در استاندارد OWASP چه مواردی مورد تست قرار می گیرند



Conduct Search Engine Discovery Reconnaissance for Information Leakage
Review Webserver Metafiles for Information Leakage
Enumerate Applications on Webserver
Review Webpage Content for Information Leakage
Identify Application Entry Points
Map Execution Paths Through Application
Testing for Credentials Transported over an Encrypted Channel
Testing for Default Credentials
Testing for Weak Lock Out Mechanism
Testing for Bypassing Authentication Schema
Testing for Vulnerable Remember Password
Testing for Browser Cache Weaknesses
Testing for Weak Password Policy
Testing for Weak Security Question Answer
Testing for Reflected Cross Site Scripting
Testing for Stored Cross Site Scripting
Testing for HTTP Verb Tampering
Testing for HTTP Parameter Pollution
Testing for IMAP SMTP Injection
Testing for Local File Inclusion
Testing for Remote File Inclusion
Testing for Format String Injection
Testing for Incubated Vulnerability
Testing for HTTP Splitting Smuggling
Testing for HTTP Incoming Requests
Testing for Host Header Injection