Inactive) logged work - 04/Aug/17 01:38 PM
            • Time Spent:
              3h
               

              Stage Environment
              Testing for Employee SSM -
              Upload document Page
              Employee Beneficiary Page
              Enroll Now Pages

            prasadp Prasad Pise (Inactive) logged work - 09/Aug/17 12:59 PM
            • Time Spent:
              3h
               

              Testing on Stage for Forgot Password Page
              and Static pages

            prasadp Prasad Pise (Inactive) logged work - 11/Aug/17 11:11 AM
            • Time Spent:
              1.75h
               

              Testing for Onboard Tour Page URLs

            prasadp Prasad Pise (Inactive) logged work - 16/Oct/17 02:09 PM
            • Time Spent:
              2h
               

              Test Plan, Authentication Test

            prasadp Prasad Pise (Inactive) logged work - 30/Oct/17 01:32 PM
            • Time Spent:
              1.5h
               

              Internal Discussion with Rakesh
              Test Plan Update
              Discussion with Anirudha J for Task understanding
              Internal discussion for Access Rights on company

            anirudha.joshi anirudha joshi (Inactive) logged work - 30/Oct/17 05:00 PM - edited
            • Time Spent:
              5h
               

              Security team discussion. Knowledge sharing

              Tested below points on production with different user logins.

              Error Handling & Logging
              Access Control

            prasadp Prasad Pise (Inactive) logged work - 31/Oct/17 02:02 PM
            • Time Spent:
              1.5h
               
              <No comment>
            anirudha.joshi anirudha joshi (Inactive) logged work - 31/Oct/17 05:00 PM
            • Time Spent:
              8h
               

              Tested below points on production with different user logins.

              Error Handling & Logging
              Access Control

            prasadp Prasad Pise (Inactive) logged work - 01/Nov/17 04:07 PM
            • Time Spent:
              2.25h
               

              Discussion with Anirudha
              Malicious input handling test

            prasadp Prasad Pise (Inactive) logged work - 02/Nov/17 01:31 PM
            • Time Spent:
              2h
               

              Security Test Access Control, Input Validations

            prasadp Prasad Pise (Inactive) logged work - 03/Nov/17 01:22 PM
            • Time Spent:
              1h
               

              Data Protection

            anirudha.joshi anirudha joshi (Inactive) logged work - 08/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Security team discussion. Knowledge sharing
              Tested below points on production with different user logins.
              Communication

            prasadp Prasad Pise (Inactive) logged work - 09/Nov/17 02:14 PM
            • Time Spent:
              3h
               
              <No comment>
            anirudha.joshi anirudha joshi (Inactive) logged work - 09/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Security team discussion. Knowledge sharing
              Tested below points on production with different user logins.
              HTTP

            prasadp Prasad Pise (Inactive) logged work - 10/Nov/17 02:13 PM - edited
            • Time Spent:
              2.5h
               
              <No comment>
            anirudha.joshi anirudha joshi (Inactive) logged work - 10/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Security team discussion. Knowledge sharing
              Tested below points on production with different user logins.
              Business Logic

            prasadp Prasad Pise (Inactive) logged work - 13/Nov/17 01:30 PM
            • Time Spent:
              3h
               

              Employee Flow Verification through ZAP

            prasadp Prasad Pise (Inactive) logged work - 14/Nov/17 01:21 PM
            • Time Spent:
              3.75h
               

              Internal Discussion with Anirudha for ZAP flow verification
              Security Test Execution

            prasadp Prasad Pise (Inactive) logged work - 15/Nov/17 01:26 PM
            • Time Spent:
              4h
               

              Fuzzing, Spider & Active Scan

            anirudha.joshi anirudha joshi (Inactive) logged work - 15/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Recorded different scenarios with OWASP ZAP and found vulnerabilities which are reported in the "JIRA ID: WT-12154 Security alerts reported during ZAP Spidering of the production application with partner login"

              Also, attached the ZAP reports to the JIRA ID: WT-12154

            prasadp Prasad Pise (Inactive) logged work - 16/Nov/17 01:41 PM
            • Time Spent:
              3h
               

              Security test Scan
              Issues & Reports
              Internal Discusison

            anirudha.joshi anirudha joshi (Inactive) logged work - 16/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Recorded different scenarios with OWASP ZAP and found vulnerabilities which are reported in the "JIRA ID: WT-12154 Security alerts reported during ZAP Spidering of the production application with partner login"

              Also, attached the ZAP reports to the JIRA ID: WT-12154

            prasadp Prasad Pise (Inactive) logged work - 17/Nov/17 02:10 PM
            • Time Spent:
              1h
               

              Discussionw with santosh for ZAP issues

            anirudha.joshi anirudha joshi (Inactive) logged work - 17/Nov/17 06:00 PM
            • Time Spent:
              8h
               

              Recorded different scenarios with OWASP ZAP and found vulnerabilities which are reported in the "JIRA ID: WT-12154 Security alerts reported during ZAP Spidering of the production application with partner login"

              Also, attached the ZAP reports to the JIRA ID: WT-12154

            prasadp Prasad Pise (Inactive) logged work - 23/Nov/17 01:24 PM
            • Time Spent:
              1h
               

              Internal Discussions iwth Santosh and Anirudha

            prasadp Prasad Pise (Inactive) logged work - 28/Nov/17 01:14 PM
            • Time Spent:
              1h
               

              Test Plan for Security- Azure

            prasadp Prasad Pise (Inactive) logged work - 29/Nov/17 01:05 PM
            • Time Spent:
              1h
               

              Internal Discussion with Santosh, Samir
              Internal Discussion Anirudha
              Project Plan Updates

            anirudha.joshi anirudha joshi (Inactive) logged work - 11/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'Login Page', 'Change Password', 'Localization Pages' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

              Reported defect related to login page vulnerability in the JIRA ID, NF-5482: [Security] Login page : Server Error with stack trace displayed on login page.

            anirudha.joshi anirudha joshi (Inactive) logged work - 12/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'Partner Dashboard', 'Configure Dashboard' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            prasadp Prasad Pise (Inactive) logged work - 13/Dec/17 03:30 PM
            • Time Spent:
              4h
               
              <No comment>
            anirudha.joshi anirudha joshi (Inactive) logged work - 13/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'User Access Policies' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            anirudha.joshi anirudha joshi (Inactive) logged work - 14/Dec/17 06:00 PM - edited
            • Time Spent:
              8h
               

              Tested 'Add Company', 'Search company' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            anirudha.joshi anirudha joshi (Inactive) logged work - 15/Dec/17 06:00 PM
            • Time Spent:
              8h
               

              Tested 'Change Employee Password', 'Change Employee Status', 'User Credentials Settings' pages for below security test checkpoints on pre-production environment.

              Access Control
              Malicious Input Handling
              Session Management
              Authentication

            prasadp Prasad Pise (Inactive) logged work - 18/Dec/17 01:36 PM
            • Time Spent:
              4h
               

              Security Testing 4h

            prasadp Prasad Pise (Inactive) logged work - 19/Dec/17 01:33 PM
            • Time Spent:
              5h
               

              Security Testing 5h

            prasadp Prasad Pise (Inactive) logged work - 20/Dec/17 01:27 PM
            • Time Spent:
              3h
               

              Security Test
              Internal Discussions
              ZAP Scan

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 21/Dec/17 10:57 AM
            • Time Spent:
              5h
               

              1. Discussion regarding the security testing for the mobile Application
              2. Review the mobile security testing points shared by Prasad

            prasadp Prasad Pise (Inactive) logged work - 21/Dec/17 01:25 PM
            • Time Spent:
              4h
               

              PreProd Security testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 22/Dec/17 10:58 AM
            • Time Spent:
              3h
               

              Review the mobile security testing points shared by Prasad

            prasadp Prasad Pise (Inactive) logged work - 03/Jan/18 01:24 PM
            • Time Spent:
              3.5h
               

              Employee Level Testing

            prasadp Prasad Pise (Inactive) logged work - 04/Jan/18 01:13 PM
            • Time Spent:
              2.5h
               

              Employee level test

            prasadp Prasad Pise (Inactive) logged work - 08/Jan/18 01:16 PM
            • Time Spent:
              2h
               
              <No comment>
            prasadp Prasad Pise (Inactive) logged work - 09/Jan/18 02:37 PM
            • Time Spent:
              3h
               

              Web App Security Test

            prasadp Prasad Pise (Inactive) logged work - 10/Jan/18 02:42 PM - edited
            • Time Spent:
              4h
               

              Web App Security Test

            prasadp Prasad Pise (Inactive) logged work - 12/Jan/18 02:09 PM
            • Time Spent:
              3h
               

              Web App Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 16/Jan/18 11:32 AM
            • Time Spent:
              5h
               

              1. Discussion with the mobile team regarding the APK installation
              2. Started Security testing on the Android mobile

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 17/Jan/18 11:32 AM
            • Time Spent:
              5h
               

              1. Self Serve Mode Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 19/Jan/18 01:17 PM
            • Time Spent:
              8h
               

              Mobile Security Testing

            prasadp Prasad Pise (Inactive) logged work - 22/Jan/18 09:19 AM
            • Time Spent:
              4h
               

              Testing for Mobile Security

            prasadp Prasad Pise (Inactive) logged work - 23/Jan/18 02:24 PM
            • Time Spent:
              2.5h
               

              Mobile Secutity Testing for Android and Ios

            prasadp Prasad Pise (Inactive) logged work - 24/Jan/18 02:39 PM
            • Time Spent:
              4h
               

              Mobile Secutity Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 29/Jan/18 01:19 PM
            • Time Spent:
              2h
               

              Mobile Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 30/Jan/18 01:25 PM
            • Time Spent:
              8h
               

              Debugging the issues encountered during the testing of Mobile Security testing.

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 31/Jan/18 01:20 PM
            • Time Spent:
              8h
               

              Debugging the issues encountered during mobile Security Testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 01/Feb/18 12:01 PM
            • Time Spent:
              6.5h
               

              Mobile Security testing on Android device.

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 07/Feb/18 11:49 AM
            • Time Spent:
              8h
               

              Mobile Security Testing on Mobile Device.

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 08/Feb/18 11:46 AM
            • Time Spent:
              4h
               

              Mobile Security Testing on Android device.

            prasadp Prasad Pise (Inactive) logged work - 12/Feb/18 12:40 PM
            • Time Spent:
              2h
               

              IPad Security testing

            prasadp Prasad Pise (Inactive) logged work - 13/Feb/18 01:39 PM
            • Time Spent:
              2h
               

              IOS Security Test
              Build verification and Discusion with Rohan

            prasadp Prasad Pise (Inactive) logged work - 14/Feb/18 01:28 PM
            • Time Spent:
              2.5h
               

              Internal Discussion and Security test for ipad

            prasadp Prasad Pise (Inactive) logged work - 15/Feb/18 01:37 PM
            • Time Spent:
              1.5h
               

              Security Testing for IOS

            prasadp Prasad Pise (Inactive) logged work - 16/Feb/18 02:12 PM
            • Time Spent:
              4h
               

              Security TEst for remaining part of IOS app
              Internal Discusison with Shailesh and Mobile Team QA

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 19/Feb/18 11:37 AM
            • Time Spent:
              8h
               

              Mobile Security Testing on Android Device

            prasadp Prasad Pise (Inactive) logged work - 19/Feb/18 12:47 PM
            • Time Spent:
              3h
               

              Test Status meeting with Samir, Vijayendra and Santosh
              Discussion with Vijayendra and Pratap
              ZAP run and Analysis for findings to be shared on Reports

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 21/Feb/18 11:32 AM - edited
            • Time Spent:
              7.5h
               

              Mobile Security testing on Android device

            prasadp Prasad Pise (Inactive) logged work - 21/Feb/18 02:15 PM
            • Time Spent:
              4h
               

              Web Remediation Plan Verification for Benchmarking of Security on Preprod environment

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 22/Feb/18 12:03 PM
            • Time Spent:
              8h
               

              Security Testing on Android Device.

            prasadp Prasad Pise (Inactive) logged work - 22/Feb/18 01:19 PM
            • Time Spent:
              5h
               

              Remediation Sheet test scenarios Verification
              Internal Discussions

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 23/Feb/18 01:18 PM
            • Time Spent:
              8h
               

              1. Manual Execution of Security Testing Scenarios on Mobile application Android device
              2. Preparing the Security testing report for Manual execution

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 27/Feb/18 01:30 PM
            • Time Spent:
              8h
               

              1. ZAP Scenario Record and scheduling active scan
              2. Created two employees on the PreProd environment to record the scenario

            prasadp Prasad Pise (Inactive) logged work - 27/Feb/18 01:47 PM
            • Time Spent:
              2h
               

              Mobile Team - ZAP Scenario reocrd, Active Scan,

            santosh.balid Santosh Balid (Inactive) logged work - 27/Feb/18 02:11 PM
            • Time Spent:
              4.5h
               
              <No comment>
            shailesh.chikate Shailesh Chikate (Inactive) logged work - 28/Feb/18 01:24 PM
            • Time Spent:
              8h
               

              1. ZAP Scenario Record and scheduling active scan
              2. Created two employees on the PreProd environment to record the scenario

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 01/Mar/18 06:57 AM
            • Time Spent:
              8h
               
              1. Analysis of security test execution report
              2. Understanding of ZAP tool.
            prasadp Prasad Pise (Inactive) logged work - 01/Mar/18 01:17 PM
            • Time Spent:
              1.5h
               

              ZAP Report for IOS
              Discussion and Verification with Shailesh

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 05/Mar/18 05:01 AM
            • Time Spent:
              8h
               

              1. Exploring the ZAP tool for Web Security testing

            shailesh.chikate Shailesh Chikate (Inactive) logged work - 06/Mar/18 05:02 AM
            • Time Spent:
              8h
               

              1. Exploring the ZAP tool for Web Security testing

            prasadp Prasad Pise (Inactive) logged work - 22/Mar/18 01:31 PM
            • Time Spent:
              4h
               

              Security PPTs and Reports documentation
              OLD Issue closure

            prasadp Prasad Pise (Inactive) logged work - 23/Mar/18 10:21 AM
            • Time Spent:
              2h
               

              Security PPTs updates for Presentation
              Test Report Document
              PenTest Tools Read

              People

              Assignee:
              jayshree.nagpure Jayshree Nagpure (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              QA:
              Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:

                  Time Tracking

                  Estimated:
                  Original Estimate - 80h Original Estimate - 80h
                  80h
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 403h
                  403h