Why is doing my web security test from within a browser

Discussion of the technology underlying the eValid solution.

Why is doing my web security test from within a browser

Postby JordanS » Wed Dec 04, 2013 3:05 pm

Why is doing my web security test from within a browser better than just analyzing the stuff on my web server?
JordanS
 
Posts: 1
Joined: Wed Dec 04, 2013 2:58 pm

Re: Why is doing my web security test from within a browser

Postby eValid » Thu Dec 05, 2013 4:20 pm

Yes, it is true that many potential vulnerabilities can be found by analyzing the pre-downloaded content that exists in various forms on your website.

The main advantage of the eValid approach, which performs the analysis entirely on what IS actually downloaded to a client user, is that the analysis process does not have the possibility to be confused by any OTHER information than what an actual client user will see.

While it is true that if your server get's hacked, a bad guy may be able to overcome security on your site from the server side, it is also true that the MAJORITY of attacks are originated from what is sent out to clients.

One other advantage: eValid can emulate/simulate/imitate ANY type of client...so a vulnerability that is not evident when your server is deliverying HTML to an IE/FireFox/Safari/Chrom browser may be evident when that same server is producing HTML for an iPhone or iPat or some other such non-PC device.

__________________
eValid Support
eValid
 
Posts: 2395
Joined: Tue Jan 01, 2008 12:48 pm
Location: USA


Return to Technology

Design Downloaded from free phpBB templates | free website templates | Free Web Buttons